Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Suchlauf Datum: 16.03.2015
Suchlauf-Zeit: 07:08:21
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.03.15.06
Rootkit Datenbank: v2015.02.25.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: butterfly
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 320415
Verstrichene Zeit: 17 Min, 38 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 19
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE, In Quarantäne, [f5dd291c6624ea4c02f05a7ad1327d83],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\13641, In Quarantäne, [05cd64e138521f171088aa45db28ff01],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [5e743a0b701a58de43c8092b887d24dc],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [01d1f94c25656ccae9234ce83cc9bd43],
PUP.Optional.Cinema.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Cinem4S-2.1, In Quarantäne, [a52d9baaa0ea57dfe838fad230d3b24e],
PUP.Optional.RadioCanyon.A, HKU\S-1-5-21-231648146-3933761938-2758524011-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Radio Canyon, In Quarantäne, [488a073ea0ea0e28690a251228dd35cb],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-231648146-3933761938-2758524011-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\13641, In Quarantäne, [25ada89de2a8a49248efdeebd62da65a],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
Registrierungswerte: 1
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE|path, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [f5dd291c6624ea4c02f05a7ad1327d83]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 22
PUP.Optional.OpenCandy, C:\Users\butterfly\AppData\Roaming\OpenCandy, In Quarantäne, [4b876fd6bdcd072f1d04e48ab350b34d],
PUP.Optional.OpenCandy, C:\Users\butterfly\AppData\Roaming\OpenCandy\C102887B7CE643528CF2FCDEDE4C470D, In Quarantäne, [4b876fd6bdcd072f1d04e48ab350b34d],
PUP.Optional.OpenCandy, C:\Users\butterfly\AppData\Roaming\OpenCandy\F85992C8DFF64E8CB9102BE7E229CD49, In Quarantäne, [4b876fd6bdcd072f1d04e48ab350b34d],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\defaults, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\defaults\preferences, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\userCode, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\locale, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\locale\en-US, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Download, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Install, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline\{598415AD-596C-4824-8E26-7CD445F0A335}, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
Dateien: 129
PUP.Optional.Conduit.A, C:\Users\butterfly\AppData\Roaming\OpenCandy\F85992C8DFF64E8CB9102BE7E229CD49\sp-downloader.exe, In Quarantäne, [d5fdd174c4c6f44275ad14341be619e7],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\RHEng\375B784FDE8C4AF0A7F7AC7DBD64697A\setup.exe, In Quarantäne, [30a2271eee9c350173da3fad7889d22e],
PUP.Optional.Trovi.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\searchplugins\trovi-search.xml, In Quarantäne, [389a98adc3c7df57d34becf8a063629e],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, In Quarantäne, [874bc58004867fb7e31058d9778e768a],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, In Quarantäne, [24ae52f3d2b8f44250a449e8c14443bd],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, In Quarantäne, [a52d44011a7016208075cc65d72e6898],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, In Quarantäne, [6b67a2a3b2d8bb7beb0bf839788d5aa6],
PUP.Optional.OpenCandy, C:\Users\butterfly\AppData\Roaming\OpenCandy\C102887B7CE643528CF2FCDEDE4C470D\TuneUpUtilities2014_de-DE.exe, In Quarantäne, [4b876fd6bdcd072f1d04e48ab350b34d],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome.manifest, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\install.rdf, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\057b3f1e108b233f2cf702754d71fd60.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\127c6efa96403d01232c62d61de017ca.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\2874aa00f4b6de4a3d19848ec7d3df6a.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\374e7bea6a98c2bf6478e9201c18781a.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\a1b86fdb5342c004020a79114c2926d6.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\afef091e59cef72d65aab445482798e1.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\background.html, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\browser.xul, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\dialog.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\ffCoreFilesIndex.txt, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\options.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\options.xul, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\search_dialog.xul, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\8197eb45ade2bbab515bcd6450ca65bc.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\20c3d565561c25a7c484d4e846874604.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\44fa50bd3cb85a640174c28465e96e3a.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\4ff3dbdbb04f192face575e46bca96f0.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\54fa52abd6c1d3bf2cb8bf02faa2221d.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\6b3cc89f78b2f5449f5c428e5dedbdf0.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\6bc049206a14afecbba228108e95b9a3.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\6dbf78dc1c04cd5e84663c2d21a8155d.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\804f46e7043f775960f7173cebe791ef.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\977adb65094048cfe7b224f4e683c048.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\ae04d703b7ec615fc4c2cf344cb6af52.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\bf8f28627e7e7db54627bf396c278cb5.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\d9ab866ac7766babd0fa93890fa3c713.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\d9d1e5ebedcc6a393310ddbd72eb9ed2.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\dbe4312452337740bdf131d7c3abcbe7.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\e889cc4ee12dddef9d50b68764d20c0d.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\ce15e6c8c24b452a5c1644d2040010f9.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\0a029f789c5f7b635763d65ff523661b.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\130476735e34a822348b72678e33bbc2.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\1a12ce7406d8b18006584d80696fdc1a.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\23aaccebd1eb43762fdb94eff699eb5e.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\23b1e97f7f557658e92df72a924ea113.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\26cad7d20ff0da713e4128bfb54fd587.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\5d586d9c1a9ea5f4b08137a80853431e.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\5ff049d26e11c11caac89fcba7f7268c.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\79b9d63e4fa895a38a97c5fac9e6e899.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\9bfa19efc6b1ab70bd79e4ddf1deeb5d.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\a3784004f3178949ae07ebddd2d06453.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\c42cc4afb071df2b4d196fbf0b1e53fb.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\ca8cbafdbd21273f91304ae512e8db39.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\ce989fa85a004b59aeef1774ad1d6e12.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\cebfe2edd583c033354c9138893f3f67.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\db5bf309947cabb4f5df05f2785579f1.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\e11dee96a314f667c5f246bb8f5ba789.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\e59d7c1c30441b7e6bf0a4091d28208f.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\f14c5928b15a9b970cb8ccae36a72fb0.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\installer.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\defaults\preferences\prefs.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\manifest.xml, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins.json, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\102.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\13.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\14.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\16.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\17.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\180.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\184.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\192.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\195.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\200.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\220.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\223.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\226.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\242.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\246.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\253.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\262.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\263.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\273.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\281.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\288.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\289.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\334.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\339.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\345.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\354.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\373.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\375.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\380.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\4.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\47.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\64.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\7.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\78.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\9.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\91.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\93.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\userCode\background.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\userCode\extension.js, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\locale\en-US\translations.dtd, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button1.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button2.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button3.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button4.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button5.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\crossrider_statusbar.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\icon128.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\icon16.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\icon24.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\icon48.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\panelarrow-up.png, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\popup.html, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\skin.css, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\update.css, In Quarantäne, [1fb34401f793a88ec0b476fdb25127d9],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll, In Quarantäne, [d3ff82c3672391a564abe99e0ff47987],
PUP.Optional.CrossRider.A, C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "1482de5f60f7ceba27452941cd52268d");), Ersetzt,[a32fef569af010260461121531d57d83]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v4.112 - Bericht erstellt 16/03/2015 um 07:41:32
# Aktualisiert 09/03/2015 von Xplode
# Datenbank : 2015-03-15.1 [Server]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (x86)
# Benutzername : butterfly - BUTTERFLY-PC
# Gestarted von : C:\Users\butterfly\Downloads\AdwCleaner_4.112.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\AdTrustMedia
Ordner Gelöscht : C:\Program Files\globalUpdate
Ordner Gelöscht : C:\Program Files\Check Point Software Technologies LTD
Ordner Gelöscht : C:\Program Files\AdTrustMedia
Ordner Gelöscht : C:\Windows\system32\config\systemprofile\AppData\Roaming\AdTrustMedia
Ordner Gelöscht : C:\Users\butterfly\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\butterfly\AppData\Local\AdTrustMedia
Ordner Gelöscht : C:\Users\butterfly\AppData\Roaming\Activeris
Ordner Gelöscht : C:\Users\butterfly\AppData\Roaming\RHEng
Ordner Gelöscht : C:\Users\butterfly\AppData\Roaming\AdTrustMedia
Ordner Gelöscht : C:\Users\butterfly\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
Datei Gelöscht : C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\Extensions\PrivDog@AdTrustMedia.com.xpi
Datei Gelöscht : C:\Users\Public\Desktop\GeekBuddy.lnk
Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
Datei Gelöscht : C:\Windows\system32\roboot.exe
Datei Gelöscht : C:\Users\BUTTER~1\AppData\Local\Temp\Uninstall.exe
Datei Gelöscht : C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\searchplugins\zonealarm.xml
Datei Gelöscht : C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : LaunchSignup
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [PrivDog@AdTrustMedia.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{987D9269-F8A1-408F-BF62-4397D2F5363E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\GeekBuddyRSP
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17689
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
-\\ Mozilla Firefox v36.0.1 (x86 de)
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a1853a82ece444a8ca6fe9bcf74a655754b6b1c165f0a4ef0866fb063e235ef97com60804.60804.internaldb.Resources_meta.value", "%7B%22popup.html%22%3A%7B%22id%22%3A954465%2C%22ver%22%3A12%2C%[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a1853a82ece444a8ca6fe9bcf74a655754b6b1c165f0a4ef0866fb063e235ef97com60804.60804.internaldb.Resources_resource_954465.value", "%22%3C%21DOCTYPE%20html%3E%5Cr%5Cn%3Chtml%3E%5Cr%5Cn[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a1853a82ece444a8ca6fe9bcf74a655754b6b1c165f0a4ef0866fb063e235ef97com60804.60804.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.crossrider.bic", "1482de5f60f7ceba27452941cd52268d");
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.trusted-ads.ExLst", "{\"u\":{\"v\":\"1.70\",\"d\":\"032414\"},\"h\":{\"pogo.com\":{\"p\":[{\"e\":\"/.*/\",\"r\":[\"/connect\\\\.facebook\\\\.net\\\\/en_US\\\\/all\\\\.js$/i\"]}]}[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.trusted-ads.list_api", "{\"r\":[\"hxxp://24x7homesecurity.com/\",\"hxxp://8tracks.com/\",\"hxxp://a1supplements.com/\",\"hxxp://aactionair.net/\",\"hxxp://abcnews.go.com/\",\"htt[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.trusted-ads.serpInject", "{\"u\":{\"v\":\"2.72\",\"d\":\"061714\"},\"l\":\"hxxp://search.adtrustmedia.com/search_safecontent.php\",\"e\":[{\"u\":\"hxxp://ads.adtrustmedia.com/con[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.trusted-ads.serp_mywebsearch", "\"%2F*!%20serp-mywebsearch%20-%20v0.1.10%20-%202014-04-07%2018%3A21%3A58%20*%2F%0D%0Avar%20u%20%3D%20%7B%7D%3B%0A%0Avar%20Util%20%3D%20%7B%0A%09de[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.zonealarm.hmpgUrl", "hxxp://search.zonealarm.com/?src=hp&tbid=HFA5&Lan=de&gu=be4cafdb64ee4f21b41a766c36a96afb&tu=10G9z00Cj1C01x0&sku=&tstsId=&ver=&");
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.zonealarm.kw_url", "hxxp://search.zonealarm.com/search?src=sp&tbid=HFA5&Lan=de&gu=be4cafdb64ee4f21b41a766c36a96afb&tu=10G9z00Cj1C01x0&sku=&tstsId=&ver=&&q=");
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.zonealarm.newTabUrl", "hxxp://search.zonealarm.com/?src=nt&tbid=HFA5&Lan=de&gu=be4cafdb64ee4f21b41a766c36a96afb&tu=10G9z00Cj1C01x0&sku=&tstsId=&ver=&");
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.zonealarm.tlbrSrchUrl", "hxxp://search.zonealarm.com/search?src=tb&tbid=HFA5&Lan={dfltLng}&gu=be4cafdb64ee4f21b41a766c36a96afb&tu=10G9z00Cj1C01x0&sku=&tstsId=&ver=&&q=");
-\\ Comodo Dragon v36.1.1.21
[C:\Users\butterfly\AppData\Local\Comodo\Dragon\User Data\Default\preferences] - Gelöscht [Extension] : cmaiofennmphjldldcpphcechfnnohja
*************************
AdwCleaner[R0].txt - [12113 Bytes] - [16/03/2015 07:38:30]
AdwCleaner[S0].txt - [12022 Bytes] - [16/03/2015 07:41:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12082 Bytes] ##########
--- --- ---
AdwCleaner Logfile:
Code:
# AdwCleaner v4.112 - Bericht erstellt 16/03/2015 um 07:41:32
# Aktualisiert 09/03/2015 von Xplode
# Datenbank : 2015-03-15.1 [Server]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (x86)
# Benutzername : butterfly - BUTTERFLY-PC
# Gestarted von : C:\Users\butterfly\Downloads\AdwCleaner_4.112.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\AdTrustMedia
Ordner Gelöscht : C:\Program Files\globalUpdate
Ordner Gelöscht : C:\Program Files\Check Point Software Technologies LTD
Ordner Gelöscht : C:\Program Files\AdTrustMedia
Ordner Gelöscht : C:\Windows\system32\config\systemprofile\AppData\Roaming\AdTrustMedia
Ordner Gelöscht : C:\Users\butterfly\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\butterfly\AppData\Local\AdTrustMedia
Ordner Gelöscht : C:\Users\butterfly\AppData\Roaming\Activeris
Ordner Gelöscht : C:\Users\butterfly\AppData\Roaming\RHEng
Ordner Gelöscht : C:\Users\butterfly\AppData\Roaming\AdTrustMedia
Ordner Gelöscht : C:\Users\butterfly\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\cmaiofennmphjldldcpphcechfnnohja
Datei Gelöscht : C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\Extensions\PrivDog@AdTrustMedia.com.xpi
Datei Gelöscht : C:\Users\Public\Desktop\GeekBuddy.lnk
Datei Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk
Datei Gelöscht : C:\Windows\system32\roboot.exe
Datei Gelöscht : C:\Users\BUTTER~1\AppData\Local\Temp\Uninstall.exe
Datei Gelöscht : C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\searchplugins\zonealarm.xml
Datei Gelöscht : C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : LaunchSignup
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [PrivDog@AdTrustMedia.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{987D9269-F8A1-408F-BF62-4397D2F5363E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\GeekBuddyRSP
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17689
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
-\\ Mozilla Firefox v36.0.1 (x86 de)
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a1853a82ece444a8ca6fe9bcf74a655754b6b1c165f0a4ef0866fb063e235ef97com60804.60804.internaldb.Resources_meta.value", "%7B%22popup.html%22%3A%7B%22id%22%3A954465%2C%22ver%22%3A12%2C%[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a1853a82ece444a8ca6fe9bcf74a655754b6b1c165f0a4ef0866fb063e235ef97com60804.60804.internaldb.Resources_resource_954465.value", "%22%3C%21DOCTYPE%20html%3E%5Cr%5Cn%3Chtml%3E%5Cr%5Cn[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.a1853a82ece444a8ca6fe9bcf74a655754b6b1c165f0a4ef0866fb063e235ef97com60804.60804.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.crossrider.bic", "1482de5f60f7ceba27452941cd52268d");
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.trusted-ads.ExLst", "{\"u\":{\"v\":\"1.70\",\"d\":\"032414\"},\"h\":{\"pogo.com\":{\"p\":[{\"e\":\"/.*/\",\"r\":[\"/connect\\\\.facebook\\\\.net\\\\/en_US\\\\/all\\\\.js$/i\"]}]}[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.trusted-ads.list_api", "{\"r\":[\"hxxp://24x7homesecurity.com/\",\"hxxp://8tracks.com/\",\"hxxp://a1supplements.com/\",\"hxxp://aactionair.net/\",\"hxxp://abcnews.go.com/\",\"htt[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.trusted-ads.serpInject", "{\"u\":{\"v\":\"2.72\",\"d\":\"061714\"},\"l\":\"hxxp://search.adtrustmedia.com/search_safecontent.php\",\"e\":[{\"u\":\"hxxp://ads.adtrustmedia.com/con[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.trusted-ads.serp_mywebsearch", "\"%2F*!%20serp-mywebsearch%20-%20v0.1.10%20-%202014-04-07%2018%3A21%3A58%20*%2F%0D%0Avar%20u%20%3D%20%7B%7D%3B%0A%0Avar%20Util%20%3D%20%7B%0A%09de[...]
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.zonealarm.hmpgUrl", "hxxp://search.zonealarm.com/?src=hp&tbid=HFA5&Lan=de&gu=be4cafdb64ee4f21b41a766c36a96afb&tu=10G9z00Cj1C01x0&sku=&tstsId=&ver=&");
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.zonealarm.kw_url", "hxxp://search.zonealarm.com/search?src=sp&tbid=HFA5&Lan=de&gu=be4cafdb64ee4f21b41a766c36a96afb&tu=10G9z00Cj1C01x0&sku=&tstsId=&ver=&&q=");
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.zonealarm.newTabUrl", "hxxp://search.zonealarm.com/?src=nt&tbid=HFA5&Lan=de&gu=be4cafdb64ee4f21b41a766c36a96afb&tu=10G9z00Cj1C01x0&sku=&tstsId=&ver=&");
[ks5gno9e.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.zonealarm.tlbrSrchUrl", "hxxp://search.zonealarm.com/search?src=tb&tbid=HFA5&Lan={dfltLng}&gu=be4cafdb64ee4f21b41a766c36a96afb&tu=10G9z00Cj1C01x0&sku=&tstsId=&ver=&&q=");
-\\ Comodo Dragon v36.1.1.21
[C:\Users\butterfly\AppData\Local\Comodo\Dragon\User Data\Default\preferences] - Gelöscht [Extension] : cmaiofennmphjldldcpphcechfnnohja
*************************
AdwCleaner[R0].txt - [12113 Bytes] - [16/03/2015 07:38:30]
AdwCleaner[S0].txt - [12022 Bytes] - [16/03/2015 07:41:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12082 Bytes] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.3 (03.01.2015:1)
OS: Windows 7 Ultimate x86
Ran by butterfly on 16.03.2015 at 7:49:43,98
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\privdogservice
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files\myfree codec"
~~~ FireFox
Successfully deleted the following from C:\Users\butterfly\AppData\Roaming\mozilla\firefox\profiles\ks5gno9e.default\prefs.js
user_pref("extensions.trusted-ads.TrustAd", "{\"r\":[{\"t\":\"FQDN\",\"r\":\"trustedads.adtrustmedia.com\",\"c\":[{\"i\":\"1\",\"s\":[\"mmgads.com\",\"www.ad2ad.ir\",\"www.pro
Emptied folder: C:\Users\butterfly\AppData\Roaming\mozilla\firefox\profiles\ks5gno9e.default\minidumps [9 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.03.2015 at 8:31:44,71
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.3 (03.01.2015:1)
OS: Windows 7 Ultimate x86
Ran by butterfly on 16.03.2015 at 7:49:43,98
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\privdogservice
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files\myfree codec"
~~~ FireFox
Successfully deleted the following from C:\Users\butterfly\AppData\Roaming\mozilla\firefox\profiles\ks5gno9e.default\prefs.js
user_pref("extensions.trusted-ads.TrustAd", "{\"r\":[{\"t\":\"FQDN\",\"r\":\"trustedads.adtrustmedia.com\",\"c\":[{\"i\":\"1\",\"s\":[\"mmgads.com\",\"www.ad2ad.ir\",\"www.pro
Emptied folder: C:\Users\butterfly\AppData\Roaming\mozilla\firefox\profiles\ks5gno9e.default\minidumps [9 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.03.2015 at 8:31:44,71
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by butterfly (administrator) on BUTTERFLY-PC on 16-03-2015 08:40:54
Running from C:\Users\butterfly\Downloads
Loaded Profiles: butterfly (Available profiles: butterfly)
Platform: Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\launcher_service.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Nitro PDF Software) C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\SAMSUNG\Kies\KiesTrayAgent.exe
(Comodo Security Solutions, Inc.) C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe
(WiseCleaner.com) C:\Program Files\Wise\Wise Care 365\WiseTray.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cavwp.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(COMODO) C:\Program Files\Comodo\COMODO Internet Security\cmdvirth.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7703072 2014-02-28] (Realtek Semiconductor)
HKLM\...\Run: [KiesTrayAgent] => C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311616 2014-04-23] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1243864 2015-02-04] (COMODO)
HKLM\...\Run: [tvncontrol] => C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-03-12] (Comodo Security Solutions, Inc.)
HKU\S-1-5-21-231648146-3933761938-2758524011-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-231648146-3933761938-2758524011-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-231648146-3933761938-2758524011-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-231648146-3933761938-2758524011-1000\Software\Microsoft\Internet Explorer\Main,Start Page = Websuche
HKU\S-1-5-21-231648146-3933761938-2758524011-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Upgrade to Google Chrome
SearchScopes: HKLM -> {1D51B119-24C9-4A97-800C-50696C0819C0} URL = hxxp://www.startseite24.net/?q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-231648146-3933761938-2758524011-1000 -> {1D51B119-24C9-4A97-800C-50696C0819C0} URL = hxxp://www.startseite24.net/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-231648146-3933761938-2758524011-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKU\S-1-5-21-231648146-3933761938-2758524011-1000 -> {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
Tcpip\..\Interfaces\{A47ED7B1-E510-46D6-8FF3-449A68CA448B}: [NameServer] 156.154.70.25,156.154.71.25
Tcpip\..\Interfaces\{B7563E8F-3600-4D19-8618-A8BC7C8827A2}: [NameServer] 156.154.70.25,156.154.71.25
FireFox:
========
FF ProfilePath: C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-25] ()
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll [2014-08-13] (Google, Inc.)
FF Plugin: @nitropdf.com/NitroPDF -> C:\Program Files\Nitro\Reader 3\npnitromozilla.dll [2013-07-26] (Nitro PDF)
FF SearchPlugin: C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\searchplugins\websuche.xml [2015-02-09]
FF Extension: Easy Youtube Video Downloader Express - C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\Extensions\{b9acf540-acba-11e1-8ccb-001fd0e08bd4}.xpi [2014-09-20]
FF Extension: Adblock Plus - C:\Users\butterfly\AppData\Roaming\Mozilla\Firefox\Profiles\ks5gno9e.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-09-22]
FF Extension: UITBAutoInstaller - C:\Program Files\Mozilla Firefox\distribution\bundles\{edd7fc99-d65c-4979-85c2-ddeed30c50c7} [2015-03-06]
FF HKU\S-1-5-21-231648146-3933761938-2758524011-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff [2014-11-15]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [cmaiofennmphjldldcpphcechfnnohja] - C:\Program Files\AdTrustMedia\PrivDog\PrivDog_chrome.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
Locked "BFE" service could not be unlocked. <===== ATTENTION
S2 CLPSLauncher; C:\Program Files\Common Files\COMODO\launcher_service.exe [70872 2015-03-12] (Comodo Security Solutions, Inc.)
U2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5868440 2015-02-04] (COMODO)
U3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [1664216 2015-02-04] (COMODO)
U2 DragonUpdater; C:\Program Files\Comodo\Dragon\dragon_updater.exe [2370240 2014-11-27] (Comodo Security Solutions, Inc.)
U2 GeekBuddyRSP; C:\Program Files\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-03-12] (Comodo Security Solutions, Inc.)
U2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-03-16] (Malwarebytes Corporation)
U2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2015-03-16] (Malwarebytes Corporation)
U2 NitroReaderDriverReadSpool3; C:\Program Files\Nitro\Reader 3\NitroPDFReaderDriverService3.exe [196624 2013-07-26] (Nitro PDF Software)
U3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [35064 2014-06-26] (Windows (R) Win 7 DDK provider)
U1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [17088 2015-01-30] (COMODO)
U1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [618072 2015-01-30] (COMODO)
U1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [41248 2015-01-30] (COMODO)
U0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed]
U1 HMD; C:\Windows\System32\DRIVERS\hmd.sys [15400 2014-06-26] ()
U1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [91200 2015-01-30] (COMODO)
U0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2013-07-17] (Kaspersky Lab ZAO)
U1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [485472 2013-10-08] (Kaspersky Lab ZAO)
U3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-03-16] (Malwarebytes Corporation)
U3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-03-16] (Malwarebytes Corporation)
U3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-03-16] (Malwarebytes Corporation)
U3 PNPMEM; C:\Windows\System32\DRIVERS\pnpmem.sys [13312 2009-07-14] (Microsoft Corporation)
U0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
U3 catchme; \??\C:\Users\BUTTER~1\AppData\Local\Temp\catchme.sys [X]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2013-10-08] (Kaspersky Lab ZAO)
U3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-16 08:40 - 2015-03-16 08:40 - 00009882 _____ () C:\Users\butterfly\Downloads\FRST.txt
2015-03-16 08:31 - 2015-03-16 08:31 - 00001255 _____ () C:\Users\butterfly\Desktop\JRT.txt
2015-03-16 07:48 - 2015-03-16 07:48 - 01388333 _____ (Thisisu) C:\Users\butterfly\Downloads\JRT.exe
2015-03-16 07:38 - 2015-03-16 07:41 - 00000000 ____D () C:\AdwCleaner
2015-03-16 07:37 - 2015-03-16 07:37 - 02171392 _____ () C:\Users\butterfly\Downloads\AdwCleaner_4.112.exe
2015-03-16 07:34 - 2015-03-16 07:34 - 00043095 _____ () C:\Users\butterfly\Desktop\mbam.txt
2015-03-16 07:07 - 2015-03-16 07:49 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-16 07:07 - 2015-03-16 07:07 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-03-16 07:07 - 2015-03-16 07:07 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-03-16 07:07 - 2015-03-16 07:07 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-16 07:07 - 2015-03-16 07:07 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-16 07:07 - 2015-03-16 07:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-16 07:07 - 2015-03-16 07:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-16 07:07 - 2015-03-16 07:07 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-03-16 07:05 - 2015-03-16 07:05 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\butterfly\Downloads\mbam-setup-2.0.4.1028.exe
2015-03-15 13:27 - 2015-03-15 13:27 - 00016031 _____ () C:\ComboFix.txt
2015-03-15 13:22 - 2015-03-16 07:43 - 00025912 _____ () C:\Windows\PFRO.log
2015-03-15 13:11 - 2015-03-15 13:06 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-03-15 13:11 - 2015-03-15 13:06 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-03-15 13:11 - 2015-03-15 13:06 - 00256000 _____ () C:\Windows\PEV.exe
2015-03-15 13:11 - 2015-03-15 13:06 - 00208896 _____ () C:\Windows\MBR.exe
2015-03-15 13:11 - 2015-03-15 13:06 - 00098816 _____ () C:\Windows\sed.exe
2015-03-15 13:11 - 2015-03-15 13:06 - 00080412 _____ () C:\Windows\grep.exe
2015-03-15 13:11 - 2015-03-15 13:06 - 00068096 _____ () C:\Windows\zip.exe
2015-03-15 13:11 - 2015-03-15 13:06 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-03-15 13:06 - 2015-03-15 13:28 - 00000000 ____D () C:\Qoobox
2015-03-15 13:06 - 2015-03-15 13:25 - 00000000 ____D () C:\Windows\erdnt
2015-03-15 13:05 - 2015-03-15 13:05 - 05615380 ____R (Swearware) C:\Users\butterfly\Downloads\ComboFix.exe
2015-03-15 07:54 - 2015-03-15 07:54 - 00001222 _____ () C:\Users\butterfly\Desktop\Revo Uninstaller.lnk
2015-03-15 07:54 - 2015-03-15 07:54 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-03-15 07:53 - 2015-03-15 07:53 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\butterfly\Downloads\revosetup95.exe
2015-03-13 12:24 - 2015-03-13 12:25 - 00034228 _____ () C:\Users\butterfly\Downloads\Addition.txt
2015-03-13 12:21 - 2015-03-13 12:25 - 00000000 ____D () C:\FRST
2015-03-13 12:19 - 2015-03-13 12:19 - 01135104 _____ (Farbar) C:\Users\butterfly\Downloads\FRST.exe
2015-03-12 17:28 - 2015-03-12 17:28 - 00000000 ____D () C:\Program Files\Common Files\COMODO
2015-03-11 14:10 - 2015-03-11 14:10 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 14:10 - 2015-03-11 14:10 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 14:10 - 2015-03-11 14:10 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 14:10 - 2015-03-11 14:10 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 14:10 - 2015-03-11 14:10 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 14:10 - 2015-03-11 14:10 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 14:10 - 2015-03-11 14:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2015-03-11 14:10 - 2015-03-11 14:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 14:10 - 2015-02-20 03:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 14:09 - 2015-03-11 14:09 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 14:09 - 2015-03-11 14:09 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 14:09 - 2015-03-11 14:09 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 14:09 - 2015-03-11 14:09 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 14:09 - 2015-03-11 14:09 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 14:09 - 2015-03-11 14:09 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-11 14:08 - 2015-03-11 14:08 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-11 14:08 - 2015-03-11 14:08 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 14:08 - 2015-03-11 14:08 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-11 14:08 - 2015-03-11 14:08 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-11 14:08 - 2015-03-11 14:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-11 14:08 - 2015-03-11 14:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-11 14:08 - 2015-03-11 14:08 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-11 14:08 - 2015-03-11 14:08 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-06 10:01 - 2015-03-06 10:01 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-03-03 21:23 - 2015-03-03 21:23 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-03-03 21:23 - 2015-03-03 21:23 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-03-03 21:23 - 2015-03-03 21:23 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-03-02 07:35 - 2015-03-02 07:35 - 03044736 _____ (Enigma Software Group USA, LLC.) C:\Users\butterfly\Downloads\SpyHunter-installer.exe
2015-02-26 07:12 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-02-25 07:34 - 2015-03-16 08:28 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-24 15:47 - 2015-02-24 15:47 - 00064024 _____ () C:\Users\butterfly\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-15 19:01 - 2015-02-15 19:02 - 00000000 ____D () C:\Users\butterfly\Desktop\Hochzeit
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-16 08:34 - 2014-12-30 21:27 - 00048330 _____ () C:\Windows\system32\Drivers\fvstore.dat
2015-03-16 08:33 - 2014-08-15 18:24 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat
2015-03-16 07:51 - 2009-07-14 05:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-03-16 07:51 - 2009-07-14 05:34 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-03-16 07:43 - 2015-02-10 10:28 - 00003657 _____ () C:\Windows\setupact.log
2015-03-16 07:43 - 2014-09-20 21:35 - 00002006 _____ () C:\Users\Public\Desktop\Wise Care 365.lnk
2015-03-16 07:43 - 2014-09-20 21:35 - 00000406 _____ () C:\Windows\Tasks\Wise Care 365.job
2015-03-16 07:43 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-16 07:42 - 2015-02-10 10:31 - 01173424 _____ () C:\Windows\WindowsUpdate.log
2015-03-15 13:27 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2015-03-15 13:22 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2015-03-15 13:21 - 2009-07-14 03:03 - 36175872 _____ () C:\Windows\system32\config\SOFTWARE.bak
2015-03-15 13:21 - 2009-07-14 03:03 - 18612224 _____ () C:\Windows\system32\config\SYSTEM.bak
2015-03-15 13:21 - 2009-07-14 03:03 - 00524288 _____ () C:\Windows\system32\config\DEFAULT.bak
2015-03-15 13:21 - 2009-07-14 03:03 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2015-03-15 13:21 - 2009-07-14 03:03 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2015-03-15 13:06 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2015-03-15 07:48 - 2014-09-20 21:35 - 00000000 ____D () C:\Users\butterfly\AppData\Roaming\Wise Care 365
2015-03-12 17:28 - 2014-08-15 18:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
2015-03-12 12:42 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2015-03-12 06:26 - 2015-02-10 10:27 - 00286616 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-12 06:24 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-03-12 06:21 - 2013-12-14 00:10 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-12 06:17 - 2013-12-14 00:10 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-10 15:39 - 2014-09-20 21:35 - 00000386 _____ () C:\Windows\Tasks\Wise Turbo Checker.job
2015-03-09 07:42 - 2014-02-28 23:03 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-03-05 20:41 - 2014-12-23 21:07 - 00000000 ____D () C:\Users\butterfly\Desktop\Bilder
2015-03-04 22:13 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing
2015-02-25 07:34 - 2014-02-28 23:08 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-02-25 07:34 - 2014-02-28 23:08 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-02-23 23:19 - 2014-12-04 15:29 - 00018112 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\browserMon.sys
Some content of TEMP:
====================
C:\Users\butterfly\AppData\Local\Temp\Quarantine.exe
C:\Users\butterfly\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-05 15:21
==================== End Of Log ============================
--- --- ---
--- --- ---