Hier: mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 04.12.2014
Suchlauf-Zeit: 19:47:32
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.12.04.08
Rootkit Datenbank: v2014.12.03.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Henoch
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 404768
Verstrichene Zeit: 43 Min, 48 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 3
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\jcdgjdiieiljkfkdcloehkohchhpekkn, , [17c11549dca0cb6b6d9289daf013c739],
PUP.Optional.FindADeal.A, HKU\S-1-5-21-3995798047-183456226-2512991475-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\find-a-deal-2, , [4d8bd48a205c70c65034e38f0cf7e41c],
PUP.Optional.SystemK.A, HKU\S-1-5-21-3995798047-183456226-2512991475-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SystemK, , [ecec65f9f686d75f23ab97cf689b07f9],
Registrierungswerte: 1
Trojan.Winminer, HKU\S-1-5-21-3995798047-183456226-2512991475-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|wm, C:\Users\Henoch\AppData\Local\Temp\wm.exe, , [0dcb0f4f9edea49249a3e7199e640af6]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 2
PUP.Optional.Conduit.A, C:\Users\Henoch\AppData\Local\Temp\TestIfExeExist\CT3312806, , [15c3f36bd9a314225bd1e03ba65dfa06],
PUP.Optional.Conduit.A, C:\Users\Henoch\AppData\Local\Temp\TestIfExeExist\CT3312806\nativeMessaging, , [15c3f36bd9a314225bd1e03ba65dfa06],
Dateien: 14
Trojan.Winminer, C:\Users\Henoch\AppData\Local\Temp\wm.exe, , [0dcb0f4f9edea49249a3e7199e640af6],
PUP.Optional.Softonic.A, C:\Users\Henoch\AppData\Local\Temp\Softonic_DE_1-5-10_DE-Production_10_CleanRelease.exe, , [e8f0aeb073097db96e7b94287d848d73],
Riskware.BitcoinMiner, C:\Users\Henoch\AppData\Local\Temp\32\wincpu.exe, , [f3e55fff116b77bf4c955c0108f921df],
PUP.Optional.AztecMedia.A, C:\Users\Henoch\AppData\Local\Temp\nspCD70.tmp\Helper.dll, , [b42483dbf08ce84ef3903003cc3915eb],
PUP.Optional.AztecMedia.A, C:\Users\Henoch\AppData\Local\Temp\nspCD70.tmp\Starter.exe, , [01d7cb933e3eb77f81f369cae124e11f],
PUP.Optional.AztecMedia.A, C:\Users\Negede\AppData\Local\Temp\nsaC2B7.tmp\Helper.dll, , [61775a04cdaff145c8bba29117eeda26],
PUP.Optional.AztecMedia.A, C:\Users\Negede\AppData\Local\Temp\nsaC2B7.tmp\Starter.exe, , [10c8025c4f2d201643319a9937ce13ed],
PUP.Optional.Linkey.A, C:\Windows\Temp\61176dd6\SettingsManagerSetup.exe, , [74640658ccb0b97d7eb3386bf20fdb25],
PUP.Optional.Linkey.A, C:\Windows\Temp\cd6075b9\SettingsManagerSetup.exe, , [fbdd4519d4a861d5929f7033b94809f7],
PUP.Optional.Iminent.A, C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage, , [5880cb93106c80b6c49f77f835ce29d7],
PUP.Optional.Wajam.A, C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.wajam.com_0.localstorage, , [0dcb1b43aece91a54321a5ca6b98c53b],
PUP.Optional.Wajam.A, C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.wajam.com_0.localstorage-journal, , [8652b5a97705072f82e27df249ba946c],
PUP.Optional.Conduit.A, C:\Users\Henoch\AppData\Local\Temp\TestIfExeExist\CT3312806\nativeMessaging\TBMessagingHost.exe, , [15c3f36bd9a314225bd1e03ba65dfa06],
PUP.Optional.DefaultSearch.A, C:\Users\Henoch\AppData\Roaming\Mozilla\Firefox\Profiles\5wimzc6q.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12692&tm=319&src=ds&p=");), ,[2cacf16da4d8dc5ad0f20b8d0df84eb2]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Hier: Adw Cleaner bei dem gab es 3 poste einfach mal alle Code:
# AdwCleaner v4.103 - Bericht erstellt am 04/12/2014 um 20:42:49
# Aktualisiert 01/12/2014 von Xplode
# Database : 2014-12-03.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Henoch - HENOCH-VAIO
# Gestartet von : C:\Users\Henoch\Downloads\AdwCleaner_4.103.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : iSafeKrnl
Dienst Gefunden : iSafeKrnlBoot
Dienst Gefunden : iSafeKrnlKit
Dienst Gefunden : iSafeKrnlR3
Dienst Gefunden : iSafeNetFilter
Dienst Gefunden : iSafeService
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage
Datei Gefunden : C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage
Datei Gefunden : C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage-journal
Datei Gefunden : C:\Users\Henoch\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\YAC.lnk
Datei Gefunden : C:\Users\Henoch\AppData\Roaming\Mozilla\Firefox\Profiles\5wimzc6q.default\user.js
Datei Gefunden : C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gefunden : C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
Datei Gefunden : C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gefunden : C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gefunden : C:\Windows\System32\drivers\iSafeKrnlBoot.sys
Datei Gefunden : C:\Windows\System32\log\iSafeKrnlCall.log
Ordner Gefunden : C:\Program Files (x86)\Elex-tech
Ordner Gefunden : C:\ProgramData\iolo
Ordner Gefunden : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC
Ordner Gefunden : C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko
Ordner Gefunden : C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
Ordner Gefunden : C:\Users\Henoch\AppData\Local\CrashRpt
Ordner Gefunden : C:\Users\Henoch\AppData\Local\Temp\iSafeRightKeyScan
Ordner Gefunden : C:\Users\Henoch\AppData\Roaming\Elex-tech
Ordner Gefunden : C:\Users\Henoch\AppData\Roaming\iolo
Ordner Gefunden : C:\Users\Henoch\AppData\Roaming\Mozilla\Firefox\Profiles\5wimzc6q.default\Extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0}
Ordner Gefunden : C:\Users\Negede\AppData\Local\Temp\iSafeRightKeyScan
Ordner Gefunden : C:\Users\Negede\AppData\Roaming\Elex-tech
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Toolbar.CT2481020
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{c3e85ee9-5892-4142-b537-bceb3dac4c3d}
Schlüssel Gefunden : HKLM\SOFTWARE\SweetIM
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{5411D116-5A37-47D4-B154-5F7FCD9062F0}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75FF6D97AF9FC004A9521D4B83FA6321
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB13D869D7D092348847B7481BB59E27
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EE58E3C298524145B73CBBED3CAC4D3
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17420
-\\ Mozilla Firefox v26.0 (de)
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.affiliate_id", "3553");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.firstrun", "false");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.log_send_info", "false");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.mappingListJsonString", "{\"version\":\"0.21088\",\"update_interval\":919,\"base_url\":\"hxxp:\\/\\/www.wajam.com\\/\",\"update_url\":\"hxxp:\\/\\/www.wajam.com\\/addon\\/m[...]
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.no_trace", "false");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.server_current_mapping_version", "0.21088");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.supported_sites.wajam_settings.wajam_utils", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam'[...]
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.trace_log", "1387712400312 - processInstallationUpgrade - version set to : 1.26\n1387712400312 - processBrowserLoad - Bad mappingListJsonString: null\n1387712401514 - onFla[...]
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.unique_id", "F7F6B7E9228251FB3D6200B04F855D42");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.user_current_mapping_version", "0");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.version", "1.26");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.LayoutId", "1");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.ShowThankyouPixel", "0");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.adapters", "{\"facebook\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Status\":1,\"expireTime\":\"1387712427052259200\"}}");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.enabledAds", "false");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent109", "1387712430303");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent110", "1387712448132");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent111", "1387712430307");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent112", "1387712430369");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent122", "1387712430312");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.version", "7.50.3.1");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.50.3.1\",\"InstallEventCTime\":1387712399836,\"InstallEvent\":\"True\"}");
[5wimzc6q.default] - Zeile gefunden : user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12692&tm=319&src=ds&p=");
-\\ Google Chrome v39.0.2171.71
[C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://anisearch.de/?page=suche&mode=auswahl&qsearch={searchTerms}
[C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
[C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=319&src=ds&p={searchTerms}
[C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=319&src=ds&p={searchTerms}
-\\ Comodo Dragon v
[C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://search.ask.com/web?o=APN10257&doi=2014-07-05&apn_dtid=%5ECMD011%5EYY%5EUS&apn_ptnrs=%5EAGO&q={searchTerms}
[C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\preferences] - Gefunden [Extension] : cmaiofennmphjldldcpphcechfnnohja
[C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\preferences] - Gefunden [Extension] : aaaalipaokhkccgmgkdglfinfnfhflko
*************************
AdwCleaner[R0].txt - [14251 octets] - [04/12/2014 20:42:49]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [14312 octets] ########## Code:
# AdwCleaner v4.103 - Bericht erstellt am 04/12/2014 um 20:56:21
# Aktualisiert 01/12/2014 von Xplode
# Database : 2014-12-03.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Henoch - HENOCH-VAIO
# Gestartet von : C:\Users\Henoch\Downloads\AdwCleaner_4.103.exe
# Option : Suchen
***** [ Dienste ] *****
Dienst Gefunden : iSafeKrnl
Dienst Gefunden : iSafeKrnlBoot
Dienst Gefunden : iSafeKrnlKit
Dienst Gefunden : iSafeKrnlR3
Dienst Gefunden : iSafeNetFilter
Dienst Gefunden : iSafeService
***** [ Dateien / Ordner ] *****
Ordner Gefunden : C:\Program Files (x86)\Elex-tech
Ordner Gefunden : C:\Users\Henoch\AppData\Roaming\Elex-tech
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17420
-\\ Mozilla Firefox v26.0 (de)
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.affiliate_id", "3553");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.firstrun", "false");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.log_send_info", "false");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.mappingListJsonString", "{\"version\":\"0.21088\",\"update_interval\":919,\"base_url\":\"hxxp:\\/\\/www.wajam.com\\/\",\"update_url\":\"hxxp:\\/\\/www.wajam.com\\/addon\\/m[...]
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.no_trace", "false");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.server_current_mapping_version", "0.21088");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.supported_sites.wajam_settings.wajam_utils", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam'[...]
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.trace_log", "1387712400312 - processInstallationUpgrade - version set to : 1.26\n1387712400312 - processBrowserLoad - Bad mappingListJsonString: null\n1387712401514 - onFla[...]
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.unique_id", "F7F6B7E9228251FB3D6200B04F855D42");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.user_current_mapping_version", "0");
[5wimzc6q.default] - Zeile gefunden : user_pref("extensions.wajam.version", "1.26");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.LayoutId", "1");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.ShowThankyouPixel", "0");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.adapters", "{\"facebook\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Status\":1,\"expireTime\":\"1387712427052259200\"}}");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.enabledAds", "false");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent109", "1387712430303");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent110", "1387712448132");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent111", "1387712430307");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent112", "1387712430369");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.registerToolbarEvent122", "1387712430312");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.version", "7.50.3.1");
[5wimzc6q.default] - Zeile gefunden : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.50.3.1\",\"InstallEventCTime\":1387712399836,\"InstallEvent\":\"True\"}");
[5wimzc6q.default] - Zeile gefunden : user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12692&tm=319&src=ds&p=");
-\\ Google Chrome v39.0.2171.71
[C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=319&src=ds&p={searchTerms}
[C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=319&src=ds&p={searchTerms}
-\\ Comodo Dragon v
*************************
AdwCleaner[R0].txt - [14509 octets] - [04/12/2014 20:42:49]
AdwCleaner[R1].txt - [4333 octets] - [04/12/2014 20:56:21]
AdwCleaner[S0].txt - [15541 octets] - [04/12/2014 20:44:24]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [4454 octets] ########## Code:
# AdwCleaner v4.103 - Bericht erstellt am 04/12/2014 um 20:44:24
# Aktualisiert 01/12/2014 von Xplode
# Database : 2014-12-03.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Henoch - HENOCH-VAIO
# Gestartet von : C:\Users\Henoch\Downloads\AdwCleaner_4.103.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\iolo
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC
[!] Ordner Gelöscht : C:\Program Files (x86)\Elex-tech
Ordner Gelöscht : C:\Users\Henoch\AppData\Local\CrashRpt
Ordner Gelöscht : C:\Users\Henoch\AppData\Local\Temp\iSafeRightKeyScan
Ordner Gelöscht : C:\Users\Henoch\AppData\Roaming\Elex-tech
Ordner Gelöscht : C:\Users\Henoch\AppData\Roaming\iolo
Ordner Gelöscht : C:\Users\Negede\AppData\Local\Temp\iSafeRightKeyScan
Ordner Gelöscht : C:\Users\Negede\AppData\Roaming\Elex-tech
Ordner Gelöscht : C:\Users\Henoch\AppData\Roaming\Mozilla\Firefox\Profiles\5wimzc6q.default\Extensions\{19D73812-1701-1B61-CBA2-12A70C87A0B0}
Ordner Gelöscht : C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
Ordner Gelöscht : C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\aaaalipaokhkccgmgkdglfinfnfhflko
Datei Gelöscht : C:\Windows\System32\drivers\iSafeKrnlBoot.sys
Datei Gelöscht : C:\Windows\System32\log\iSafeKrnlCall.log
Datei Gelöscht : C:\Users\Henoch\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\YAC.lnk
Datei Gelöscht : C:\Users\Henoch\AppData\Roaming\Mozilla\Firefox\Profiles\5wimzc6q.default\user.js
Datei Gelöscht : C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
Datei Gelöscht : C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage
Datei Gelöscht : C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\Local Storage\chrome-extension_aaaalipaokhkccgmgkdglfinfnfhflko_0.localstorage
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\SettingsManagerIEHelper.DNSGuard
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2481020
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{5411D116-5A37-47D4-B154-5F7FCD9062F0}
Schlüssel Gelöscht : HKLM\SOFTWARE\SweetIM
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{c3e85ee9-5892-4142-b537-bceb3dac4c3d}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\02F47BF73B948514FAACADD8CBBDF37D
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\080D9F5E1E95FEE4794CE438E635239E
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E264E0A5959A1C46BA9175A878B12EA
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E6768B6932D112438F047C54D180635
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\351716A953E21214898904032EAE2E81
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69D6A6B2ED56AF24EA6335EAD6E91CA4
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75FF6D97AF9FC004A9521D4B83FA6321
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFA128C2B0FF414D805FC5627883401
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EDC790504E1834DBC20C9A04328FD2
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97C3D0F82E712E241A2F969F45E3351C
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9E7F556BF224D804D96A96F0F6344789
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A189D17A469616C4688D23E192996267
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF4F885EDEE45644EB1E0C99E0162399
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB13D869D7D092348847B7481BB59E27
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CE21F3FD57B244142880EF15A165A156
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9EE58E3C298524145B73CBBED3CAC4D3
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A97CEC23332751B47BA4B95BAA50C9D0
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17420
-\\ Mozilla Firefox v26.0 (de)
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.affiliate_id", "3553");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.firstrun", "false");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.log_send_info", "false");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.mappingListJsonString", "{\"version\":\"0.21088\",\"update_interval\":919,\"base_url\":\"hxxp:\\/\\/www.wajam.com\\/\",\"update_url\":\"hxxp:\\/\\/www.wajam.com\\/addon\\/m[...]
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.no_trace", "false");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.server_current_mapping_version", "0.21088");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.supported_sites.wajam_settings.wajam_utils", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_LABEL_NAME_UC'] = 'Wajam'[...]
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.trace_log", "1387712400312 - processInstallationUpgrade - version set to : 1.26\n1387712400312 - processBrowserLoad - Bad mappingListJsonString: null\n1387712401514 - onFla[...]
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.unique_id", "F7F6B7E9228251FB3D6200B04F855D42");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.user_current_mapping_version", "0");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("extensions.wajam.version", "1.26");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.LayoutId", "1");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.ShowThankyouPixel", "0");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.adapters", "{\"facebook\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Status\":1,\"expireTime\":\"1387712427052259200\"}}");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.enabledAds", "false");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.registerToolbarEvent109", "1387712430303");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.registerToolbarEvent110", "1387712448132");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.registerToolbarEvent111", "1387712430307");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.registerToolbarEvent112", "1387712430369");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.registerToolbarEvent122", "1387712430312");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.version", "7.50.3.1");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.50.3.1\",\"InstallEventCTime\":1387712399836,\"InstallEvent\":\"True\"}");
[5wimzc6q.default\prefs.js] - Zeile gelöscht : user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12692&tm=319&src=ds&p=");
-\\ Google Chrome v39.0.2171.71
[C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://anisearch.de/?page=suche&mode=auswahl&qsearch={searchTerms}
[C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
[C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=319&src=ds&p={searchTerms}
[C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=319&src=ds&p={searchTerms}
[C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.ask.com/web?o=APN10257&doi=2014-07-05&apn_dtid=%5ECMD011%5EYY%5EUS&apn_ptnrs=%5EAGO&q={searchTerms}
-\\ Comodo Dragon v
[C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://anisearch.de/?page=suche&mode=auswahl&qsearch={searchTerms}
[C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
[C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=319&src=ds&p={searchTerms}
[C:\Users\Negede\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=319&src=ds&p={searchTerms}
[C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://search.ask.com/web?o=APN10257&doi=2014-07-05&apn_dtid=%5ECMD011%5EYY%5EUS&apn_ptnrs=%5EAGO&q={searchTerms}
[C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\preferences] - Gelöscht [Extension] : cmaiofennmphjldldcpphcechfnnohja
[C:\Users\Henoch\AppData\Local\Comodo\Dragon\User Data\Default\preferences] - Gelöscht [Extension] : aaaalipaokhkccgmgkdglfinfnfhflko
*************************
AdwCleaner[R0].txt - [14509 octets] - [04/12/2014 20:42:49]
AdwCleaner[S0].txt - [15283 octets] - [04/12/2014 20:44:24]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [15344 octets] ########## Hier: JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Home Premium x64
Ran by Henoch on 04.12.2014 at 20:59:53,88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Failed to stop: [Service] isafekrnl
Failed to stop: [Service] isafekrnlkit
Failed to stop: [Service] isafekrnlr3
Failed to stop: [Service] isafenetfilter
Failed to stop: [Service] isafeservice
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Henoch\AppData\Roaming\elex-tech"
Successfully deleted: [Folder] "C:\Users\Henoch\appdata\local\cre"
Failed to delete: [Folder] "C:\Program Files (x86)\elex-tech"
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{0068C03D-36F6-402A-AB87-5E701F97EC75}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{007EDC0C-DB4F-4D2A-8DF6-76EEE828205B}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{008FE068-0C87-433C-8FD0-27F97E7D6828}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{00A7E966-ACAB-46BD-9889-588F7B63AF35}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{029E04E5-D466-40EF-B4C8-87E8BB22730B}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{03291152-3627-400F-8E37-8F6352A8C86F}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{03B36BA1-6F18-47E9-B07C-B3D67D2EA869}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{03BE32F9-9DA8-4AD7-83F4-F0E8A4D28886}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{03F2D33C-3190-48A0-BC32-715BEEF4F5CE}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{05280976-D492-4544-8FC2-58C3BAF2F9C6}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{0646A333-7AAB-41C8-815A-5403FF962A44}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{072F04ED-CD8A-4130-A442-FA4F765E080E}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{076C4DA0-EB2D-49E9-A769-7E981FA12A07}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{0820C272-4B47-493F-B2A7-3975B02D7649}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{0AE8CE4A-AA16-474C-960E-66A9A1FA93FA}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{0D4A2B38-FEA7-4211-9FFA-D0C66074D5CF}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{0D78B923-F959-4FAE-9903-BDED29D6C9F6}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{0F21EF93-7CED-41F9-8135-0BAB64C1726B}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{1304D21D-55F1-42B2-91F0-12BEE5CBFA37}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{1396F8E7-DD7A-411C-92EF-F175A219F419}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{14F9CF85-B8CF-469E-809C-4C8509EDD69E}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{156CA0EE-C325-4811-A639-5A52DBC41E11}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{162B0D47-F7B4-4706-B9A0-4B8BA8E6DA0F}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{1A662ED7-DAB2-4DCC-8D41-C625397B45A1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{1AC3852C-ED0D-4D47-A3F9-A056742A0E14}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{1B0F86F8-D4B9-47BE-9C68-9EEBF692A78A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{1B7FDB59-DB25-4596-A240-EA9E8945D3BA}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{1DD46B2D-95C4-4FDD-ADC9-3A7400B1835C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2112FF6B-25D7-4BA3-8EC6-29B805BA5B43}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2156F5EE-68D1-4088-A6A8-23D242981756}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{21FAC655-E77F-4680-9D38-2C464AE25E49}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{23D7603D-AF41-4CC4-AEA0-B4BA2F0054EA}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{24B399B0-7349-46C4-BC56-128285CB525D}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{25999472-CFFD-4E4B-BCF0-91FFB2B86987}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{25A53CA1-10B4-475E-BE8E-50D80CAAFAF0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{26A1840D-DE17-4311-9774-9B1E848D43F2}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{26F25A2C-BEF2-48E3-8EEE-EE70BB9A6152}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{27D08A0A-7499-4615-A40C-5D2446272D03}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{288AB76E-FCFE-4B8D-A107-787632595918}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{28B0E844-D8C8-4498-B4FC-9670676B2C55}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{290C410C-30AB-4A80-9412-993EC877C0BD}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2A132FDE-F325-4F32-824E-CD75FA69A6CF}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2B31163D-455C-4453-B555-7757E8E85C54}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2B68A1B3-7F8C-4A44-879F-3B74217803B3}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2B6DE6B5-E2E4-4712-B262-4D45390B39BB}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2C7D1443-03E2-4539-A011-8441FE6D5B96}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2DF338BF-B144-43D9-A9AA-4FB5BDC366C0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2E6943E6-EF4B-4614-863C-DB17D8AB147E}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2E775E92-33A1-41CC-9EF7-5242F90D62C0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2F07BE98-6E64-40E9-8689-FE1182CDECC1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2F9F433C-7EFF-49D1-80C9-E935AF8C4DE3}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{2FF7BF88-2C4B-4666-8DA3-0A623704DBA8}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{3034A5CA-1A0D-45EB-B24F-499E9597A9CF}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{307FC519-B38C-42C1-A09C-076FD85B3580}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{309638F8-1322-436A-AB4A-F56F64238AC0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{30A609A5-1CD0-41E7-9971-B8C74E4A4342}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{3219B956-BE71-4356-8713-A8204C620954}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{33331B3C-B4A7-40C2-ACC7-B16FF8FD65E5}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{35194F46-C59A-47C0-927E-1D8573088144}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{3813CCA0-AEEB-43CB-92C2-6C48F6A795E2}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{381412CF-511C-4394-BF82-849BD0CA5488}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{3A1B53F9-A3FC-4DB4-980B-485C44CAD626}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{3BC2D61D-50BE-484D-AC23-589B00C5F6D6}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{3D202CF6-BC43-41E5-B256-A41402178CC6}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{3EE2797A-C88A-4B6F-A81E-AC7B88CCEEF4}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{3FE4D78E-F896-4419-AB2A-4E1AE7E31A76}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{3FFCD665-1FC4-499E-871D-3313E6127B35}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4032AB76-AC91-470D-94FE-C50856654C12}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{40D45FB4-275A-4508-9F5A-A476E3C53029}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{414284CB-799D-4F1A-8E69-FC92E0EF5571}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{41549BDF-87EC-4361-9CAC-B5B0584B5797}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4494FAC2-5235-4749-B8CA-68C7033D04DF}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{455529A7-9652-4F04-BB33-AF204E6BB1E1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{47EA59ED-D0F5-48BA-A0A3-09CEFDA23C93}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4817581D-D459-430A-AFDA-369A31114185}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{48F5B149-D2F4-4499-B0F4-F9C2D3E9D279}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4B880976-6AFF-4B45-90F8-537C82129916}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4C072626-30E2-462A-94A2-3E84614F96D6}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4CBA5A24-662B-48B0-8294-76DE15115B61}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4E7224EA-297F-4748-B3CA-89B7166F648D}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4E86FD0D-88D6-4C40-9F34-B06E46E75049}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4EA4FC5E-3B10-4F9F-8AB6-19A091951E3A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4EC81182-95E5-4733-A961-303E9C71C699}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{4F605D8E-7A59-4D0E-9EBC-343C7A5F9F19}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{506D1108-FDC8-41B3-8343-622168573F50}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{526B747A-5AA7-4377-8E87-DA77C6327F4A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{53405CE3-749A-48CE-ABBE-C40328408514}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{545181B2-D04F-4A10-8A97-43E132D79507}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{54C0BD6D-2B97-47A7-B321-FDB03B42E8F3}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{54C16B38-6AE8-4DAF-86D0-FA51A5524252}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{55CC92D5-1052-4F21-B53F-96C6763DE378}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{57B7166E-F88B-4A2B-8677-78BB4889F336}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{586CB17C-4273-40EE-BF56-5D31FE4AD2D0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{596D3A70-D348-49F9-9C93-AB67092BD457}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5A913224-AC74-47B7-B7C4-9FF076CC3617}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5AFA5739-F573-4073-B708-2DE5DD2D5ADC}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5B05F23F-B8C0-4E12-80C1-F8AFA7CE4CE7}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5C77BFE3-B863-4164-A9F0-BF1B34DA3633}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5CBD422C-94C9-414E-B80C-1AE11A1AD2B1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5D523A87-6C54-43E3-83EE-C57209631146}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5DBCA463-F23A-4F34-9020-B374D1B0EBED}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5E3B2DE1-1A92-4329-80B3-3FC0F682EE48}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5E4A5DF6-1E86-4E99-8769-B9F68F42C3BC}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5F4081F5-C982-4D86-A667-0B5AF3C0CDFA}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{5FBAB3EF-BCC6-43D2-AC86-6EE5CB3D891E}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6039F03A-BD93-4C84-8EB7-4CBE80324EFD}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{61F9A428-BDA2-4F42-9185-FC082B3F4197}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6357DDCC-172B-4E0F-B848-20CFEB02B3C5}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{63939698-50C5-4954-8A76-0CB45D285FE7}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6450F488-77EB-4C67-A247-3A89CDACF60F}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{650654AA-3B39-41F9-8136-BB29659B2BA9}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{650CAC75-644A-4077-97E7-6D8D9C9AAC43}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{65BFE0B9-5382-4078-9799-CF7A37A977AD}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{66D1FE6A-3F09-4D93-BAB6-E8DD291267B9}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6785D256-5A4C-4FE1-8EB2-AB40CADBC15D}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{68EAEDCB-0234-4E50-BC35-26DFAD8F1839}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6B456ACC-8692-43F6-8309-D2AD5D715D4F}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6B7EBCE7-7C9C-4730-836B-79D351B5BDEB}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6C6E6367-AA2E-42A5-B794-29B3F19C5724}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6C9C83FE-8DB6-48E5-AC1D-8D7699754556}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6D167E7A-5719-4651-9DD7-137A987548FA}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6E00131E-CA2B-4A1C-9D23-BB97F1A83403}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6E4CDB92-2025-41B1-AD39-C294FA5533C2}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6E65312D-E623-47BD-8A83-47FED260E1D0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6F043944-835B-4F86-9353-905E27BD3D22}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{6FC9D17D-BA71-41D8-9DAB-70A40C8D8BBC}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{715EF16E-1205-4F3C-839F-1C36E8DA5B02}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{719BFD13-7B21-4ED6-A147-29ABD8846CDA}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{71AFF0D6-2F40-4F70-99DC-525C8B15D86B}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{72BA4000-5A8C-4C90-B5B5-3C233EF307D3}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{738BDCCF-B6F2-4E44-AE3E-1E1BCE900589}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{73DB4DD0-AC55-43C7-9649-14BC1545D4F3}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{75F4DA71-1FE6-4EBD-B0DC-8E8801B9ABFC}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{763F4BCE-D9BD-4E67-95B7-82227763AB0C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{764045C4-17CC-4F07-BAA0-9433EDADB831}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{79A38E85-8287-4DC0-A997-1E07E99CF9FC}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{7A8A6CB0-A496-4B20-B4E0-A0AE60A397A4}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{7E59B9AE-650A-464F-8FF8-44051944E903}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{81DCF8B8-3B9A-420C-846A-40C774600489}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{81EA7DD4-2741-4239-9CA3-08176805B900}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{82297B71-F32E-4618-8474-4BB1710E3012}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{82F709A8-D8C3-4A77-95A8-50398951724B}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{84C6FCC9-4A08-4E1A-A4BF-F2A5FB60633A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{875AB168-A109-40C9-9586-1E6F2770ED80}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{87D8FB96-5D4A-4A90-A3DC-466111FA6EE1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{8B4C9694-F1C3-4F1C-9060-02AF562991F7}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{8EEA2EA4-14BA-4878-AFD8-9C2B7BA20E3A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{8F8015F6-5CB2-4C9A-A400-BD512A68C166}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{90371118-E8C9-40A6-B129-74B88122C2E5}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{903899E2-473A-4909-BADC-1501D7B416B3}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{90A7FE95-C86F-4115-9D43-8E4AFDFB5BBB}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{9155A91D-9262-42D6-9612-AB6E8A37C6D0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{92E8D8B9-08B6-412F-9AC3-CDB52D75543E}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{9334040C-5AA9-48A3-94A2-68707C61AC62}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{942A1A08-C5F5-4237-BE14-683D1DCC4052}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{9559364B-05D5-474C-AE1B-877A855BFD1A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{962DFDDA-2223-4F9C-8833-D38F94BE612C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{96DF5501-6AF4-42A7-9D91-4B0C85CD5D33}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{984D6CD9-2ECD-4137-BB7D-CE6DBB6B14CE}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{9894DBB4-A384-4FD1-A2F6-C6D8BBC2EF32}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{9897BF2E-E0E2-4F7C-9317-256E14FED612}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{99180701-8331-4CF7-9B5C-4F4B85853F51}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{992637D9-7522-4FB8-9E50-41AB75894219}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{996F5A4C-F38E-4BE6-B97A-B6CBCA6A240D}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{9B071422-CBD0-43A2-84D9-D795B8FBD47B}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{9CC81DEA-D446-42BB-87E8-E1E84424D9EF}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{9F40BD2A-58D6-4C74-8C53-564B30F378D9}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{9FDD3EDF-8386-4ED7-898C-0575C664456A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A18AB588-5DA7-4DEC-95DA-35E38407EC07}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A255B98A-83F5-4310-9BDB-5631F424A358}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A3661B9B-0DF3-42BF-A2D7-C472E8D5C0A9}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A4871461-4818-4066-9454-161C428A51A5}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A6F8E6AB-42A6-464E-851F-B62B932C91A8}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A70C9A12-4AC4-4568-96D6-8CDBD78ED286}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A71FCE49-6368-4013-B1D5-3973993611B0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A74A07AF-F5EC-4BA7-809B-CE3934CE5C8D}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A8222F1C-2955-4FDA-A350-A89D1B003304}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A8A15B94-9C8D-432C-ACD4-B414C34FA6BD}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{A9E34E72-41D3-4646-BDD2-3015F70423E1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{AA4E47C8-1384-4AD4-8535-23EDE2E2A2D3}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{AADFB505-CAE2-490A-AC05-0604F61DCE2A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{AB320AD3-B7C6-42D6-BBE5-1840FAE8D847}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{AB6DF812-AA6B-4B56-BC48-44DB453FCD98}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{ABA9DA80-51F4-4DF0-BDFC-CC3ACDDCDCB5}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{AC48CFC7-40E6-41F3-8C4A-99374B44CF8C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{ACCC85F9-FF11-40D5-9A45-0E4A9CF409C1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{AE27E7D2-D1CE-4A1D-9276-FED46A54D8F8}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{AE8C0C41-6CD5-4D44-9911-406524B44B3C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{AEDB795B-B43B-47A3-8A24-6B7C2DB2A98C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{AEF9C83B-17E2-4F5E-A840-E0998E6825CB}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B131D5BB-41CA-4794-89EA-9CE24574E303}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B1DF8AF1-9A36-421E-BAEF-1167CC5D3C18}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B28976F3-487B-45D7-B740-2EB4F5D6EAD1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B34D3A40-F703-4800-98E0-7F89D22966CD}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B4B8CB48-F5F7-4EBF-BFF5-6E45D5DD08DA}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B5F834EC-AC6A-4978-9D8B-522799F6F0B7}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B6D09FDC-EEBD-4DF9-8C78-A35C6A724816}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B7B3A32A-3B4C-46C5-BC73-B3F4C4854A21}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B8D980B4-AA7D-4D89-897D-58C10FE32CB9}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{B92437BE-89A4-4743-BB89-5EF34134B3AE}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BA14B256-904D-455C-B6B7-4DA99E9D9BA8}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BA452966-9FEB-4218-8E20-9EFB4FA7CFD7}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BA6C8CE9-7616-4284-9484-E01A88C53651}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BA72D936-9BFF-46EE-B557-01E28BCE1FE4}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BB03CBEB-74B0-46DC-94BA-6882271B9FA9}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BBEA3FBF-C2E8-41A4-96AD-2BB307548538}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BCA022BC-056E-4A3B-905F-715E49C2EB6D}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BCD2D6DD-90B8-4756-A075-AEF651397EC2}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BD1A87B3-B779-412B-8843-2E94ABDBC651}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BDCFC626-F232-4F49-92C9-64E8FFA9FA79}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{BFE9E6F6-96B8-4EC2-A46D-E948047B928D}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C12216CF-49EE-4D5E-903C-861E1D384C65}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C21BCF28-29B5-4CCD-82FB-5A19A184ED60}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C4A961F6-DB89-4BF1-B7A5-9502FF26361A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C4EBEAEF-C1D0-4AD8-A008-A1DBFEBD50CE}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C716D444-6483-4952-8F10-DFC0E21EEC92}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C752DECD-4608-49C4-94F0-C65C3C82BB4C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C7FA1B01-8186-42F2-AC59-48A2DC5BC4DB}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C81CE60A-8FED-47A7-99EC-CB0AA69F2F2E}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C8D161EE-6401-4223-828D-23C3DA11D24C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C961B655-835E-4EC5-8BF3-819ABAC3536D}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C979F3CF-1B53-4DAC-B483-7F8FBBA9F4F2}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{C97E45EA-4D39-49E0-93F1-7DC80135D2B1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{CA7CA0AF-9FDF-4023-A431-8936843B0E7A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{CADE826E-ED1C-4D52-95B0-BE90E881B095}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{CB50912B-4E26-4952-9BC4-337B4963C526}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{CBBF79D4-F763-49FB-8D58-DF5825B23FD7}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{CE5C15B0-21D8-46FB-8F91-3290ECE482C1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{CF36AF32-8EE1-4AAC-8BF6-7009684492B0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{CF8DC9E2-FA96-48B3-B08F-36CBC2380052}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{CFF67602-F930-4FD9-9292-2AFE2E815E97}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{D08D6F98-D0AC-4F7A-A832-F3162C956CA8}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{D1E649FC-F466-4597-803E-9303BF7044B6}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{D2ED5CD1-C2EF-46F4-B65D-B9EB9A44B6DB}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{D4125EA8-895C-4E33-8834-8E1DB17301F6}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{D4A859B7-1A65-48C3-9364-10A5404D3AA0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{D5625DC4-F2ED-412E-A4C6-044A494FB473}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{D6414171-E34A-4896-B424-68CF27C03D0C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{D66207EC-2D84-473E-844D-1773EAAF75AC}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{D8AB553D-CB39-4E69-A30A-B00B8A362EA1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{DB70F403-1DF6-493D-BE11-414607FE5258}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{DC4A9952-CA75-431F-9218-6A6AE7BB311E}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{DD344C43-FF73-44C4-BFE8-859CAA1D4293}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{DDC800D3-BD97-446C-A236-CDC23D4F0D68}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{DE146BB4-3DF9-4BA2-BB34-2CFED7719C7E}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{DEA17635-8B81-4501-A9BB-936D65C55652}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E01411E5-7CF0-404C-910B-A5F2B65D29CB}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E017E9FF-ADEF-499C-B3CE-F425B8D9949B}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E1BCD3BE-0E6A-45B0-8A61-B64CF2BC49DB}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E1D52C45-491F-4684-8211-4968F45EF4BF}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E1D7C44A-E0DB-4933-970B-C7DFDCB206C7}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E29778B0-2FB7-41F1-A789-4D3E04003C03}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E3F0CCC9-C53A-454C-AEA4-43D63EFBFB87}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E5340779-F5F0-4059-84A3-1E097E42EF5C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E56191C8-6E81-4E98-A2AD-15AE838812A0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E6509D7E-8C04-4CAA-83EF-9990B024DF1A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E6AAAD96-12A5-4D50-A10B-C382E64357A7}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E7C13390-50BD-4AE8-B33D-60096325683C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E818EF9F-7160-4370-B2D7-450761C822F1}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E9373DAF-2E42-47C4-89BC-F25A5033A048}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{E94681FB-DC70-4B99-AF22-78B9F43F48C4}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{EB121EE4-BB45-4B64-8019-66FB119A0959}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{EB54C328-4869-443A-92F6-13EE05933FF7}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{EDD08B35-B130-4387-B91A-F77357A3784C}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{EE2FD5D8-7430-4BD7-B6EE-629482B873CD}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F03D47DA-CB62-48B5-B455-067315ABE581}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F04FAC81-6C82-4033-AB36-3200CA1C2A71}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F10142CE-7EC6-4EEE-B7EF-B0C0A1FC86B3}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F2BED5A8-6E60-4A3C-8B2E-ABD619D828E4}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F3D68BE8-072F-43B7-856B-CD2A3B0EED9A}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F70B0917-C036-4AB6-910A-938C0A1C3163}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F778EDA0-5665-41C4-9482-77F26A7CD7D0}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F854CB2E-4E60-4DAF-9D82-15A8FA70002E}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F88ACC60-AD28-434B-AFB6-C5B7CEB36F04}
Successfully deleted: [Empty Folder] C:\Users\Henoch\appdata\local\{F949DD2C-6267-4F2A-8DBE-85C8FFA7A44D}
~~~ FireFox
Successfully deleted the following from C:\Users\Henoch\AppData\Roaming\mozilla\firefox\profiles\5wimzc6q.default\prefs.js
user_pref("extensions.wajam.affiliate_id", "3553");
user_pref("extensions.wajam.firstrun", "false");
user_pref("extensions.wajam.log_send_info", "false");
user_pref("extensions.wajam.mappingListJsonString", "{\"version\":\"0.21088\",\"update_interval\":919,\"base_url\":\"hxxp:\\/\\/www.wajam.com\\/\",\"update_url\":\"hxxp:\\/\\/
user_pref("extensions.wajam.no_trace", "false");
user_pref("extensions.wajam.server_current_mapping_version", "0.21088");
user_pref("extensions.wajam.supported_sites.encryptedgoogle.wajam_google_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM
user_pref("extensions.wajam.supported_sites.google.wajam_google_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_L
user_pref("extensions.wajam.supported_sites.wajam_settings.wajam_utils", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_
user_pref("extensions.wajam.supported_sites.youtubesearch.wajam_se_js", "try {window['APP_LABEL_NAME'] = 'wajam';window['APP_LABEL_NAME_FULL_UC'] = 'WAJAM';window['WAJAM_APP_L
user_pref("extensions.wajam.trace_log", "1387712400312 - processInstallationUpgrade - version set to : 1.26\n1387712400312 - processBrowserLoad - Bad mappingListJsonString: nu
user_pref("extensions.wajam.unique_id", "F7F6B7E9228251FB3D6200B04F855D42");
user_pref("extensions.wajam.user_current_mapping_version", "0");
user_pref("extensions.wajam.version", "1.26");
user_pref("iminent.LayoutId", "1");
user_pref("iminent.ShowThankyouPixel", "0");
user_pref("iminent.adapters", "{\"facebook\":{\"CountryCode\":\"DE\",\"NoAds\":false,\"Status\":1,\"expireTime\":\"1387712427052259200\"}}");
user_pref("iminent.enabledAds", "false");
user_pref("iminent.registerToolbarEvent109", "1387712430303");
user_pref("iminent.registerToolbarEvent110", "1387712448132");
user_pref("iminent.registerToolbarEvent111", "1387712430307");
user_pref("iminent.registerToolbarEvent112", "1387712430369");
user_pref("iminent.registerToolbarEvent122", "1387712430312");
user_pref("iminent.version", "7.50.3.1");
user_pref("iminent.versioning", "{\"CurrentVersion\":\"7.50.3.1\",\"InstallEventCTime\":1387712399836,\"InstallEvent\":\"True\"}");
user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12692&tm=319&src=ds&p=");
Emptied folder: C:\Users\Henoch\AppData\Roaming\mozilla\firefox\profiles\5wimzc6q.default\minidumps [9 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.12.2014 at 21:04:18,50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-12-2014
Ran by Henoch (administrator) on HENOCH-VAIO on 04-12-2014 21:12:53
Running from C:\Users\Henoch\Downloads
Loaded Profiles: Henoch & Negede (Available profiles: Henoch & Negede)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\ipcdl.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAdmin.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe
(Thisisu) C:\Users\Henoch\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-11-18] (Avira Operations GmbH & Co. KG)
HKLM\...\RunOnce: [*Restore] => C:\Windows\system32\rstrui.exe [296960 2014-08-19] (Microsoft Corporation)
HKU\S-1-5-21-3995798047-183456226-2512991475-1001\...\Run: [LOLReplay Recorder] => "C:\Program Files (x86)\LOLReplay\LOLRecorder.exe" -minimize
HKU\S-1-5-21-3995798047-183456226-2512991475-1001\...\Run: [wm] => C:\Users\Henoch\AppData\Local\Temp\wm.exe [5892096 2014-06-14] () <===== ATTENTION
HKU\S-1-5-21-3995798047-183456226-2512991475-1001\...\RunOnce: [Report] => C:\AdwCleaner\AdwCleaner[S0].txt [15541 2014-12-04] ()
HKU\S-1-5-21-3995798047-183456226-2512991475-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3995798047-183456226-2512991475-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://sony.msn.com
HKU\S-1-5-21-3995798047-183456226-2512991475-1003\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://sony.msn.com
HKU\S-1-5-21-3995798047-183456226-2512991475-1003\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://sony.msn.com
URLSearchHook: HKU\S-1-5-21-3995798047-183456226-2512991475-1003 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
SearchScopes: HKLM -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=SNYEDF&pc=MASE&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3995798047-183456226-2512991475-1001 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3995798047-183456226-2512991475-1001 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3995798047-183456226-2512991475-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3995798047-183456226-2512991475-1001 -> {81DC31DA-8B77-49F8-8FEC-177610596CC0} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-Q212&_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-3995798047-183456226-2512991475-1003 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3995798047-183456226-2512991475-1003 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3995798047-183456226-2512991475-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3995798047-183456226-2512991475-1003 -> {96280204-BD24-4DE9-BDDC-7A031A59168E} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-Q212&_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-3995798047-183456226-2512991475-1003 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2476} URL = hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12521&tm=319&src=ds&p={searchTerms}
BHO: No Name -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> No File
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKU\S-1-5-21-3995798047-183456226-2512991475-1003 -> No Name - {5786D022-540E-4699-B350-B4BE0AE94B79} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Henoch\AppData\Roaming\Mozilla\Firefox\Profiles\5wimzc6q.default
FF Keyword.URL: hxxp://www.default-search.net/search?sid=476&aid=122&itype=a&ver=12692&tm=319&src=ds&p=
FF Homepage: hxxp://www.google.com
FF NewTab: hxxp://www.google.com
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_239.dll ()
FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 -> C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3995798047-183456226-2512991475-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Henoch\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: Avira Browser Safety - C:\Users\Henoch\AppData\Roaming\Mozilla\Firefox\Profiles\5wimzc6q.default\Extensions\abs@avira.com [2014-08-17]
Chrome:
=======
CHR Profile: C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-08]
CHR Extension: (AdBlock) - C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-08-17]
CHR Extension: (Google Wallet) - C:\Users\Henoch\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-01]
CHR HKU\S-1-5-21-3995798047-183456226-2512991475-1001\...\Chrome\Extension: [fkjoiggkbepedjmjjbhhecjiimlckcga] - C:\Users\Henoch\AppData\Local\CRE\fkjoiggkbepedjmjjbhhecjiimlckcga.crx [Not Found]
CHR HKU\S-1-5-21-3995798047-183456226-2512991475-1001\...\Chrome\Extension: [iokhogohoamdhejdbenjbjkhjmjlggab] - C:\Users\Henoch\AppData\Local\CRE\iokhogohoamdhejdbenjbjkhjmjlggab.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [fkjoiggkbepedjmjjbhhecjiimlckcga] - C:\Users\Henoch\AppData\Local\CRE\fkjoiggkbepedjmjjbhhecjiimlckcga.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\...\Chrome\Extension: [iokhogohoamdhejdbenjbjkhjmjlggab] - C:\Users\Henoch\AppData\Local\CRE\iokhogohoamdhejdbenjbjkhjmjlggab.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2014-11-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2014-11-18] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [106144 2012-02-23] (Atheros Commnucations) [File not signed]
S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [112256 2012-03-21] (Atheros Communication Inc.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-03-13] ()
R2 iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [118048 2014-10-08] (Elex do Brasil Participações Ltda)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-03-13] (Intel Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5284208 2013-10-30] (INCA Internet Co., Ltd.)
R2 PMBDeviceInfoProvider; c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [473960 2012-02-21] (Sony Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-07-10] ()
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [260768 2011-11-30] (Sony Corporation)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-28] (Sony Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [158880 2012-02-23] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-19] (Avira Operations GmbH & Co. KG)
S3 BTATH_VDP; C:\Windows\System32\drivers\btath_vdp.sys [421664 2012-02-23] (Atheros)
R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [248488 2014-10-08] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [99496 2014-10-08] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [65704 2014-10-08] (Elex do Brasil Participações Ltda)
R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [49320 2014-09-22] (Elex do Brasil Participações Ltda)
S3 lehidmini; C:\Windows\system32\drivers\leath_hid.sys [36128 2012-02-23] (Atheros)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-04] (Malwarebytes Corporation)
S3 RZMAELSTROMVADService; C:\Windows\System32\drivers\RzMaelstromVAD.sys [32768 2014-06-09] (Windows (R) Win 7 DDK provider)
S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver.sys [21264 2012-03-13] (Synaptics Incorporated)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-04 21:12 - 2014-12-04 21:12 - 02117632 _____ (Farbar) C:\Users\Henoch\Downloads\FRST64.exe
2014-12-04 21:04 - 2014-12-04 21:04 - 00033734 _____ () C:\Users\Henoch\Desktop\JRT.txt
2014-12-04 20:59 - 2014-12-04 20:59 - 01707646 _____ (Thisisu) C:\Users\Henoch\Downloads\JRT.exe
2014-12-04 20:59 - 2014-12-04 20:59 - 00000000 ____D () C:\Windows\ERUNT
2014-12-04 20:50 - 2014-12-04 20:50 - 00000000 __SHD () C:\Users\Henoch\AppData\Local\EmieBrowserModeList
2014-12-04 20:42 - 2014-12-04 20:58 - 00000000 ____D () C:\AdwCleaner
2014-12-04 20:41 - 2014-12-04 20:41 - 02154496 _____ () C:\Users\Henoch\Downloads\AdwCleaner_4.103.exe
2014-12-04 20:40 - 2014-12-04 20:40 - 00004197 _____ () C:\Users\Henoch\Desktop\mbam.txt
2014-12-04 19:46 - 2014-12-04 20:38 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-04 19:45 - 2014-12-04 19:45 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-04 19:45 - 2014-12-04 19:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-04 19:45 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-04 19:45 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-04 19:45 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-04 19:44 - 2014-12-04 19:44 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Henoch\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-04 19:33 - 2014-12-04 19:33 - 00001264 _____ () C:\Users\Henoch\Desktop\Revo Uninstaller.lnk
2014-12-04 19:33 - 2014-12-04 19:33 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-12-04 19:32 - 2014-12-04 19:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Henoch\Downloads\revosetup95.exe
2014-12-04 17:21 - 2014-12-04 17:21 - 00045333 _____ () C:\Users\Henoch\Downloads\Addition.txt
2014-12-04 17:19 - 2014-12-04 21:12 - 00019546 _____ () C:\Users\Henoch\Downloads\FRST.txt
2014-12-04 17:19 - 2014-12-04 21:12 - 00000000 ____D () C:\FRST
2014-11-24 18:02 - 2014-11-24 18:02 - 00022528 _____ () C:\Users\Henoch\Downloads\(4) Uebung_SVerweis.xls
2014-11-22 18:43 - 2014-11-22 18:43 - 01159216 _____ () C:\Users\Henoch\Downloads\The Binding of Isaac Rebirth (1).rar
2014-11-22 18:37 - 2014-11-22 18:38 - 01159216 _____ () C:\Users\Henoch\Downloads\The Binding of Isaac Rebirth.rar
2014-11-20 08:42 - 2014-11-20 08:42 - 00930246 _____ () C:\Users\Negede\Downloads\sprache.html
2014-11-20 08:42 - 2014-11-20 08:42 - 00000000 ____D () C:\Users\Negede\Downloads\sprache_files
2014-11-19 10:50 - 2014-11-11 04:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 10:50 - 2014-11-11 04:08 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 10:50 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-11-19 10:50 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pku2u.dll
2014-11-19 10:45 - 2014-11-19 10:45 - 00001141 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
2014-11-15 14:26 - 2014-11-15 14:26 - 01725304 _____ (Razer Inc.) C:\Users\Henoch\Downloads\RazerSurroundInstaller_v2.00.10 (1).exe
2014-11-15 14:26 - 2014-11-15 14:26 - 00000000 ____D () C:\ProgramData\RzMaelstromVAD_1.1.58.1854
2014-11-15 14:22 - 2014-12-04 20:58 - 00000000 ____D () C:\Program Files (x86)\Razer
2014-11-15 14:21 - 2014-12-04 20:58 - 00000000 ____D () C:\ProgramData\Razer
2014-11-15 14:21 - 2014-12-04 20:57 - 00000000 ____D () C:\Users\Henoch\AppData\Local\Razer
2014-11-15 14:20 - 2014-11-15 14:20 - 01725304 _____ (Razer Inc.) C:\Users\Henoch\Downloads\RazerSurroundInstaller_v2.00.10.exe
2014-11-12 16:18 - 2014-11-07 20:49 - 00388272 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-12 16:18 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-11-12 16:18 - 2014-11-06 05:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-12 16:18 - 2014-11-06 05:03 - 25110016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-12 16:18 - 2014-11-06 05:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-12 16:18 - 2014-11-06 04:47 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-12 16:18 - 2014-11-06 04:46 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-12 16:18 - 2014-11-06 04:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-12 16:18 - 2014-11-06 04:44 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-12 16:18 - 2014-11-06 04:43 - 02884096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-12 16:18 - 2014-11-06 04:36 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-12 16:18 - 2014-11-06 04:35 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-12 16:18 - 2014-11-06 04:31 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-12 16:18 - 2014-11-06 04:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-12 16:18 - 2014-11-06 04:30 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-12 16:18 - 2014-11-06 04:29 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-12 16:18 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-11-12 16:18 - 2014-11-06 04:23 - 06040064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-12 16:18 - 2014-11-06 04:20 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-12 16:18 - 2014-11-06 04:16 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-12 16:18 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-11-12 16:18 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-11-12 16:18 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-11-12 16:18 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-11-12 16:18 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-11-12 16:18 - 2014-11-06 04:07 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-12 16:18 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-11-12 16:18 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-11-12 16:18 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-11-12 16:18 - 2014-11-06 04:02 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-12 16:18 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-11-12 16:18 - 2014-11-06 04:00 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-12 16:18 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-11-12 16:18 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-11-12 16:18 - 2014-11-06 03:57 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-12 16:18 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-11-12 16:18 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-11-12 16:18 - 2014-11-06 03:41 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-12 16:18 - 2014-11-06 03:41 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-12 16:18 - 2014-11-06 03:39 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-12 16:18 - 2014-11-06 03:38 - 02124288 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-12 16:18 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-11-12 16:18 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-11-12 16:18 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-11-12 16:18 - 2014-11-06 03:30 - 14390272 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-12 16:18 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-11-12 16:18 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-11-12 16:18 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-11-12 16:18 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-11-12 16:18 - 2014-11-06 03:17 - 02365440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-12 16:18 - 2014-11-06 03:04 - 01550336 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-12 16:18 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-11-12 16:18 - 2014-11-06 02:53 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-12 16:18 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-11-12 16:18 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-11-12 16:18 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-11-12 16:18 - 2014-11-05 18:56 - 00304640 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-12 16:18 - 2014-11-05 18:56 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-12 16:18 - 2014-11-05 18:52 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-12 16:18 - 2014-10-14 03:16 - 00155064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-12 16:18 - 2014-10-14 03:13 - 00683520 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-12 16:18 - 2014-10-14 03:12 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-12 16:18 - 2014-10-14 03:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-12 16:18 - 2014-10-14 03:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-12 16:18 - 2014-10-14 02:50 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-11-12 16:18 - 2014-10-14 02:49 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-11-12 16:18 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2014-11-12 16:18 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2014-11-12 16:17 - 2014-10-25 02:57 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-12 16:17 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-11-12 16:17 - 2014-10-18 03:05 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-12 16:17 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2014-11-12 16:17 - 2014-10-14 03:13 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-12 16:17 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-11-12 16:17 - 2014-10-10 01:57 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-12 16:17 - 2014-10-03 03:12 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-12 16:17 - 2014-10-03 03:11 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-12 16:17 - 2014-10-03 03:11 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-12 16:17 - 2014-10-03 03:11 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-12 16:17 - 2014-10-03 03:11 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-12 16:17 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-11-12 16:17 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-11-12 16:17 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-11-12 16:17 - 2014-09-19 10:42 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-12 16:17 - 2014-09-19 10:42 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-12 16:17 - 2014-09-19 10:42 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-12 16:17 - 2014-09-19 10:42 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-12 16:17 - 2014-09-19 10:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-12 16:17 - 2014-09-19 10:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-12 16:17 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-11-12 16:17 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-11-12 16:17 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-11-12 16:17 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-11-12 16:17 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-11-12 16:17 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-11-12 16:17 - 2014-08-21 07:43 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-12 16:17 - 2014-08-21 07:40 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-12 16:17 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-11-12 16:17 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-11-12 16:17 - 2014-08-12 03:02 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-12 16:17 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2014-11-09 10:23 - 2014-11-09 10:23 - 00000000 ____D () C:\Users\Negede\AppData\Roaming\OpenOffice
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-04 21:00 - 2014-07-05 14:38 - 00000308 _____ () C:\Windows\Tasks\RegistryCleanerKit Maintenance.job
2014-12-04 20:57 - 2012-08-04 10:56 - 00126320 _____ () C:\Users\Henoch\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-04 20:56 - 2009-07-14 05:45 - 00028576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-04 20:56 - 2009-07-14 05:45 - 00028576 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-04 20:53 - 2012-08-04 10:54 - 01752161 _____ () C:\Windows\WindowsUpdate.log
2014-12-04 20:48 - 2012-10-14 20:12 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-04 20:47 - 2014-07-05 14:38 - 00000302 _____ () C:\Windows\Tasks\RegistryCleanerKit Startup.job
2014-12-04 20:47 - 2010-11-21 04:47 - 01404478 _____ () C:\Windows\PFRO.log
2014-12-04 20:47 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-04 20:47 - 2009-07-14 05:51 - 00254352 _____ () C:\Windows\setupact.log
2014-12-04 20:44 - 2014-11-02 16:18 - 00000000 ____D () C:\Windows\system32\log
2014-12-04 20:37 - 2012-10-14 20:12 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-04 20:33 - 2013-06-15 07:15 - 00000000 ____D () C:\Users\Negede
2014-12-04 20:29 - 2012-04-23 05:35 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-04 19:45 - 2014-10-04 09:03 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-04 18:38 - 2014-11-02 14:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph
2014-12-04 18:38 - 2014-11-02 14:11 - 00000000 ____D () C:\Program Files (x86)\Glyph
2014-12-04 18:38 - 2012-08-04 10:56 - 00000000 ____D () C:\Users\Henoch
2014-12-04 18:38 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-12-04 12:57 - 2012-02-24 05:01 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-12-03 16:32 - 2012-08-07 19:06 - 00000000 ____D () C:\Users\Henoch\AppData\Roaming\Skype
2014-12-03 16:13 - 2014-11-01 17:16 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-11-28 14:29 - 2012-04-23 05:35 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-11-28 14:29 - 2012-04-23 05:35 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-11-28 14:29 - 2012-04-23 05:35 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-27 16:40 - 2014-02-01 14:38 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-11-25 17:28 - 2014-08-18 10:14 - 00000000 ____D () C:\Program Files (x86)\CABAL Online (EU)
2014-11-22 20:48 - 2014-06-07 18:38 - 00000002 _____ () C:\Users\Henoch\Downloads\myFile.txt
2014-11-22 20:47 - 2014-06-07 18:38 - 00000757 _____ () C:\Users\Henoch\Downloads\serial.txt
2014-11-20 21:10 - 2014-03-24 15:25 - 00000000 ____D () C:\Users\Henoch\AppData\Local\Battle.net
2014-11-20 20:37 - 2012-09-11 14:27 - 00000000 ____D () C:\Users\Henoch\AppData\Local\CrashDumps
2014-11-18 16:59 - 2013-10-26 12:14 - 00000000 ____D () C:\Users\Henoch\Desktop\Naruto
2014-11-18 16:59 - 2013-06-27 18:22 - 00000000 ____D () C:\Users\Henoch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-11-18 16:59 - 2013-06-27 18:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2014-11-18 16:59 - 2012-08-04 15:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows - LIVE
2014-11-17 08:36 - 2013-06-15 07:17 - 00126768 _____ () C:\Users\Negede\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-16 14:52 - 2009-07-14 06:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-11-15 18:18 - 2009-07-14 05:45 - 00488488 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-15 11:26 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-11-14 14:32 - 2012-10-14 20:12 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-14 14:32 - 2012-10-14 20:12 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-14 13:45 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-11-13 15:56 - 2014-04-30 15:04 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-12 19:37 - 2013-08-14 10:07 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-12 19:28 - 2012-10-15 16:18 - 103374192 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-11 17:20 - 2014-04-08 17:24 - 00000000 ____D () C:\Users\Henoch\Desktop\LoL
2014-11-09 11:49 - 2014-01-25 11:40 - 00000000 ____D () C:\Users\Negede\AppData\Roaming\SoftGrid Client
2014-11-09 10:32 - 2013-06-15 07:16 - 00000000 ____D () C:\Users\Negede\AppData\Roaming\Adobe
2014-11-08 09:37 - 2012-04-23 05:44 - 00000000 ____D () C:\Program Files\Sony
2014-11-08 09:09 - 2012-04-23 05:11 - 00000000 ____D () C:\Windows\System32\Tasks\Sony Corporation
2014-11-04 14:30 - 2010-11-21 04:27 - 00275080 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
Files to move or delete:
====================
C:\Users\Henoch\AppData\Local\Temp\wm.exe
Some content of TEMP:
====================
C:\Users\Henoch\AppData\Local\Temp\7z920.exe
C:\Users\Henoch\AppData\Local\Temp\AskSLib.dll
C:\Users\Henoch\AppData\Local\Temp\avgnt.exe
C:\Users\Henoch\AppData\Local\Temp\BullseyeCoverage-2-x86.dll
C:\Users\Henoch\AppData\Local\Temp\drm_dyndata_7400006.dll
C:\Users\Henoch\AppData\Local\Temp\GoogleSetup.exe
C:\Users\Henoch\AppData\Local\Temp\i4jdel0.exe
C:\Users\Henoch\AppData\Local\Temp\i4jdel1.exe
C:\Users\Henoch\AppData\Local\Temp\OfficeSetup.exe
C:\Users\Henoch\AppData\Local\Temp\sdanircmdc.exe
C:\Users\Henoch\AppData\Local\Temp\sdapskill.exe
C:\Users\Henoch\AppData\Local\Temp\sdaspwn.exe
C:\Users\Henoch\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Henoch\AppData\Local\Temp\sfamcc00002.dll
C:\Users\Henoch\AppData\Local\Temp\sfextra.dll
C:\Users\Henoch\AppData\Local\Temp\SIMEEI2Installer.exe
C:\Users\Henoch\AppData\Local\Temp\SIMEEIInstaller.exe
C:\Users\Henoch\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Henoch\AppData\Local\Temp\Softonic_DE_1-5-10_DE-Production_10_CleanRelease.exe
C:\Users\Henoch\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\Henoch\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Henoch\AppData\Local\Temp\swt-win32-3740.dll
C:\Users\Henoch\AppData\Local\Temp\Uninstaller-2276.exe
C:\Users\Henoch\AppData\Local\Temp\Uninstaller-2776.exe
C:\Users\Henoch\AppData\Local\Temp\Uninstaller-4292.exe
C:\Users\Henoch\AppData\Local\Temp\Uninstaller-5688.exe
C:\Users\Henoch\AppData\Local\Temp\Uninstaller-8172.exe
C:\Users\Henoch\AppData\Local\Temp\Uninstaller-8400.exe
C:\Users\Henoch\AppData\Local\Temp\Uninstaller-9100.exe
C:\Users\Henoch\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Henoch\AppData\Local\Temp\wm.exe
C:\Users\Negede\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-29 11:23
==================== End Of Log ============================ --- --- ---
Danke Für die Hilfe |