Chris792 | 18.10.2014 00:55 | Ich habe nun alles nach Anleitung ausgeführt.
Anbei die Log-Files:
MalwareBites Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 17.10.2014
Scan Time: 19:38:50
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.09.19.05
Rootkit Database: v2014.09.18.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Chris
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 319640
Time Elapsed: 11 min, 49 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 39
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220622512223}, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644514423}, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655515523}, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666516623}, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655515523}, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666516623}, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644514423}, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\68671f62832e4803b34065d441f9a2210065123.Sandbox.1, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\68671f62832e4803b34065d441f9a2210065123.Sandbox, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\68671f62832e4803b34065d441f9a2210065123.Sandbox, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\68671f62832e4803b34065d441f9a2210065123.Sandbox.1, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622512223}, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.Senses.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220622192215}, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644194415}, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655195515}, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666196615}, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655195515}, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666196615}, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644194415}, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\CLASSES\cb53b500f3e90131a6091fb939dcadf40061915.Sandbox.1, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\CLASSES\cb53b500f3e90131a6091fb939dcadf40061915.Sandbox, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\cb53b500f3e90131a6091fb939dcadf40061915.Sandbox, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\cb53b500f3e90131a6091fb939dcadf40061915.Sandbox.1, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622192215}, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\20891, Quarantined, [3e43628d2c4fb28461e9a9832ed5817f],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, Quarantined, [2b5649a604779e9896b474b841c2dd23],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\iWebar, Quarantined, [592808e7a0dbbf77a91187cfcd37f907],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, Quarantined, [0e73c12e2f4ca096ed384ac7f310d927],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\20891, Quarantined, [6b1623cc2259a88e4cfe111bb053ad53],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21836, Quarantined, [552cdb140d6e8caa50fa54d8ea1922de],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Quarantined, [1a67bf30cbb02a0cb974fc76a46043bd],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Quarantined, [027f1dd26417e056cb639ad8c93bd729],
PUP.Optional.iWebar.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, Quarantined, [d2afe30c3b4093a36e90c76cb74c7a86],
PUP.Optional.iWebar.A, HKU\S-1-5-21-382975922-1326899409-4056930197-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, Quarantined, [9be625ca4b30fc3a40be092a56adcb35],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-382975922-1326899409-4056930197-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\20891, Quarantined, [d7aaa24d4932bc7a57625ba95fa458a8],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-382975922-1326899409-4056930197-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, Quarantined, [cdb49c534c2ffd39cdec50b4a75c5da3],
PUP.Optional.iWebar.A, HKU\S-1-5-21-382975922-1326899409-4056930197-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\iWebar, Quarantined, [7a077e71ec8f24127ff1dd58857e966a],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-382975922-1326899409-4056930197-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Object Browser, Quarantined, [3a47fef1bebdef478a9294d0f50fda26],
PUP.Optional.Softonic.A, HKU\S-1-5-21-382975922-1326899409-4056930197-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, Quarantined, [daa731be2259e650b21561c6f60d17e9],
Registry Values: 1
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [0e73c12e2f4ca096ed384ac7f310d927]
Registry Data: 0
(No malicious items detected)
Folders: 22
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Users\Chris\AppData\LocalLow\iWebar, Quarantined, [9ce5c728ccaf69cddafdc2168b774eb2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, Quarantined, [dba61ed1afcc9a9cc61222cd966cec14],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, Quarantined, [dba61ed1afcc9a9cc61222cd966cec14],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, Quarantined, [dba61ed1afcc9a9cc61222cd966cec14],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, Quarantined, [dba61ed1afcc9a9cc61222cd966cec14],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, Quarantined, [dba61ed1afcc9a9cc61222cd966cec14],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{33E3282F-C1EC-400D-A042-B770989CA00C}, Quarantined, [dba61ed1afcc9a9cc61222cd966cec14],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\defaults, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\defaults\preferences, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\userCode, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\locale, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\locale\en-US, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
Files: 187
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\53385511-d284-4bcb-bcee-b6b52521c8e3-11.exe, Quarantined, [1e63d41b2d4e5bdba4216cc66d94c23e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\53385511-d284-4bcb-bcee-b6b52521c8e3-2.exe, Quarantined, [82ff7b7425569c9a675e61d136cb758b],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\53385511-d284-4bcb-bcee-b6b52521c8e3-5.exe, Quarantined, [6c153fb0e3981d19b80d36fc31d055ab],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\53385511-d284-4bcb-bcee-b6b52521c8e3-64.exe, Quarantined, [6819618e0b70f83e903501313ec37d83],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bg.exe, Quarantined, [3c4538b73a4184b210b5d2603bc613ed],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bho.dll, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bho64.dll, Quarantined, [96eb737cde9dbf77794cd45e02ff1de3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil.exe, Quarantined, [8bf69e5198e31a1c9431230f52af22de],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil64.exe, Quarantined, [265b717e007b0333af16a38ff30e2bd5],
PUP.Optional.crossRider.A, C:\Program Files (x86)\iWebar\utils.exe, Quarantined, [a5dc8867d3a80b2b4fc972ce0000b64a],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Senses-bho.dll, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Senses-bho64.dll, Quarantined, [7b06d11e69123ef84dd3951d30d133cd],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\4696d05c-2f34-43ae-be32-b1dc97f8c184-11.exe, Quarantined, [daa73fb083f870c6aa76704222df5ba5],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\4696d05c-2f34-43ae-be32-b1dc97f8c184-3.exe, Quarantined, [daa7da15007bb38378a8b6fccf321ae6],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\4696d05c-2f34-43ae-be32-b1dc97f8c184-4.exe, Quarantined, [4e337976443783b327f93a780cf503fd],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\4696d05c-2f34-43ae-be32-b1dc97f8c184-5.exe, Quarantined, [453ca7488eed0135ac74fcb6ff027c84],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\4696d05c-2f34-43ae-be32-b1dc97f8c184-6.exe, Quarantined, [daa736b983f859dd21ff684ac83925db],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\4696d05c-2f34-43ae-be32-b1dc97f8c184-64.exe, Quarantined, [ceb36887c7b4152168b87b3739c89868],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\4696d05c-2f34-43ae-be32-b1dc97f8c184-7.exe, Quarantined, [463b5b94b8c339fd2df36e4459a86f91],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Senses-bg.exe, Quarantined, [b8c924cb6615a195c25e0fa327dac23e],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Senses-buttonutil.exe, Quarantined, [9be622cdaccf102629f7377b37ca29d7],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Senses-buttonutil64.exe, Quarantined, [97ea0be4c2b9092d1f01eac8c23fe51b],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Senses-codedownloader.exe, Quarantined, [0180a946c0bb6bcba37d793924ddad53],
PUP.Optional.crossRider.A, C:\Program Files (x86)\Senses\utils.exe, Quarantined, [4a37af40097273c3ac6cbb85c43c8878],
PUP.Optional.GoobZo, C:\Users\Chris\AppData\Local\Installer\Installiwebar_28528\delay.exe, Quarantined, [a5dcae416d0e2016576f06eb22e27e82],
PUP.Optional.GoobZo, C:\Users\Chris\AppData\Local\Installer\Installsense_28095\delay.exe, Quarantined, [f28fc728bac1f6403a8ccb26e321bf41],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\background.html, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\1293297481.mxaddon, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\4696d05c-2f34-43ae-be32-b1dc97f8c184.crx, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\4696d05c-2f34-43ae-be32-b1dc97f8c184.xpi, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\64b8168d-d368-4f6b-93ff-fb57e8a4b674.crx, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\9b6b6e4f-c233-41cb-b9a6-5390dc73c9fd.crx, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\bgNova.html, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Senses-buttonutil.dll, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Senses-buttonutil64.dll, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Senses.ico, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.Senses.A, C:\Program Files (x86)\Senses\Uninstall.exe, Quarantined, [334ef0ff5d1e092dca3df3162fd45ea2],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-1, Quarantined, [94ed27c81c5f063025fba56c4cb7b44c],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-11, Quarantined, [a5dc31be700b3105a67a3cd5996afa06],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-3, Quarantined, [225fb33cdf9cfe38f62aea2728db926e],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-4, Quarantined, [354cc22d2853072f958b828f768df10f],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-5, Quarantined, [414038b7f685b28449d70a07bb48916f],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-5_user, Quarantined, [8af7549b4c2fc96de53b25ec798a8080],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-6, Quarantined, [ea979758c5b6d363a37dd041ba49c937],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-7, Quarantined, [0180f8f75a213df917098f82eb18956b],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\53385511-d284-4bcb-bcee-b6b52521c8e3-11, Quarantined, [bfc2f2fdb9c286b0b0700d04c142ce32],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\53385511-d284-4bcb-bcee-b6b52521c8e3-2, Quarantined, [740d2ec14f2ce650cb552ce5fe05f50b],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\53385511-d284-4bcb-bcee-b6b52521c8e3-5, Quarantined, [4b36816efb807fb7cf51858c2dd641bf],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\53385511-d284-4bcb-bcee-b6b52521c8e3-5_user, Quarantined, [f1900ce35724dc5a36ea1af75ea521df],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\background.html, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\1293297481.mxaddon, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\1a2f7a77-f02f-4409-9091-dd132ebc2f4c.crx, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\53385511-d284-4bcb-bcee-b6b52521c8e3.crx, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\53385511-d284-4bcb-bcee-b6b52521c8e3.xpi, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\bgNova.html, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil.dll, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil64.dll, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar.ico, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\Uninstall.exe, Quarantined, [e69b846b37440b2bbbfdf561c143b749],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-1.job, Quarantined, [324f628df98251e5b3f2541bee16817f],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-11.job, Quarantined, [b7caa847dba049ed980d056acc387f81],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-3.job, Quarantined, [ccb58f604e2de1550c99f37c21e33ec2],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-4.job, Quarantined, [3e4327c8fb8023134f5699d6ac581ce4],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-5.job, Quarantined, [463b05ea314a8ea830757ff0dd275ca4],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-5_user.job, Quarantined, [0081fcf389f276c08d184a25af55946c],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-6.job, Quarantined, [e29fdc1339421026990ce68953b1c13f],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\4696d05c-2f34-43ae-be32-b1dc97f8c184-7.job, Quarantined, [2f52915e3d3eca6caef7c5aabc48bc44],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\53385511-d284-4bcb-bcee-b6b52521c8e3-11.job, Quarantined, [84fd4aa52e4d51e5089d79f611f37d83],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\53385511-d284-4bcb-bcee-b6b52521c8e3-2.job, Quarantined, [c9b8ba353942270f4c59125d19ebf709],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\53385511-d284-4bcb-bcee-b6b52521c8e3-5.job, Quarantined, [800142ad94e7bc7abfe63a35f1136e92],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\53385511-d284-4bcb-bcee-b6b52521c8e3-5_user.job, Quarantined, [8ef3529d85f6979f51549dd28d77aa56],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome.manifest, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\install.rdf, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\257572ad8e80dbc696d34d8e3c3768a0.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\60505addc8adf9537521673f78cda741.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\82c4d4d23617edec75e0134f06b16b79.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\background.html, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\bcff9a2db65bf2194b345f9989a55b5a.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\browser.xul, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\dialog.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\e192902fadc0348c56d9bc43655c931a.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\ec99f0666f6ea163a82017cd4c69e0e8.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\ffCoreFilesIndex.txt, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\options.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\options.xul, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\search_dialog.xul, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\22e7f6425bfe3545715758d527af9f69.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\7974916360cf3cf50bee1d39a5f379e0.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\7c58afff6a2f2ee3508d9f1400259354.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\8f4fac5fe31d653b464719f89fa9baee.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\93223383b389ac3b0469b37639d4ee6c.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\a811ccebeff3c64078de58fa3df0eff5.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\afae649f09f20d42fcde5ca6d09f7d87.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\c1822905f61470a2b5494cde24b05500.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\cff70a8cf85b25b5f604e80de6d2024d.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\dad61f127eeaa71915c41785bda26a20.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\daf901bb0e9b55ce24ed9facbd7cf5c0.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\e30e7acae9f80c25ea695d021ed63a6d.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\e4d509279f6526e84f39de4d37869b3b.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\eb875a7a13d080bac3161cf46f1d9ad7.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\f2e9732f7e5a9dd21bb676efb44696c4.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\api\f78b172734801cf4072b7eb4087bc986.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\0364472ef8c814e6fce811cb10e8c9ac.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\070e7b68f345ea0f655d4b09f25289d8.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\0831108ab7fceb990b5009609296bfb9.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\1f3298021c7474d67cbaee141117975e.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\200918703f04e10b56c8e7edd7a12d6e.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\28282577da88a45071880304e2899bdc.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\45f1a18c64c8f9da4edff293ca376d41.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\8181d2702b6318d20a0e7742faf3ddeb.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\9c1ce30aa76a99e88fb3e8d91df3e908.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\a1825d9d6dbd4e615e72df0986a239e9.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\a5e78c9376116c83373065e534a7524f.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\a82ebe43a2b99a42544ddee1631af682.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\cb2744645362940f13329cf3a097a253.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\d185a25ee43c131eb7fa9f9f5cfa11c9.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\d5483cc98c97a7c413e955b4a430b73c.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\dbbec850d3e0ad21a5ba132530c95578.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\dc9402c541e21b591b927474cb7bae5c.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\e40b1481d133f2d593fe615e624ea698.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\f12c71256b433217b3ef7fe5d916d003.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\fa803f74c0f9f43e2b98c8789b48f719.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\chrome\content\core\installer.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\defaults\preferences\prefs.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\manifest.xml, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins.json, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\223.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\1.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\102.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\104.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\123.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\13.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\14.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\16.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\17.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\177.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\180.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\182.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\183.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\184.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\192.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\193.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\195.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\207.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\21.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\22.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\220.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\221.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\226.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\239.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\244.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\246.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\262.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\263.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\268.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\273.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\28.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\281.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\288.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\300.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\4.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\47.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\64.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\7.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\72.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\78.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\9.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\91.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\plugins\98.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\userCode\background.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\extensionData\userCode\extension.js, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\locale\en-US\translations.dtd, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\button1.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\button2.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\button3.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\button4.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\button5.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\crossrider_statusbar.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\icon128.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\icon16.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\icon24.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\icon48.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\panelarrow-up.png, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\popup.html, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\skin.css, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\extensions\warnerroberts@hotmail.com\skin\update.css, Quarantined, [ed94767995e69b9b11bb52a427db8d73],
PUP.Optional.CrossRider.A, C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\prefs.js, Good: (), Bad: (user_pref("extensions.crossrider.bic", "148ea6328f4af0fd8a0d2efebbf55af7");), Replaced,[770ab43badcecd696a7c3800dd28ac54]
Physical Sectors: 0
(No malicious items detected)
(end) AdwCleaner
AdwCleaner Logfile: Code:
# AdwCleaner v4.000 - Bericht erstellt am 17/10/2014 um 20:11:44
# DB v2014-10-17.9
# Aktualisiert 12/10/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : Chris - CHRIS-PC
# Gestartet von : C:\Users\Chris\Downloads\AdwCleaner_4.000.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : YouTubeAcceleratorService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Users\Chris\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Chris\AppData\LocalLow\Goobzo
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
Ordner Gelöscht : C:\ProgramData\YTAHelper
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{58FDA6AF-67D8-4198-B7CD-94B17532C8D5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{8FB1A663-2820-468B-95C4-5060A4C5F413}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FCE3FA8B-BA81-467C-81D8-E43C00D1BC71}
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\Goobzo
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\Goobzo
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\iWebar-nv
Schlüssel Gelöscht : HKLM\SOFTWARE\Senses-nv
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\iWebar-nv
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Senses-nv
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17280
-\\ Mozilla Firefox v32.0.3 (x86 de)
[oib0uo3x.default] - Zeile gelöscht : user_pref("extensions.aROUAILDE73397174UXGZI17268980com65123.65123.internaldb.Resources_meta.value", "%7B%22handlebars.js%22%3A%7B%22id%22%3A838651%2C%22ver%22%3A1%2C%22status%22%3A1%2C%22name%22%3A%2[...]
[oib0uo3x.default] - Zeile gelöscht : user_pref("extensions.aROUAILDE73397174UXGZI17268980com65123.65123.internaldb.Resources_resource_838660.value", "%22function%20startAskCom%28e%2Ct%2Cr%29%7Bfunction%20a%28e%29%7Bvar%20t%3Dnew%20RegExp[...]
[oib0uo3x.default] - Zeile gelöscht : user_pref("extensions.aROUAILDE73397174UXGZI17268980com65123.65123.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22[...]
[oib0uo3x.default] - Zeile gelöscht : user_pref("extensions.awarnerrobertshotmailcom61915.61915.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22dealply_p%22%3A%7B%22[...]
[oib0uo3x.default] - Zeile gelöscht : user_pref("extensions.crossrider.bic", "148ea6328f4af0fd8a0d2efebbf55af7");
*************************
AdwCleaner[R0].txt - [7144 octets] - [17/10/2014 20:05:31]
AdwCleaner[S0].txt - [6821 octets] - [17/10/2014 20:11:44]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6881 octets] ########## --- --- ---
[/CODE]
JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.14.2014:1)
OS: Windows 7 Professional x64
Ran by Chris on 17.10.2014 at 20:16:44,70
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.10.2014 at 20:25:28,66
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST_fresh
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014
Ran by Chris (administrator) on CHRIS-PC on 17-10-2014 20:41:18
Running from C:\Users\Chris\Desktop
Loaded Profile: Chris (Available profiles: Chris)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(AVAST Software) C:\Software\avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(TeamViewer GmbH) C:\Software\Teamviewer\TeamViewer_Service.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(AVAST Software) C:\Software\avast\avastui.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE
(Mozilla Corporation) C:\Software\Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Lenovo) C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-04-24] (Synaptics Incorporated)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [557768 2014-09-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [113656 2013-01-17] (Intel Corporation)
HKLM-x32\...\Run: [PWMTRV] => rundll32 "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL",PwrMgrBkGndMonitor
HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Software\avast\AvastUI.exe [4085896 2014-10-01] (AVAST Software)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694320 2014-10-01] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Software\avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x41A7228DDD84CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: No Name -> {11111111-1111-1111-1111-110611191115} -> No File
BHO: No Name -> {11111111-1111-1111-1111-110611511123} -> No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Software\avast\aswWebRepIE64.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Software\avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 172.20.0.10 200.69.24.10
FireFox:
========
FF ProfilePath: C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Extension: Adblock Plus - C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\oib0uo3x.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-07]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Software\avast\WebRep\FF
FF Extension: avast! Online Security - C:\Software\avast\WebRep\FF [2014-10-01]
FF StartMenuInternet: FIREFOX.EXE - C:\Software\Firefox\firefox.exe
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Software\avast\WebRep\Chrome\aswWebRepChrome.crx [2014-10-01]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Software\avast\AvastSvc.exe [50344 2014-10-01] (AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2428088 2014-08-12] (Microsoft Corporation)
S3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [320560 2014-03-20] (Lenovo.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-17] ()
R2 TeamViewer9; C:\Software\Teamviewer\TeamViewer_Service.exe [5052224 2014-08-06] (TeamViewer GmbH)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-01-17] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-10-01] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-10-01] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-10-01] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-10-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-10-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-10-01] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-10-01] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-10-01] ()
S1 funfrm; C:\Windows\SysWow64\Drivers\funfrm.sys [53136 2014-08-02] ()
R1 LUMDriver; C:\Windows\system32\drivers\LUMDriver.sys [24848 2008-01-02] (IBM)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-17 20:39 - 2014-10-17 20:39 - 02112000 _____ (Farbar) C:\Users\Chris\Desktop\FRST64.exe
2014-10-17 20:25 - 2014-10-17 20:26 - 00000625 _____ () C:\Users\Chris\Desktop\JRT.txt
2014-10-17 20:16 - 2014-10-17 20:16 - 00000000 ____D () C:\Windows\ERUNT
2014-10-17 20:14 - 2014-10-17 20:14 - 00006977 _____ () C:\Users\Chris\Desktop\AdwCleaner[S0].txt
2014-10-17 20:04 - 2014-10-17 20:12 - 00000000 ____D () C:\AdwCleaner
2014-10-17 19:58 - 2014-10-17 19:58 - 00046952 _____ () C:\Users\Chris\Desktop\mbam.txt
2014-10-17 19:26 - 2014-10-17 19:26 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-17 19:26 - 2014-10-17 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-17 19:25 - 2014-10-17 19:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-17 19:25 - 2014-10-17 19:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-17 19:25 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-17 19:25 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-17 19:25 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-16 20:24 - 2014-10-16 20:23 - 01705698 _____ (Thisisu) C:\Users\Chris\Downloads\JRT.exe
2014-10-16 20:24 - 2014-10-16 20:20 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Chris\Downloads\mbam-setup-2.0.3.1025.exe
2014-10-16 20:24 - 2014-10-16 20:20 - 01976320 _____ () C:\Users\Chris\Downloads\AdwCleaner_4.000.exe
2014-10-14 14:06 - 2014-10-14 14:06 - 00000000 ____D () C:\Users\Chris\Documents\Adobe
2014-10-14 14:04 - 2014-10-14 14:04 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2014-10-14 13:38 - 2014-10-14 13:38 - 00002035 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Lightroom 5.6 64-bit.lnk
2014-10-14 13:38 - 2014-10-14 13:38 - 00002015 _____ () C:\Users\Public\Desktop\Lightroom 5.6 64-bit.lnk
2014-10-14 13:38 - 2014-10-14 13:38 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-10-14 13:36 - 2014-10-14 13:36 - 00000000 ____D () C:\Program Files\Adobe
2014-10-14 12:56 - 2014-10-14 12:56 - 00000000 ___RD () C:\Users\Chris\Creative Cloud Files
2014-10-14 12:51 - 2014-10-14 13:38 - 00000000 ____D () C:\ProgramData\Adobe
2014-10-14 12:50 - 2014-10-14 12:50 - 00001309 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2014-10-14 12:50 - 2014-10-14 12:50 - 00001297 _____ () C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2014-10-14 12:50 - 2014-10-14 12:50 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-10-14 12:41 - 2014-10-14 12:41 - 00672432 _____ (Adobe Systems Incorporated) C:\Users\Chris\Downloads\CreativeCloudSet-Up.exe
2014-10-14 12:09 - 2014-10-14 12:09 - 00026656 _____ () C:\Users\Chris\Desktop\ComboFix.txt
2014-10-14 11:49 - 2014-10-14 12:09 - 00000000 ____D () C:\Qoobox
2014-10-14 11:49 - 2014-10-14 12:05 - 00000000 ____D () C:\Windows\erdnt
2014-10-14 11:49 - 2011-06-26 03:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-14 11:49 - 2010-11-07 14:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-14 11:49 - 2009-04-20 01:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-14 11:49 - 2000-08-30 21:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-14 11:49 - 2000-08-30 21:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-14 11:49 - 2000-08-30 21:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-14 11:49 - 2000-08-30 21:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-14 11:49 - 2000-08-30 21:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-09 21:54 - 2014-10-09 21:55 - 00000000 ____D () C:\.Trash-999
2014-10-09 18:47 - 2014-10-09 18:48 - 00031506 _____ () C:\Users\Chris\Desktop\Addition.txt
2014-10-09 18:45 - 2014-10-17 20:42 - 00013347 _____ () C:\Users\Chris\Desktop\FRST.txt
2014-10-09 18:45 - 2014-10-17 20:41 - 00000000 ____D () C:\FRST
2014-10-08 23:14 - 2014-10-08 23:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image Writer
2014-10-06 20:02 - 2014-10-06 20:07 - 00000576 _____ () C:\Users\Chris\Desktop\MonitorOff.lnk
2014-10-06 11:38 - 2014-10-06 11:38 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Macromedia
2014-10-06 11:38 - 2014-10-06 11:38 - 00000000 ____D () C:\Users\Chris\AppData\Local\Macromedia
2014-10-06 10:37 - 2014-10-06 10:37 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-06 10:37 - 2014-10-06 10:37 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-06 10:37 - 2014-10-06 10:37 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-10-06 10:37 - 2014-10-06 10:37 - 00000000 ____D () C:\Windows\system32\Macromed
2014-10-06 10:36 - 2014-10-17 12:38 - 00000000 ____D () C:\Users\Chris\AppData\Local\Adobe
2014-10-06 10:09 - 2014-10-06 10:09 - 03453440 _____ () C:\Users\Chris\Downloads\Programacion_control_y_ejecucion_del_movimiento_2008.ppt
2014-10-05 10:35 - 2014-10-05 10:35 - 00000083 _____ () C:\Users\Chris\Desktop\Zitatesammlung.txt
2014-10-05 09:25 - 2014-10-17 20:36 - 00002083 _____ () C:\Windows\setupact.log
2014-10-05 09:25 - 2014-10-17 20:13 - 00078472 _____ () C:\Windows\PFRO.log
2014-10-05 09:25 - 2014-10-05 09:25 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-04 11:20 - 2014-10-04 11:20 - 00000000 ____D () C:\Windows\pss
2014-10-04 11:15 - 2014-10-04 11:15 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Mozilla
2014-10-04 11:15 - 2014-10-04 11:15 - 00000000 ____D () C:\Users\Chris\AppData\Local\Mozilla
2014-10-04 11:13 - 2014-10-04 11:13 - 00000000 ____D () C:\ProgramData\Mozilla
2014-10-04 11:13 - 2014-10-04 11:13 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-02 21:32 - 2014-10-02 21:32 - 00000000 ____D () C:\Users\Chris\Desktop\Asimov_Foundation
2014-10-02 14:09 - 2014-10-02 14:09 - 00007607 _____ () C:\Users\Chris\AppData\Local\Resmon.ResmonCfg
2014-10-02 08:36 - 2014-10-02 08:36 - 00028250 _____ () C:\Users\Chris\Documents\bookmarks_02.10.14.html
2014-10-01 12:05 - 2014-10-01 12:05 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\AVAST Software
2014-10-01 11:56 - 2014-10-01 11:56 - 00001678 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-10-01 11:56 - 2014-10-01 11:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast
2014-10-01 11:55 - 2014-10-17 20:00 - 00004142 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-10-01 11:55 - 2014-10-01 11:56 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-10-01 11:55 - 2014-10-01 11:55 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-10-01 11:55 - 2014-10-01 11:55 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-10-01 11:55 - 2014-10-01 11:55 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-10-01 11:55 - 2014-10-01 11:55 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-10-01 11:55 - 2014-10-01 11:55 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-10-01 11:55 - 2014-10-01 11:55 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-10-01 11:55 - 2014-10-01 11:55 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-10-01 11:55 - 2014-10-01 11:55 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-10-01 11:55 - 2014-10-01 11:55 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-10-01 10:50 - 2014-10-01 10:50 - 00001012 _____ () C:\Users\Chris\Desktop\calibre.lnk
2014-10-01 10:38 - 2014-09-24 23:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-01 10:38 - 2014-09-24 22:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-10-01 01:10 - 2014-10-01 01:10 - 00000000 ____D () C:\Program Files (x86)\Skype
2014-09-30 23:59 - 2014-09-30 23:59 - 00002984 _____ () C:\Windows\System32\Tasks\{C54A89D8-F4E2-4DEC-87BB-9CF0AD7C93E2}
2014-09-30 22:22 - 2014-09-30 23:14 - 00000000 ____D () C:\ProgramData\TEMP
2014-09-30 22:21 - 2014-09-30 22:21 - 00172032 _____ (Jin Hui E-mail: jinhui@jcomsoft.com Web: hxxp://www.jcomsoft.com) C:\Windows\SysWOW64\AniGIF.ocx
2014-09-30 22:21 - 2014-09-30 22:21 - 00000000 ____D () C:\Users\Chris\AppData\Local\CrashRpt
2014-09-30 22:21 - 2014-09-30 22:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project 64 2.0
2014-09-30 16:08 - 2014-10-14 16:24 - 00000000 ____D () C:\Users\Chris\Documents\Buchprojekt
2014-09-30 14:24 - 2014-10-01 01:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-09-30 14:15 - 2014-09-30 14:16 - 06004224 _____ () C:\Users\Chris\Downloads\SintNuc1.ppt
2014-09-30 14:15 - 2014-09-30 14:15 - 05917987 _____ () C:\Users\Chris\Downloads\SintNuc1.pptx
2014-09-29 10:32 - 2014-09-29 10:32 - 04305874 _____ () C:\Users\Chris\Downloads\X-Plane10DemoInstallerWindows.zip
2014-09-23 18:05 - 2014-09-09 19:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-23 18:05 - 2014-09-09 18:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-17 10:51 - 2014-09-17 10:51 - 00001113 _____ () C:\Users\Chris\Downloads\matlab2.m
2014-09-17 10:51 - 2014-09-17 10:51 - 00000592 _____ () C:\Users\Chris\Downloads\simulation.m
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-17 20:40 - 2011-04-12 04:43 - 00699134 _____ () C:\Windows\system32\perfh007.dat
2014-10-17 20:40 - 2011-04-12 04:43 - 00149242 _____ () C:\Windows\system32\perfc007.dat
2014-10-17 20:40 - 2009-07-14 02:13 - 01618440 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-17 20:39 - 2014-07-17 17:41 - 00000498 ____H () C:\Windows\Tasks\MATLAB R2014a Startup Accelerator.job
2014-10-17 20:36 - 2014-06-10 14:46 - 02039422 _____ () C:\Windows\WindowsUpdate.log
2014-10-17 20:36 - 2009-07-14 02:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-17 20:20 - 2009-07-14 01:45 - 00032080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-17 20:20 - 2009-07-14 01:45 - 00032080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-17 19:49 - 2014-06-16 14:50 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Skype
2014-10-17 19:29 - 2014-08-03 17:40 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\ViberPC
2014-10-17 19:29 - 2014-08-03 17:28 - 00000000 ____D () C:\Users\Chris\AppData\Local\Viber
2014-10-17 12:42 - 2014-09-13 23:17 - 00000000 ____D () C:\Users\Chris\Documents\MATLAB
2014-10-14 22:10 - 2014-08-04 17:33 - 00000000 ___RD () C:\Users\Chris\Dropbox
2014-10-14 22:09 - 2014-08-04 17:28 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Dropbox
2014-10-14 16:39 - 2014-08-31 07:55 - 00000000 ____D () C:\Users\Chris\Desktop\Fotos_temp
2014-10-14 16:30 - 2014-06-10 15:43 - 00000000 ____D () C:\Software
2014-10-14 14:06 - 2014-06-23 14:37 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Adobe
2014-10-14 12:56 - 2014-06-10 14:46 - 00000000 ____D () C:\Users\Chris
2014-10-14 12:50 - 2014-06-10 15:35 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-14 12:09 - 2009-07-14 00:20 - 00000000 __RHD () C:\Users\Default
2014-10-14 12:04 - 2009-07-13 23:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-09 11:02 - 2014-08-25 10:40 - 00000000 ____D () C:\Users\Chris\Desktop\Raspberry Pi
2014-10-09 02:25 - 2014-09-16 22:47 - 00000324 _____ () C:\Users\Chris\Desktop\todo.txt
2014-10-08 12:03 - 2014-07-19 16:42 - 00000464 _____ () C:\Users\Chris\Desktop\bbb.txt
2014-10-06 22:59 - 2009-07-14 00:20 - 00000000 ____D () C:\Windows\rescache
2014-10-04 11:19 - 2014-06-10 15:41 - 00000000 ____D () C:\Users\Chris\AppData\Local\Google
2014-10-04 11:19 - 2014-06-10 15:41 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-03 12:53 - 2014-08-26 23:06 - 00000000 ____D () C:\Users\Chris\Documents\Uni BsAs
2014-10-01 11:54 - 2014-06-10 15:39 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-10-01 11:44 - 2014-06-16 14:50 - 00000000 ____D () C:\ProgramData\Skype
2014-10-01 11:15 - 2014-08-31 19:20 - 00000000 ____D () C:\Users\Chris\Documents\Calibre-Bibliothek
2014-10-01 10:39 - 2014-09-09 18:24 - 00000207 _____ () C:\Users\Chris\Desktop\goodtoknow.txt
2014-10-01 10:19 - 2009-07-14 00:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-30 23:17 - 2014-06-10 15:51 - 00000075 _____ () C:\Users\Chris\Desktop\Programme.txt
2014-09-28 12:29 - 2014-07-17 16:52 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-09-20 01:11 - 2014-08-04 17:33 - 00001017 _____ () C:\Users\Chris\Desktop\Dropbox.lnk
2014-09-20 01:11 - 2014-08-04 17:31 - 00000000 ____D () C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
Some content of TEMP:
====================
C:\Users\Chris\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp8nmmdh.dll
C:\Users\Chris\AppData\Local\Temp\Quarantine.exe
C:\Users\Chris\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-06 22:52
==================== End Of Log ============================ --- --- --- |