So, hier also
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.07.2014
Suchlauf-Zeit: 19:01:56
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.15.09
Rootkit Datenbank: v2014.07.14.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Vera
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 290571
Verstrichene Zeit: 7 Min, 40 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 7
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, Keine Aktion durch Benutzer, [9045c5da1b609d996f5d8f3709f9f10f],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [9441faa594e7a5916529addf010129d7],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [9441faa594e7a5916529addf010129d7],
PUP.Optional.Babylon.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, In Quarantäne, [1cb94b5436451422980a04f6d03328d8],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-3047707071-1413158378-3072078544-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, In Quarantäne, [25b0940b4536f541c8d69c5d6e957b85],
PUP.Optional.Delta.A, HKU\S-1-5-21-3047707071-1413158378-3072078544-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA, In Quarantäne, [16bf712e413ac96d8eaf4aae37cc15eb],
PUP.Optional.BProtector.A, HKU\S-1-5-21-3047707071-1413158378-3072078544-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, In Quarantäne, [ce07dbc45d1ecd6909ea926a7192f20e],
Registrierungswerte: 3
PUP.Optional.Delta.A, HKU\S-1-5-21-3047707071-1413158378-3072078544-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DELTA\DELTA|tlbrSrchUrl, In Quarantäne, [16bf712e413ac96d8eaf4aae37cc15eb],
PUP.BProtector, HKU\S-1-5-21-3047707071-1413158378-3072078544-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, In Quarantäne, [b02559468eede650ccd4c534ba49956b],
PUP.BProtector, HKU\S-1-5-21-3047707071-1413158378-3072078544-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0633EE93-D776-472f-A0FF-E1416B8B2E3A}, In Quarantäne, [f4e1e9b6e794b3833968c73224dfab55]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 16
PUP.Optional.OpenCandy, C:\Users\Vera\AppData\Roaming\OpenCandy, In Quarantäne, [5b7a3b64007ba591883a2a7506fcd22e],
PUP.Optional.OpenCandy, C:\Users\Vera\AppData\Roaming\OpenCandy\3309451FF7D6462787240E81CCBC6996, In Quarantäne, [5b7a3b64007ba591883a2a7506fcd22e],
PUP.Optional.OpenCandy, C:\Users\Vera\AppData\Roaming\OpenCandy\E75A67630BCC43DC853C82D3322D9C13, In Quarantäne, [5b7a3b64007ba591883a2a7506fcd22e],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\defaults, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\defaults\preferences, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\userCode, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\locale, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\locale\en-US, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
Dateien: 120
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\OpenCandy\3309451FF7D6462787240E81CCBC6996\DeltaTB.exe, In Quarantäne, [6273702f2f4c94a2eee017f7fe03c13f],
PUP.Optional.OpenCandy, C:\Users\Vera\Downloads\pdfsam-x64-v2_2_2.exe, In Quarantäne, [08cd6936384374c2aca214b213f12ad6],
PUP.Optional.BitGuard.A, C:\Windows\System32\Tasks\BitGuard, In Quarantäne, [0fc6cad5116af0464d7b2a96c939c838],
PUP.Optional.Babylon.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\searchplugins\babylon.xml, In Quarantäne, [dafbcdd239422f07c50f02d6d1312dd3],
PUP.Optional.BProtector.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\bProtector_extensions.sqlite, In Quarantäne, [33a25748ff7c9d99de028850c63cec14],
PUP.Optional.BProtector.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\bprotector_prefs.js, In Quarantäne, [4d886d324338b68005dc6c6c9171e020],
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\searchplugins\delta.xml, In Quarantäne, [f2e34e51ccaf49ed6b9cb722a75b30d0],
PUP.Optional.OpenCandy, C:\Users\Vera\AppData\Roaming\OpenCandy\3309451FF7D6462787240E81CCBC6996\5472.ico, In Quarantäne, [5b7a3b64007ba591883a2a7506fcd22e],
PUP.Optional.OpenCandy, C:\Users\Vera\AppData\Roaming\OpenCandy\3309451FF7D6462787240E81CCBC6996\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [5b7a3b64007ba591883a2a7506fcd22e],
PUP.Optional.OpenCandy, C:\Users\Vera\AppData\Roaming\OpenCandy\3309451FF7D6462787240E81CCBC6996\OCBrowserHelper_1.0.6.124.exe, In Quarantäne, [5b7a3b64007ba591883a2a7506fcd22e],
PUP.Optional.OpenCandy, C:\Users\Vera\AppData\Roaming\OpenCandy\E75A67630BCC43DC853C82D3322D9C13\Deltabar_p1v6.exe, In Quarantäne, [5b7a3b64007ba591883a2a7506fcd22e],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome.manifest, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\install.rdf, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\background.html, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\baseObject.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\browser.xul, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\dialog.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\ffCoreFilesIndex.txt, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\main.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\options.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\options.xul, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\platformVersion.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\search_dialog.xul, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\setup.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\asyncDB.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\background.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\browserAction.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\contextMenu.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\dbManager.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\dom_bg.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\fileManager.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\firefox.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\firefoxNotifications.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\firefoxOmnibox.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\message.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\pageAction.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\request.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\tabs.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\webRequest.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\api\windowsMessagingHandler.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\addressBarChangeObserver.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\console.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\consts.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\delegate.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\extensionDataStore.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\folderIOWrapper.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\httpObserver.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\IDBWrapper.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\installer.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\logFile.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\prefs.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\progressListenerObserver.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\registry.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\reloadObserver.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\reports.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\requestObject.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\searchSettings.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\uninstallObserver.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\updateManager.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\utils.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\chrome\content\core\xhr.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\defaults\preferences\prefs.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\manifest.xml, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins.json, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\1.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\13.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\14.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\16.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\17.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\177.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\182.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\183.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\207.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\21.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\22.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\28.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\4.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\47.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\64.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\72.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\78.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\plugins\98.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\userCode\background.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\extensionData\userCode\extension.js, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\locale\en-US\translations.dtd, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\button1.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\button2.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\button3.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\button4.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\button5.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\crossrider_statusbar.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\icon128.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\icon16.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\icon24.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\icon48.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\panelarrow-up.png, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\popup.html, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\skin.css, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\extensions\971d5a0e-9273-487f-b423-ed4d001e437a@73136d87-5f3a-4380-8edb-16a7fa56bbc4.com\skin\update.css, In Quarantäne, [cb0a455ab6c59a9c410de7bee9193ec2],
PUP.Optional.CrossRider.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "1427a116ecaca2fbd91e7f9d1565daf5");), Ersetzt,[d005b5eac3b80b2ba525864a5aaa5aa6]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.admin", false);), Ersetzt,[696cffa0790277bfdb06ffd121e38a76]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.aflt", "babsst");), Ersetzt,[fed7b3ec3546b581cb166d6329db31cf]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");), Ersetzt,[696c940b91ea79bd8e53c10fa85c04fc]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.autoRvrt", "false");), Ersetzt,[d7fe039cf7843600b130c60a20e48a76]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.dfltLng", "en");), Ersetzt,[b322a7f8e09bcd69439e5977669e7a86]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.excTlbr", false);), Ersetzt,[72635f4003783cfa726f7c5440c4f20e]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.id", "8eaedf0800000000000008606e6d496f");), Ersetzt,[4f866c33106be056f8e9ffd131d3728e]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlDay", "15800");), Ersetzt,[31a4b2ed0576ed4950912ba5659fc739]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlRef", "sst");), Ersetzt,[efe68a15186382b47170fcd408fcd42c]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.newTab", false);), Ersetzt,[12c33d62df9ccb6b30b1923eee167090]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prdct", "delta");), Ersetzt,[8b4a7f20cab1ba7c6a77953b8d774cb4]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prtnrId", "delta");), Ersetzt,[b124aff0017ab87ee8f98a465ba99f61]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.rvrt", "false");), Ersetzt,[7f569a050576ae88c12069679d675fa1]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.smplGrp", "none");), Ersetzt,[31a44c5347349f97c819f3ddbd471ee2]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrId", "base");), Ersetzt,[4e876b34fd7e50e61fc218b8986cab55]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrSrchUrl", "");), Ersetzt,[c60f0b947a0179bd7f62765ad2326b95]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsn", "1.8.10.0");), Ersetzt,[08cd742b36459b9b429f349c2fd550b0]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsnTs", "1.8.10.012:38:32");), Ersetzt,[1bba2f7090eb48ee3ca5517f956f2dd3]
PUP.Optional.Delta.A, C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsni", "1.8.10.0");), Ersetzt,[a233e8b7bac13ef8964b814fb252f60a]
Physische Sektoren: 0
(No malicious items detected)
(end) adwareCleaner.txt Code:
# AdwCleaner v3.215 - Bericht erstellt am 15/07/2014 um 20:22:48
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Vera - PC-VERA
# Gestartet von : C:\Users\Vera\Downloads\adwcleaner_3.215.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\BitGuard
Ordner Gelöscht : C:\Users\Vera\AppData\Local\eSupport.com
Ordner Gelöscht : C:\Users\Vera\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Vera\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Vera\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Vera\AppData\Roaming\pdfforge
Datei Gelöscht : C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\53538f8ce06aec49
Schlüssel Gelöscht : HKLM\SOFTWARE\53538f8ce06aec49
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\filescout
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\DataMngr
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.17028
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\prefs.js ]
Zeile gelöscht : user_pref("avg.install.userHPSettings", "hxxp://www.delta-search.com/?affID=1215612&tt=040413_9113&babsrc=HP_ss&mntrId=8EAE08606E6D496F");
Zeile gelöscht : user_pref("avg.install.userSPSettings", "Delta Search");
Zeile gelöscht : user_pref("browser.search.order.1", "Delta Search");
Zeile gelöscht : user_pref("extensions.a971d5a0e9273487fb423ed4d001e437a73136d875f3a43808edb16a7fa56bbc4com39090.39090.internaldb.Resources_meta.value", "%7B%22HTML/settings_old.html%22%3A%7B%22id%22%3A704654%2C%22ver[...]
Zeile gelöscht : user_pref("extensions.a971d5a0e9273487fb423ed4d001e437a73136d875f3a43808edb16a7fa56bbc4com39090.39090.internaldb.Resources_resource_704662.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEU[...]
Zeile gelöscht : user_pref("extensions.a971d5a0e9273487fb423ed4d001e437a73136d875f3a43808edb16a7fa56bbc4com39090.39090.internaldb.Resources_resource_704667.value", "%22data%3Aimage/png%3Bbase64%2CiVBORw0KGgoAAAANSUhEU[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "1427a116ecaca2fbd91e7f9d1565daf5");
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "en");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.id", "8eaedf0800000000000008606e6d496f");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15800");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.10.0");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.10.012:38:32");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.10.0");
Zeile gelöscht : user_pref("extensions.ffxtlbr@delta.com.install-event-fired", true);
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Vera\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [4594 octets] - [15/07/2014 20:21:21]
AdwCleaner[S0].txt - [4247 octets] - [15/07/2014 20:22:48]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4307 octets] ########## JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by Vera on 15.07.2014 at 20:28:24,03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3047707071-1413158378-3072078544-1001\Software\sweetim
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Vera\AppData\Roaming\mozilla\firefox\profiles\yvabtsxy.default\prefs.js
user_pref("extensions.a971d5a0e9273487fb423ed4d001e437a73136d875f3a43808edb16a7fa56bbc4com39090.39090.internaldb.Resources_resource_704664.value", "%22data%3Aimage/png%3Bbase6
user_pref("extensions.a971d5a0e9273487fb423ed4d001e437a73136d875f3a43808edb16a7fa56bbc4com39090.39090.internaldb.Resources_resource_704665.value", "%22data%3Aimage/png%3Bbase6
user_pref("extensions.a971d5a0e9273487fb423ed4d001e437a73136d875f3a43808edb16a7fa56bbc4com39090.39090.internaldb.Resources_resource_704666.value", "%22data%3Aimage/png%3Bbase6
Emptied folder: C:\Users\Vera\AppData\Roaming\mozilla\firefox\profiles\yvabtsxy.default\minidumps [11 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.07.2014 at 20:32:22,41
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ neue FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-07-2014
Ran by Vera (administrator) on PC-VERA on 15-07-2014 20:35:50
Running from C:\Users\Vera\Downloads
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(brother Industries Ltd) C:\Windows\SysWOW64\BRSVC01A.EXE
(brother Industries Ltd) C:\Windows\SysWOW64\BRSS01A.EXE
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Dropbox, Inc.) C:\Users\Vera\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Marek Jasinski - www.FreeCommander.com) C:\Program Files (x86)\FreeCommander\FreeCommander.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-18] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [OpwareSE2] => C:\Program Files (x86)\ScanSoft\OmniPageSE2.0\OpwareSE2.exe [49152 2003-05-08] (ScanSoft, Inc.)
HKLM-x32\...\Run: [OPSE reminder] => C:\Program Files (x86)\ScanSoft\OmniPageSE2.0\EregGer\Ereg.exe [729088 2003-07-07] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [186408 2013-12-12] (Geek Software GmbH)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3047707071-1413158378-3072078544-1001\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
HKU\S-1-5-21-3047707071-1413158378-3072078544-1001\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Vera\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-3047707071-1413158378-3072078544-1001\...\Run: [eM Client for SoftMaker] => C:\Program Files (x86)\eM Client for SoftMaker\MailClient.exe [15378728 2014-04-16] (SoftMaker Software GmbH)
HKU\S-1-5-21-3047707071-1413158378-3072078544-1001\...\Run: [Boxcryptor.exe] => C:\Program Files (x86)\Boxcryptor\Boxcryptor.exe [1063168 2014-04-08] (Secomba GmbH)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
ShortcutTarget: Adobe Gamma Loader.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\USB Sharing.lnk
ShortcutTarget: USB Sharing.lnk -> C:\Program Files (x86)\USB Sharing\usbshare.exe ()
Startup: C:\Users\Vera\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Vera\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
SSODL: EldosMountNotificator-cbfs4 - {DA0E58F5-086C-42C8-A45E-B00B71471214} - C:\Windows\system32\cbfsMntNtf4.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator-cbfs4 - {DA0E58F5-086C-42C8-A45E-B00B71471214} - C:\Windows\SysWOW64\cbfsMntNtf4.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: EldosIconOverlay-cbfs4 -> {884612F2-685B-4295-8EDC-CED7B5750D3B} => C:\Windows\system32\cbfsMntNtf4.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: ShareOverlay -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: EldosIconOverlay-cbfs4 -> {884612F2-685B-4295-8EDC-CED7B5750D3B} => C:\Windows\SysWOW64\cbfsMntNtf4.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: ShareOverlay -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE27236412926CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll (Adblock Plus)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
BHO-x32: Adblock Plus for IE Browser Helper Object - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll (Adblock Plus)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default
FF NewTab: user_pref("browser.newtab.url", "");
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\pdfxviewer\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\pdfxviewer\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\pdfxviewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\pdfxviewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\pdfxviewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Vera\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF SearchPlugin: C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\searchplugins\bildungsspender-websuche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus Pop-up Addon - C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\Extensions\adblockpopups@jessehakanen.net.xpi [2013-08-04]
FF Extension: Personas Plus - C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\Extensions\personas@christopher.beard.xpi [2013-03-24]
FF Extension: Adblock Plus - C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-12]
FF Extension: Tab Mix Plus - C:\Users\Vera\AppData\Roaming\Mozilla\Firefox\Profiles\yvabtsxy.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2013-03-24]
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2014-06-02]
Chrome:
=======
CHR HomePage:
CHR Extension: (Google Docs) - C:\Users\Vera\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-17]
CHR Extension: (Google Drive) - C:\Users\Vera\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-17]
CHR Extension: (YouTube) - C:\Users\Vera\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-17]
CHR Extension: (Adblock Plus) - C:\Users\Vera\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-12-17]
CHR Extension: (Google-Suche) - C:\Users\Vera\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-17]
CHR Extension: (Google Wallet) - C:\Users\Vera\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-17]
CHR Extension: (Google Mail) - C:\Users\Vera\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-17]
CHR HKLM-x32\...\Chrome\Extension: [ohgndokldibnndfnjnagojmheejlengn] - C:\Program Files (x86)\Citavi 4\Pickers\Chrome\ChromePicker.crx [2014-02-07]
==================== Services (Whitelisted) =================
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 Brother XP spl Service; C:\Windows\SysWOW64\brsvc01a.exe [57344 2004-06-14] (brother Industries Ltd)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S2 AdobeFlashPlayerUpdateSvc; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [X]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R3 AU8168; C:\Windows\system32\DRIVERS\au630x64.sys [792648 2013-09-23] (Realtek )
R1 cbfs4; C:\Windows\system32\drivers\cbfs4.sys [387776 2013-11-15] (EldoS Corporation)
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [306536 2011-03-04] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31136 2013-08-10] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-15] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [564824 2013-03-28] (Duplex Secure Ltd.)
R3 vpnpbus; C:\Windows\System32\drivers\vpnpbus.sys [18624 2013-11-15] (EldoS Corporation)
U3 a5dg5bz5; C:\Windows\System32\Drivers\a5dg5bz5.sys [0 ] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S1 hsfswvte; \??\C:\Windows\system32\drivers\hsfswvte.sys [X]
S1 texbrcsh; \??\C:\Windows\system32\drivers\texbrcsh.sys [X]
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-15 20:32 - 2014-07-15 20:34 - 00001721 _____ () C:\Users\Vera\Desktop\JRT.txt
2014-07-15 20:28 - 2014-07-15 20:28 - 01016261 _____ (Thisisu) C:\Users\Vera\Downloads\JRT.exe
2014-07-15 20:28 - 2014-07-15 20:28 - 00000000 ____D () C:\Windows\ERUNT
2014-07-15 20:26 - 2014-07-15 20:26 - 00004387 _____ () C:\Users\Vera\Desktop\AdwCleaner[S0].txt
2014-07-15 20:21 - 2014-07-15 20:22 - 00000000 ____D () C:\AdwCleaner
2014-07-15 20:21 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-15 20:20 - 2014-07-15 20:20 - 01348263 _____ () C:\Users\Vera\Downloads\adwcleaner_3.215.exe
2014-07-15 20:20 - 2014-07-15 20:20 - 00037030 _____ () C:\Users\Vera\Desktop\mbam.txt
2014-07-15 19:00 - 2014-07-15 20:25 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-15 19:00 - 2014-07-15 19:00 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-15 19:00 - 2014-07-15 19:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-15 18:59 - 2014-07-15 19:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-15 18:59 - 2014-07-15 18:59 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Vera\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-15 18:59 - 2014-07-15 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-15 18:59 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-15 18:59 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-15 18:59 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-15 14:09 - 2014-07-15 20:26 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\ClassicShell
2014-07-15 14:09 - 2014-07-15 14:09 - 00000000 ____D () C:\ProgramData\ClassicShell
2014-07-15 14:08 - 2014-07-15 14:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2014-07-15 14:06 - 2014-07-15 14:06 - 00961360 _____ (Chip Digital GmbH) C:\Users\Vera\Downloads\Classic Shell - CHIP-Installer.exe
2014-07-14 15:58 - 2014-07-14 15:58 - 01974656 _____ (Crawler, LLC ) C:\Users\Vera\Downloads\ClassicStart8Setup.exe
2014-07-14 15:53 - 2014-07-14 15:53 - 00457944 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-14 15:05 - 2014-07-14 15:05 - 00031680 _____ () C:\ComboFix.txt
2014-07-14 14:59 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-14 14:59 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-14 14:59 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-14 14:59 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-14 14:59 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-14 14:59 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-07-14 14:59 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-14 14:59 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-14 14:59 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-14 14:58 - 2014-07-14 15:05 - 00000000 ____D () C:\Qoobox
2014-07-14 14:58 - 2014-07-14 15:04 - 00000000 ____D () C:\Windows\erdnt
2014-07-14 14:55 - 2014-07-14 14:56 - 05219590 ____R (Swearware) C:\Users\Vera\Desktop\ComboFix.exe
2014-07-13 18:04 - 2014-07-13 18:04 - 00031440 _____ () C:\Users\Vera\Desktop\Addition.txt
2014-07-13 18:03 - 2014-07-13 18:03 - 00040456 _____ () C:\Users\Vera\Desktop\FRST.txt
2014-07-13 16:01 - 2014-07-13 16:01 - 00031440 _____ () C:\Users\Vera\Downloads\Addition.txt
2014-07-13 16:00 - 2014-07-15 20:35 - 00018184 _____ () C:\Users\Vera\Downloads\FRST.txt
2014-07-13 16:00 - 2014-07-15 20:35 - 00000000 ____D () C:\FRST
2014-07-13 15:58 - 2014-07-13 15:58 - 02086912 _____ (Farbar) C:\Users\Vera\Downloads\FRST64.exe
2014-07-09 11:52 - 2014-06-18 01:27 - 01440256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 11:52 - 2014-06-18 01:24 - 01557504 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 11:52 - 2014-06-11 06:18 - 04038144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 11:52 - 2014-05-30 01:31 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-07-09 11:52 - 2014-05-30 01:03 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-07-09 11:52 - 2014-05-30 01:02 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 11:52 - 2014-05-30 01:02 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2014-07-09 11:52 - 2014-05-03 08:34 - 06974808 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-07-09 11:52 - 2014-05-03 08:33 - 01824808 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-07-09 11:52 - 2014-05-03 06:51 - 01408976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-07-09 11:52 - 2014-05-02 00:37 - 01023488 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-07-09 11:52 - 2014-04-30 00:32 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\Robocopy.exe
2014-07-09 11:52 - 2014-04-30 00:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Robocopy.exe
2014-07-09 11:52 - 2014-04-24 01:51 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-07-09 11:52 - 2014-04-24 01:51 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 11:52 - 2014-04-24 01:38 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-07-09 11:52 - 2014-04-24 01:38 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 11:52 - 2014-02-08 06:34 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-07-09 11:51 - 2014-06-19 04:12 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 11:51 - 2014-06-19 04:12 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 11:51 - 2014-06-19 04:12 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-07-09 11:51 - 2014-06-19 04:12 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-07-09 11:51 - 2014-06-19 04:12 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 11:51 - 2014-06-19 04:11 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 11:51 - 2014-06-19 04:11 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 11:51 - 2014-06-19 04:11 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 11:51 - 2014-06-19 04:10 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 11:51 - 2014-06-19 04:09 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 11:51 - 2014-06-19 02:53 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 11:51 - 2014-06-19 02:53 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 11:51 - 2014-06-19 02:53 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 11:51 - 2014-06-19 02:53 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 11:51 - 2014-06-19 02:53 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 11:51 - 2014-06-19 02:53 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 11:51 - 2014-06-19 02:53 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 11:51 - 2014-06-19 02:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 11:51 - 2014-06-19 02:52 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 11:51 - 2014-06-19 02:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 11:51 - 2014-06-19 02:30 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 11:51 - 2014-06-19 00:05 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-07-09 11:51 - 2014-06-06 16:06 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 11:51 - 2014-06-06 12:17 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 11:51 - 2014-05-30 00:24 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-07 09:50 - 2014-07-07 21:46 - 03286528 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-07-07 09:50 - 2014-07-07 21:46 - 01623040 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-07-07 09:50 - 2014-07-07 21:46 - 00773632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-07-07 09:50 - 2014-07-07 21:46 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-07-07 09:50 - 2014-07-07 21:46 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-07-07 09:50 - 2014-07-07 21:46 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-07-07 09:50 - 2014-07-07 21:46 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-07-07 09:50 - 2014-07-07 21:46 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-07-07 09:50 - 2014-07-07 21:46 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-07-07 09:49 - 2014-07-07 21:46 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-07-07 09:49 - 2014-07-07 21:46 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-07-07 09:49 - 2014-07-07 21:46 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-07-07 09:49 - 2014-07-07 21:46 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-06-29 15:13 - 2014-06-29 15:13 - 00001077 _____ () C:\Users\Vera\Desktop\Jodix Free WMA to MP3 Converter.lnk
2014-06-29 15:13 - 2014-06-29 15:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jodix
2014-06-29 15:13 - 2014-06-29 15:13 - 00000000 ____D () C:\Program Files (x86)\Free WMA to MP3 Converter
2014-06-29 15:12 - 2014-06-29 15:13 - 00948090 _____ (Jodix Technologies Ltd. ) C:\Users\Vera\Downloads\free-wma-mp3-converter.exe
2014-06-18 17:34 - 2014-06-18 17:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-17 14:58 - 2014-06-17 14:58 - 02190408 _____ (Logitech Inc.) C:\Users\Vera\Downloads\ConnectUtility.exe
2014-06-17 14:58 - 2014-06-17 14:58 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\Logitech
2014-06-17 14:58 - 2014-06-17 14:58 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\Logishrd
==================== One Month Modified Files and Folders =======
2014-07-15 20:36 - 2014-07-13 16:00 - 00018184 _____ () C:\Users\Vera\Downloads\FRST.txt
2014-07-15 20:35 - 2014-07-13 16:00 - 00000000 ____D () C:\FRST
2014-07-15 20:34 - 2014-07-15 20:32 - 00001721 _____ () C:\Users\Vera\Desktop\JRT.txt
2014-07-15 20:34 - 2013-03-21 13:47 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3047707071-1413158378-3072078544-1001
2014-07-15 20:31 - 2012-07-26 12:27 - 00852442 _____ () C:\Windows\system32\perfh007.dat
2014-07-15 20:31 - 2012-07-26 12:27 - 00200996 _____ () C:\Windows\system32\perfc007.dat
2014-07-15 20:31 - 2012-07-26 09:28 - 02010534 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-15 20:28 - 2014-07-15 20:28 - 01016261 _____ (Thisisu) C:\Users\Vera\Downloads\JRT.exe
2014-07-15 20:28 - 2014-07-15 20:28 - 00000000 ____D () C:\Windows\ERUNT
2014-07-15 20:26 - 2014-07-15 20:26 - 00004387 _____ () C:\Users\Vera\Desktop\AdwCleaner[S0].txt
2014-07-15 20:26 - 2014-07-15 14:09 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\ClassicShell
2014-07-15 20:26 - 2013-08-11 16:06 - 01563917 _____ () C:\Windows\WindowsUpdate.log
2014-07-15 20:25 - 2014-07-15 19:00 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-15 20:25 - 2014-05-14 13:25 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\DropboxMaster
2014-07-15 20:25 - 2013-03-28 13:12 - 00000000 ___RD () C:\Users\Vera\Dropbox
2014-07-15 20:25 - 2013-03-28 13:10 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\Dropbox
2014-07-15 20:24 - 2014-03-03 12:05 - 00025814 _____ () C:\Windows\PFRO.log
2014-07-15 20:24 - 2013-07-30 19:44 - 00001118 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-15 20:24 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-15 20:22 - 2014-07-15 20:21 - 00000000 ____D () C:\AdwCleaner
2014-07-15 20:22 - 2013-07-30 19:44 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-15 20:20 - 2014-07-15 20:20 - 01348263 _____ () C:\Users\Vera\Downloads\adwcleaner_3.215.exe
2014-07-15 20:20 - 2014-07-15 20:20 - 00037030 _____ () C:\Users\Vera\Desktop\mbam.txt
2014-07-15 19:13 - 2014-04-14 20:35 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\eM Client for SoftMaker
2014-07-15 19:02 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-07-15 19:00 - 2014-07-15 19:00 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-15 19:00 - 2014-07-15 19:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-15 19:00 - 2014-07-15 18:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-15 18:59 - 2014-07-15 18:59 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Vera\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-15 18:59 - 2014-07-15 18:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-15 15:26 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-07-15 14:52 - 2013-04-01 14:56 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\FileZilla
2014-07-15 14:12 - 2013-03-24 15:48 - 00000000 ____D () C:\Program Files\Classic Shell
2014-07-15 14:09 - 2014-07-15 14:09 - 00000000 ____D () C:\ProgramData\ClassicShell
2014-07-15 14:08 - 2014-07-15 14:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2014-07-15 14:06 - 2014-07-15 14:06 - 00961360 _____ (Chip Digital GmbH) C:\Users\Vera\Downloads\Classic Shell - CHIP-Installer.exe
2014-07-15 12:38 - 2013-10-14 11:18 - 01374208 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2014-07-15 12:38 - 2013-10-14 11:18 - 01245696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2014-07-15 12:38 - 2013-10-14 11:18 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2014-07-15 12:38 - 2013-10-14 11:18 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2014-07-15 12:38 - 2013-10-14 11:18 - 00437248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2014-07-15 12:38 - 2013-10-14 11:18 - 00399360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2014-07-14 16:01 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-07-14 15:58 - 2014-07-14 15:58 - 01974656 _____ (Crawler, LLC ) C:\Users\Vera\Downloads\ClassicStart8Setup.exe
2014-07-14 15:53 - 2014-07-14 15:53 - 00457944 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-14 15:05 - 2014-07-14 15:05 - 00031680 _____ () C:\ComboFix.txt
2014-07-14 15:05 - 2014-07-14 14:58 - 00000000 ____D () C:\Qoobox
2014-07-14 15:04 - 2014-07-14 14:58 - 00000000 ____D () C:\Windows\erdnt
2014-07-14 15:04 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-07-14 14:56 - 2014-07-14 14:55 - 05219590 ____R (Swearware) C:\Users\Vera\Desktop\ComboFix.exe
2014-07-14 13:00 - 2013-03-31 00:12 - 00000661 _____ () C:\Users\Vera\Documents\ax_files.xml
2014-07-14 13:00 - 2013-03-28 14:49 - 00000000 ____D () C:\Users\Public\Documents\Tintenklex11
2014-07-14 03:19 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-07-13 18:09 - 2013-03-30 23:35 - 00000000 ____D () C:\A-01
2014-07-13 18:04 - 2014-07-13 18:04 - 00031440 _____ () C:\Users\Vera\Desktop\Addition.txt
2014-07-13 18:03 - 2014-07-13 18:03 - 00040456 _____ () C:\Users\Vera\Desktop\FRST.txt
2014-07-13 16:01 - 2014-07-13 16:01 - 00031440 _____ () C:\Users\Vera\Downloads\Addition.txt
2014-07-13 15:58 - 2014-07-13 15:58 - 02086912 _____ (Farbar) C:\Users\Vera\Downloads\FRST64.exe
2014-07-10 10:24 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-10 10:24 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-10 10:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-07-10 03:14 - 2013-08-11 10:20 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-10 03:12 - 2013-03-21 14:05 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-07 21:46 - 2014-07-07 09:50 - 03286528 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-07-07 21:46 - 2014-07-07 09:50 - 01623040 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-07-07 21:46 - 2014-07-07 09:50 - 00773632 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-07-07 21:46 - 2014-07-07 09:50 - 00629248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-07-07 21:46 - 2014-07-07 09:50 - 00253440 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-07-07 21:46 - 2014-07-07 09:50 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2014-07-07 21:46 - 2014-07-07 09:50 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-07-07 21:46 - 2014-07-07 09:50 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-07-07 21:46 - 2014-07-07 09:50 - 00059416 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-07-07 21:46 - 2014-07-07 09:49 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-07-07 21:46 - 2014-07-07 09:49 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-07-07 21:46 - 2014-07-07 09:49 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-07-07 21:46 - 2014-07-07 09:49 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-07-07 15:11 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-06-29 15:13 - 2014-06-29 15:13 - 00001077 _____ () C:\Users\Vera\Desktop\Jodix Free WMA to MP3 Converter.lnk
2014-06-29 15:13 - 2014-06-29 15:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jodix
2014-06-29 15:13 - 2014-06-29 15:13 - 00000000 ____D () C:\Program Files (x86)\Free WMA to MP3 Converter
2014-06-29 15:13 - 2014-06-29 15:12 - 00948090 _____ (Jodix Technologies Ltd. ) C:\Users\Vera\Downloads\free-wma-mp3-converter.exe
2014-06-29 13:10 - 2013-03-23 23:17 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 22:53 - 2012-07-26 10:14 - 00703968 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-26 22:53 - 2012-07-26 10:14 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-19 04:12 - 2014-07-09 11:51 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-19 04:12 - 2014-07-09 11:51 - 01366528 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-19 04:12 - 2014-07-09 11:51 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-19 04:12 - 2014-07-09 11:51 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-19 04:12 - 2014-07-09 11:51 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-19 04:11 - 2014-07-09 11:51 - 19277312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-19 04:11 - 2014-07-09 11:51 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-19 04:11 - 2014-07-09 11:51 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 15369728 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 02650624 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-19 04:10 - 2014-07-09 11:51 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-19 04:09 - 2014-07-09 11:51 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-19 02:53 - 2014-07-09 11:51 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-19 02:53 - 2014-07-09 11:51 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-19 02:53 - 2014-07-09 11:51 - 01141760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-19 02:53 - 2014-07-09 11:51 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-19 02:53 - 2014-07-09 11:51 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-19 02:53 - 2014-07-09 11:51 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-19 02:53 - 2014-07-09 11:51 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 13732352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 02863616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-19 02:52 - 2014-07-09 11:51 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-19 02:52 - 2014-07-09 11:51 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-19 02:33 - 2014-07-09 11:51 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-19 02:30 - 2014-07-09 11:51 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-19 00:05 - 2014-07-09 11:51 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-06-18 17:34 - 2014-06-18 17:34 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-18 17:17 - 2013-07-30 19:44 - 00004094 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-18 17:17 - 2013-07-30 19:44 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-18 12:01 - 2013-11-06 19:25 - 00000000 ____D () C:\A-03-Studium
2014-06-18 01:27 - 2014-07-09 11:52 - 01440256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-06-18 01:24 - 2014-07-09 11:52 - 01557504 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-06-17 14:58 - 2014-06-17 14:58 - 02190408 _____ (Logitech Inc.) C:\Users\Vera\Downloads\ConnectUtility.exe
2014-06-17 14:58 - 2014-06-17 14:58 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\Logitech
2014-06-17 14:58 - 2014-06-17 14:58 - 00000000 ____D () C:\Users\Vera\AppData\Roaming\Logishrd
Some content of TEMP:
====================
C:\Users\Vera\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp5abmna.dll
C:\Users\Vera\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-10 03:05
==================== End Of Log ============================ --- --- ---
--- --- ---
Das Ding, das Combofix rausgeschmissen hat, die ClassicShell, simuliert die alte Benutzeroberfläche von Windows 7. Ich hab mir die neueste Version von Chip runtergeladen (gibts auch bei den Windows-Apps) und wieder installiert. Aber eins von den anderen Programmen hats wieder gelöscht. Kannst du erkennen, ob da wirklich ein Problem vorliegt, oder ob die Reinigungsprogramme das missinterpretieren? Ich komme mit der Windows-8-Oberfläche nämlich nicht klar.
Muss ich jetzt eigentlich davon ausgehen, dass alle meine Passwörter aufgeflogen sind und überall ändern?
Schöne Grüße
Sassa
Kommando zurück. ClassicShell ist nach Neustart wieder aufgetaucht. Bleibt also nur die Frage mit den Passwörtern.
Schönen Abend noch
Sassa |