marvin1105 | 30.06.2015 16:06 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 27.06.2015
Suchlauf-Zeit: 09:03:58
Logdatei: mbam_27-06.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.26.08
Rootkit Datenbank: v2015.06.26.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Marvin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 514894
Verstrichene Zeit: 53 Min, 27 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 1
PUP.Optional.Multiplug.A, C:\Program Files (x86)\SoftwareForce\SoftwareForce.dll, Löschen bei Neustart, [1b35596646440b2b9e34e36c6b97649c],
Registrierungsschlüssel: 56
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{03D3D23D-C575-4060-8BE2-C234ACCB729B}, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{03D3D23D-C575-4060-8BE2-C234ACCB729B}, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{03D3D23D-C575-4060-8BE2-C234ACCB729B}, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P03D3D23D_C575_4060_8BE2_C234ACCB729B_.P03D3D23D_C575_4060_8BE2_C234ACCB729B_, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P03D3D23D_C575_4060_8BE2_C234ACCB729B_.P03D3D23D_C575_4060_8BE2_C234ACCB729B_.9, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P03D3D23D_C575_4060_8BE2_C234ACCB729B_.P03D3D23D_C575_4060_8BE2_C234ACCB729B_, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P03D3D23D_C575_4060_8BE2_C234ACCB729B_.P03D3D23D_C575_4060_8BE2_C234ACCB729B_.9, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P03D3D23D_C575_4060_8BE2_C234ACCB729B_.P03D3D23D_C575_4060_8BE2_C234ACCB729B_, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P03D3D23D_C575_4060_8BE2_C234ACCB729B_.P03D3D23D_C575_4060_8BE2_C234ACCB729B_.9, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{03D3D23D-C575-4060-8BE2-C234ACCB729B}, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{03D3D23D-C575-4060-8BE2-C234ACCB729B}, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{03D3D23D-C575-4060-8BE2-C234ACCB729B}, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{03D3D23D-C575-4060-8BE2-C234ACCB729B}, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{03D3D23D-C575-4060-8BE2-C234ACCB729B}\INPROCSERVER32, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{062A6244-B07F-4074-8730-69EA166B2830}, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{062A6244-B07F-4074-8730-69EA166B2830}, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{062A6244-B07F-4074-8730-69EA166B2830}, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P062A6244_B07F_4074_8730_69EA166B2830_.P062A6244_B07F_4074_8730_69EA166B2830_, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P062A6244_B07F_4074_8730_69EA166B2830_.P062A6244_B07F_4074_8730_69EA166B2830_.9, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P062A6244_B07F_4074_8730_69EA166B2830_.P062A6244_B07F_4074_8730_69EA166B2830_, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P062A6244_B07F_4074_8730_69EA166B2830_.P062A6244_B07F_4074_8730_69EA166B2830_.9, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P062A6244_B07F_4074_8730_69EA166B2830_.P062A6244_B07F_4074_8730_69EA166B2830_, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P062A6244_B07F_4074_8730_69EA166B2830_.P062A6244_B07F_4074_8730_69EA166B2830_.9, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{062A6244-B07F-4074-8730-69EA166B2830}, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{062A6244-B07F-4074-8730-69EA166B2830}, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{062A6244-B07F-4074-8730-69EA166B2830}, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{062A6244-B07F-4074-8730-69EA166B2830}, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{062A6244-B07F-4074-8730-69EA166B2830}\INPROCSERVER32, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.Multiplug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{6C998B44-82D8-CC7E-D847-4CD73036412A}, In Quarantäne, [c18f3e81008a053101f18daacb37cb35],
PUP.Optional.Multiplug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5CDF2354-26AF-2DBC-1012-44FEDFCC75BB}, In Quarantäne, [56fa16a9aae0063081711b1c91715aa6],
PUP.Optional.Multiplug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{730C1F02-ABB6-7601-60ED-659A59700742}, In Quarantäne, [f9573c83cac02c0a60928fa88f735ba5],
PUP.Optional.Multiplug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{4E5FE462-1A84-47B4-3411-C72434AAD86C}, In Quarantäne, [e967e1de8dfd6accae44cd6ae41e1ae6],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A1965763-A486-4E1E-B574-19E44B3842E8}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9CABED0D-99E4-457C-A192-D528B389F53C}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{CED50656-D422-418C-8A20-A0F455842FA5}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D8B5D394-6974-40D4-9DFB-DAAD64E422D6}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{ED2A17AC-87A9-4640-9DE9-07AB5B63E902}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9CABED0D-99E4-457C-A192-D528B389F53C}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{CED50656-D422-418C-8A20-A0F455842FA5}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D8B5D394-6974-40D4-9DFB-DAAD64E422D6}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{ED2A17AC-87A9-4640-9DE9-07AB5B63E902}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{9CABED0D-99E4-457C-A192-D528B389F53C}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{CED50656-D422-418C-8A20-A0F455842FA5}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{D8B5D394-6974-40D4-9DFB-DAAD64E422D6}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{ED2A17AC-87A9-4640-9DE9-07AB5B63E902}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A1965763-A486-4E1E-B574-19E44B3842E8}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{A1965763-A486-4E1E-B574-19E44B3842E8}, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
Security.Hijack, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CCLEANER.EXE, In Quarantäne, [361ae9d65a304cea6c46675d08fc58a8],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [1d330db251390135bada40529c6945bb],
PUP.Optional.CinemaPlus.A, HKLM\SOFTWARE\WOW6432NODE\CinemaPlus-3.2cV17.05-nv-ie, In Quarantäne, [0e42843b1872eb4bc937927d56aea35d],
PUP.Optional.Infonaut.A, HKLM\SOFTWARE\WOW6432NODE\Infonaut_1.10.0.14, In Quarantäne, [3917cef193f75adc06d7d029f211d52b],
Security.Hijack, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CCLEANER.EXE, In Quarantäne, [b59bbf00f7937abc6a48873d25dfbd43],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{9714eddf}, In Quarantäne, [64ecd9e6e2a8b1859550a6ea8a7b09f7],
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE, In Quarantäne, [2828308fc3c7c274553fc1d14eb79967],
PUP.Optional.SoftwareForce.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\9714eddf, In Quarantäne, [9cb4a31c5b2fe254f9097d86a95b1be5],
PUP.Optional.CinemaPlus.A, HKU\S-1-5-21-2545573064-1671415295-1629012448-1000\SOFTWARE\CinemaPlus-3.2cV17.05-nv-ie, In Quarantäne, [a1afccf37b0f2a0c47babc53ce3658a8],
Registrierungswerte: 12
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\CLASSES\.HTML\OPENWITHPROGIDS|CRSBRWSHTML, In Quarantäne, [f65a0eb15f2b57dffbf75f2f4db87090],
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\CLASSES\.HTM\OPENWITHPROGIDS|CRSBRWSHTML, In Quarantäne, [fa5606b902885ed8c031721c050056aa],
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\.HTML\OPENWITHPROGIDS|CRSBRWSHTML, In Quarantäne, [1f31b20d0486310533bfb1dd4abb35cb],
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\CLASSES\WOW6432NODE\.HTM\OPENWITHPROGIDS|CRSBRWSHTML, In Quarantäne, [e7692f9005854cead61bd0be996c36ca],
Security.Hijack, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CCLEANER.EXE|Debugger, "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe", In Quarantäne, [361ae9d65a304cea6c46675d08fc58a8]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [1d330db251390135bada40529c6945bb]
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\REGISTEREDAPPLICATIONS|Crossbrowse, Software\Clients\StartMenuInternet\Crossbrowse\Capabilities, In Quarantäne, [d779ecd34f3b8da9301984097c894fb1]
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\.HTML\OPENWITHPROGIDS|CRSBRWSHTML, In Quarantäne, [ee6299262268d75f7a78563823e2748c],
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\.HTM\OPENWITHPROGIDS|CRSBRWSHTML, In Quarantäne, [a6aa645b781251e56d84543aee17c13f],
Security.Hijack, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\CCLEANER.EXE|Debugger, "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe", In Quarantäne, [b59bbf00f7937abc6a48873d25dfbd43]
PUM.Security.Hijack.DisableChromeUpdates, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\UPDATE|DisableAutoUpdateChecksCheckboxValue, 1, In Quarantäne, [2828308fc3c7c274553fc1d14eb79967]
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\WOW6432NODE\REGISTEREDAPPLICATIONS|Crossbrowse, Software\Clients\StartMenuInternet\Crossbrowse\Capabilities, In Quarantäne, [ea665867f397d95d53f63c519174d62a]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 9
PUP.Optional.WebSaver.A, C:\Program Files (x86)\wEbsaver, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\memcdolmmnmnleeiodllgpibdjlkbpim\167, In Quarantäne, [331d714e1872b58149c1701a679ec040],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\memcdolmmnmnleeiodllgpibdjlkbpim, In Quarantäne, [331d714e1872b58149c1701a679ec040],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\A3C@K.com\content, In Quarantäne, [7cd46c53b8d2d46204140d7d7f864db3],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\A3C@K.com, In Quarantäne, [7cd46c53b8d2d46204140d7d7f864db3],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\vpmI@X.net\content, In Quarantäne, [a1aff5caa0eaec4aa37553370ff62fd1],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\vpmI@X.net, In Quarantäne, [a1aff5caa0eaec4aa37553370ff62fd1],
PUP.Optional.WebSaver.A, C:\Program Files (x86)\websavear, In Quarantäne, [440c37889febbb7b8b63810992737a86],
PUP.Optional.KikBlaster.A, C:\ProgramData\Kikblaster, In Quarantäne, [034d754af6947bbb50e50ee682816c94],
Dateien: 39
PUP.Optional.Multiplug.A, C:\Program Files (x86)\SoftwareForce\SoftwareForce.dll, Löschen bei Neustart, [1b35596646440b2b9e34e36c6b97649c],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\wEbsaver\1mt0Cqv7235L8K.x64.dll, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\wEbsaver\1mt0Cqv7235L8K.dll, In Quarantäne, [113f803fd9b19b9bc7a85221bd4541bf],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\websavear\OEPOkQdTgSTejJ.x64.dll, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\websavear\OEPOkQdTgSTejJ.dll, In Quarantäne, [143c3887fd8d4aec3a35017218ea22de],
PUP.Optional.KikBlaster.A, C:\ProgramData\Kikblaster\NSISHelper.dll, In Quarantäne, [2a262e91e9a1ae88275268f41be7bc44],
PUP.Optional.Crossrider, C:\Program Files (x86)\Adobe\b05f4dc8-3eb1-4310-b007-92743b80b6d6.dll, In Quarantäne, [93bdf5caa3e78ea8d46e1f4bac5641bf],
PUP.Optional.Crossrider, C:\Program Files (x86)\b05f4dc8-3eb1-4310-b007-92743b80b6d6\22db4f5e-694f-4323-adb1-c8de975adbc2.dll, In Quarantäne, [b39df2cd8bff5fd7c37f8dddfc06f50b],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\VIA3 Video Conferencing Messaging\VIA3 Video Conferencing Messaging.exe, In Quarantäne, [c18f3e81008a053101f18daacb37cb35],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\websavear\OEPOkQdTgSTejJ.exe, In Quarantäne, [f858ab145b2f9d99ea0886b117eb5fa1],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\wEbsaver\1mt0Cqv7235L8K.exe, In Quarantäne, [7fd114ab0c7e5cdaeb073ef9bd4542be],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\Weebsaver\Weebsaver.exe, In Quarantäne, [56fa16a9aae0063081711b1c91715aa6],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\Mozilla Firefox\dbghelp.dll, In Quarantäne, [9bb5a61995f5ea4c0106343d5aa86b95],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\ReAldEal\Y05QoAd37KaLG7.exe, In Quarantäne, [f25e902f3951fa3c3cb6ae89cc363fc1],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\realodeala\PFHOOcnKjn0ess.exe, In Quarantäne, [f9573c83cac02c0a60928fa88f735ba5],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\reeAlddeal\reeAlddeal.exe, In Quarantäne, [e56b9a25aedccb6b09e954e3de24956b],
PUP.Optional.Multiplug.A, C:\Program Files (x86)\Responsive Inspector\Responsive Inspector.exe, In Quarantäne, [e967e1de8dfd6accae44cd6ae41e1ae6],
PUP.Optional.AppDataFR.A, C:\Users\Marvin\AppData\Roaming\appdataFr25.bin, In Quarantäne, [e46c3b842f5b86b0f43a3abcf70c8977],
PUP.Optional.PricePeep.A, C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage, In Quarantäne, [440ce3dc98f25cdab37d31c7de258b75],
PUP.Optional.PricePeep.A, C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal, In Quarantäne, [30209827d1b91620be72a652020103fd],
PUP.Optional.WebSaver.A, C:\Program Files (x86)\wEbsaver\1mt0Cqv7235L8K.tlb, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.WebSaver.A, C:\Program Files (x86)\wEbsaver\1mt0Cqv7235L8K.dat, In Quarantäne, [75dba21dbfcb94a24e65d13ed72d33cd],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\memcdolmmnmnleeiodllgpibdjlkbpim\167\lsdb.js, In Quarantäne, [331d714e1872b58149c1701a679ec040],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\memcdolmmnmnleeiodllgpibdjlkbpim\167\background.html, In Quarantäne, [331d714e1872b58149c1701a679ec040],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\memcdolmmnmnleeiodllgpibdjlkbpim\167\content.js, In Quarantäne, [331d714e1872b58149c1701a679ec040],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\memcdolmmnmnleeiodllgpibdjlkbpim\167\L5.js, In Quarantäne, [331d714e1872b58149c1701a679ec040],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\memcdolmmnmnleeiodllgpibdjlkbpim\167\manifest.json, In Quarantäne, [331d714e1872b58149c1701a679ec040],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\A3C@K.com\content\bg.js, In Quarantäne, [7cd46c53b8d2d46204140d7d7f864db3],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\A3C@K.com\bootstrap.js, In Quarantäne, [7cd46c53b8d2d46204140d7d7f864db3],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\A3C@K.com\chrome.manifest, In Quarantäne, [7cd46c53b8d2d46204140d7d7f864db3],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\A3C@K.com\install.rdf, In Quarantäne, [7cd46c53b8d2d46204140d7d7f864db3],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\vpmI@X.net\content\bg.js, In Quarantäne, [a1aff5caa0eaec4aa37553370ff62fd1],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\vpmI@X.net\bootstrap.js, In Quarantäne, [a1aff5caa0eaec4aa37553370ff62fd1],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\vpmI@X.net\chrome.manifest, In Quarantäne, [a1aff5caa0eaec4aa37553370ff62fd1],
PUP.Optional.MultiPlug.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\vpmI@X.net\install.rdf, In Quarantäne, [a1aff5caa0eaec4aa37553370ff62fd1],
PUP.Optional.WebSaver.A, C:\Program Files (x86)\websavear\OEPOkQdTgSTejJ.tlb, In Quarantäne, [440c37889febbb7b8b63810992737a86],
PUP.Optional.WebSaver.A, C:\Program Files (x86)\websavear\OEPOkQdTgSTejJ.dat, In Quarantäne, [440c37889febbb7b8b63810992737a86],
PUP.Optional.KikBlaster.A, C:\ProgramData\Kikblaster\RfndNSIS.dll, In Quarantäne, [034d754af6947bbb50e50ee682816c94],
PUP.Optional.CrossRider.A, C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "14d62da8cba3b88c36a4721b1bf5971a");), Ersetzt,[f55b10af434743f3ea83533a14f259a7]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) P.S. wenn ich versuche die zoek.exe zu starten, dann wird gefragt, ob ich es zulassen möchte, aber danach passiert nichts mehr
Das Öffnen als Administrator hab ich schon versucht
Etwas später ging es dann doch und ich glaube es hat deutlich was gebracht Code:
Zoek.exe v5.0.0.0 Updated 04-May-2015
Tool run by Marvin on 30.06.2015 at 16:15:18,82.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Marvin\Desktop\zoek.exe [Scan all users] [Script inserted]
==== System Restore Info ======================
30.06.2015 16:19:40 Zoek.exe System Restore Point Created Successfully.
==== Empty Folders Check ======================
C:\PROGRA~2\b05f4dc8-3eb1-4310-b007-92743b80b6d6 deleted successfully
C:\PROGRA~2\Daedalic Entertainment deleted successfully
C:\PROGRA~2\Malwarebytes' Anti-Malware deleted successfully
C:\PROGRA~2\MSXML 4.0 deleted successfully
C:\PROGRA~2\OXXOGames deleted successfully
C:\PROGRA~2\SoftwareForce deleted successfully
C:\PROGRA~2\COMMON~1\EAInstaller deleted successfully
C:\Program Files\Symantec deleted successfully
C:\PROGRA~3\DAEMON Tools Pro deleted successfully
C:\PROGRA~3\install_clap deleted successfully
C:\PROGRA~3\Reflection deleted successfully
C:\PROGRA~3\Reflector deleted successfully
C:\PROGRA~3\Synetic deleted successfully
C:\PROGRA~3\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3} deleted successfully
C:\PROGRA~3\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} deleted successfully
C:\PROGRA~3\{32364CEA-7855-4A3C-B674-53D8E9B97936} deleted successfully
C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001} deleted successfully
C:\PROGRA~3\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} deleted successfully
C:\Users\Marvin\AppData\Roaming\DAEMON Tools Pro deleted successfully
C:\Users\Marvin\AppData\Roaming\IrfanView deleted successfully
C:\Users\Marvin\AppData\Roaming\Malwarebytes deleted successfully
C:\Users\Marvin\AppData\Roaming\Media Player Classic deleted successfully
C:\Users\Marvin\AppData\Roaming\Opera Software deleted successfully
C:\Users\Marvin\AppData\Roaming\Solveig Multimedia deleted successfully
C:\Users\Marvin\AppData\Roaming\uTorrent deleted successfully
C:\Users\Marvin\AppData\Roaming\Video DVD Maker FREE deleted successfully
C:\Users\Marvin\AppData\Local\CrashDumps deleted successfully
C:\Users\Marvin\AppData\Local\Opera Software deleted successfully
C:\Users\Marvin\AppData\Local\WarThunder deleted successfully
==== Deleting CLSID Registry Keys ======================
HKEY_USERS\S-1-5-21-2545573064-1671415295-1629012448-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\S-1-5-21-2545573064-1671415295-1629012448-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_USERS\S-1-5-21-2545573064-1671415295-1629012448-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D} deleted successfully
HKEY_USERS\S-1-5-21-2545573064-1671415295-1629012448-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D} deleted successfully
HKEY_USERS\S-1-5-21-2545573064-1671415295-1629012448-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C442AC41-9200-4770-8CC0-7CDB4F245C55} deleted successfully
HKEY_USERS\S-1-5-21-2545573064-1671415295-1629012448-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C442AC41-9200-4770-8CC0-7CDB4F245C55} deleted successfully
HKEY_CLASSES_ROOT\CLSID\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{C3101A8B-0EE1-4612-BFE9-41FFC1A3C19D} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C442AC41-9200-4770-8CC0-7CDB4F245C55} deleted successfully
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{C442AC41-9200-4770-8CC0-7CDB4F245C55} deleted successfully
==== Deleting CLSID Registry Values ======================
HKEY_USERS\S-1-5-21-2545573064-1671415295-1629012448-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{9421DD08-935F-4701-A9CA-22DF90AC4EA6} deleted successfully
==== Deleting Services ======================
==== FireFox Fix ======================
Deleted from C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\vn2c9pwe.default\prefs.js:
Added to C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\vn2c9pwe.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\prefs.js:
user_pref("browser.search.useDBForOrder", true);
Added to C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
Deleted from C:\Users\Marvin\AppData\Roaming\Thunderbird\Profiles\ww68v8ez.default\prefs.js:
Added to C:\Users\Marvin\AppData\Roaming\Thunderbird\Profiles\ww68v8ez.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\vn2c9pwe.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1639_.backup
ProfilePath: C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default
user.js not found
---- Lines ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893 removed from prefs.js ----
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.active", true);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.addressbar", "NA");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.addressbarenhanced", "");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.backgroundver", 5);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.certdomaininstaller", "");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.changeprevious", false);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.cookie.InstallationTime.expiration", "Fri Feb 01 2030 00:00:00 GMT+
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.cookie.InstallationTime.value", "%221431880770%22");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.cookie.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 GMT+0
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.cookie.InstallerParams.value", "%7B%22source_id%22%3A%22002978%22%2
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.comad4db60df25f14dae
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.comad4db60df25f14dae
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.comasyncdb_dbWasSet"
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.comasyncdb_dbWasSet_
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.comasyncinternaldb_d
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.d4db60df25f14dae9dd18@185c395f9e794c9ab86be3eb.comasyncinternaldb_d
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.description", "Lights out for YouTube");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.domain", "");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.enablesearch", false);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.homepage", "");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.iframe", false);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.InstallationThankYouPage", true);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.InstallationTime", 1431880770);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.__defualt_browser__.expiration", "Fri Feb 01 2030 00:00:
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.__defualt_browser__.value", "%22crossbrowser%22");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.installer.expiration", "Fri Feb 01 2030 00:00:00 GMT+010
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.installer.value", "%7B%22InstallerIdentifiers%22%3A%7B%2
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.InstallerIdentifiers.expiration", "Fri Feb 01 2030 00:00
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.InstallerIdentifiers.value", "%7B%22installer_bic%22%3A%
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.InstallerParams.expiration", "Fri Feb 01 2030 00:00:00 G
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.internaldb.InstallerParams.value", "%7B%22source_id%22%3A%22002978%
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.lastDailyReport", "1431882605866");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.lastUpdate", "1431882605620");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.manifesturl", "");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.name", "CinemaPlus-3.2cV17.05");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.newtab", "");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.opensearch", "");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.pluginsurl", "hxxp://js.basememlog.com/plugin/apps/72893/plugins/na
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.pluginsversion", 41);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.publisher", "Cinema PlusV17.05");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.searchstatus", 0);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.setnewtab", false);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.thankyou", "");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.updateinterval", 360);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.72893.ver", 50);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.apps", "72893");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.bic", "14d62da8cba3b88c36a4721b1bf5971a");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.cid", 72893);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.firstrun", false);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.hadappinstalled", true);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.installationdate", 1431882600);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.installerAdditionalInfo", "{\"asw\":[67108872, -1610612731, 536875520, 10
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.modetype", "production");
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.reportInstall", true);
user_pref("extensions.ad4db60df25f14dae9dd18185c395f9e794c9ab86be3ebcom72893.statsDailyCounter", 1);
---- Lines extensions.X2nAGQDjJoj6Sle5 removed from prefs.js ----
user_pref("extensions.X2nAGQDjJoj6Sle5.epoch", "1435477367");
user_pref("extensions.X2nAGQDjJoj6Sle5.url", "hxxp://veterances.com/sync2/?q=hfZ9oeV9CGhEAen0rjaErdaEtMqLDe49CNU0mwkMCMlNhd9Fqja7rdUFrjr6rTgMBzqUojw8r
---- Lines extensions.hlnvstiPH2NFRDt9 removed from prefs.js ----
user_pref("extensions.hlnvstiPH2NFRDt9.epoch", "1435477366");
user_pref("extensions.hlnvstiPH2NFRDt9.url", "hxxp://superpent.org/sync2/?q=hfZ9ofDVgNrMCyVUojwErdaErchTB6lKDzt4okmxtNtVh7n0rjkEqTs6rdkFrTn7tMFHhd9Fqj
---- FireFox user.js and prefs.js backups ----
prefs__1639_.backup
ProfilePath: C:\Users\Marvin\AppData\Roaming\Thunderbird\Profiles\ww68v8ez.default
user.js not found
---- FireFox user.js and prefs.js backups ----
prefs__1639_.backup
==== Registry Fix Code ======================
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\Google Chrome.IAXQ5T3223REKSPIGQKFT7RRYQ\shell\open\command]
@="C:\\Users\\Marvin\\AppData\\Local\\Google\\Chrome\\Application\\chrome.exe"
==== Deleting Files \ Folders ======================
C:\PROGRA~2\b05f4dc8-3eb1-4310-b007-92743b80b6d6 not found
C:\PROGRA~2\Daedalic Entertainment not found
C:\PROGRA~2\OXXOGames not found
C:\PROGRA~2\SoftwareForce not found
C:\PROGRA~3\{1C6FDDD8-FC9E-4C12-9FA5-1AAD377097B3} not found
C:\PROGRA~3\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16} not found
C:\PROGRA~3\{32364CEA-7855-4A3C-B674-53D8E9B97936} not found
C:\PROGRA~3\{93E26451-CD9A-43A5-A2FA-C42392EA4001} not found
C:\PROGRA~3\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F} not found
C:\PROGRA~2\UltraISO deleted
C:\PROGRA~2\Responsive Inspector deleted
C:\PROGRA~2\VIA3 Video Conferencing Messaging deleted
C:\Users\Marvin\AppData\Roaming\ProtectDISC deleted
C:\PROGRA~2\Deskperience deleted
C:\PROGRA~2\ProtectDisc Driver Installer deleted
C:\PROGRA~2\COMMON~1\DVDVideoSoft\bin deleted
C:\PROGRA~3\InstallMate deleted
C:\PROGRA~3\Package Cache deleted
C:\windows\SysNative\config\systemprofile\Searches deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\gpt.ini deleted
C:\windows\Syswow64\InstallUtil.InstallLog deleted
C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\vn2c9pwe.default\extensions\staged deleted
C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default\extensions\extension@ciuvo.com.xpi deleted
"C:\windows\Installer\21d02f.msi" deleted
"C:\Users\Marvin\AppData\Roaming\09grw4H1Lq1DtjJuwoG" deleted
"C:\Users\Marvin\AppData\Roaming\Brother" deleted
"C:\Users\Marvin\AppData\Roaming\D4Bmst5g3iT3eCVS4UrxT8h2" deleted
"C:\ProgramData\Bundle" deleted
==== Firefox Start and Search pages ======================
ProfilePath: C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\vn2c9pwe.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
ProfilePath: C:\Users\Marvin\AppData\Roaming\Thunderbird\Profiles\ww68v8ez.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");
==== Firefox Extensions Registry ======================
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"e-webprint@epson.com"="C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on" [30.04.2014 13:55]
==== Firefox Extensions ======================
ProfilePath: C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default
- Stealthy - %ProfilePath%\extensions\stealthyextension@gmail.com.xpi
ProfilePath: C:\Users\Marvin\AppData\Roaming\Thunderbird\Profiles\ww68v8ez.default
- Instrument Test - %ProfilePath%\extensions\tbtestpilot@labs.mozilla.com.xpi
AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Marvin\AppData\Roaming\Mozilla\Firefox\Profiles\gsf1j48l.default
9741513D6C9D76C8903BFA362AC8BF9D - C:\ProgramData\NexonEU\NGM\npNxGameeu.dll - Nexon Game Controller
D7324EB1EDCB8990F8522DE0311359E9 - C:\windows\SysWOW64\npDeployJava1.dll - Java Deployment Toolkit 7.0.250.17
701F455DE89E110EF05F0413D8E3A4D1 - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_190.dll - Shockwave Flash
6A8A6B3C42CA4D1403C8FEA50BACEC63 - C:\Users\Marvin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll - Unity Player
15E298B5EC5B89C5994A59863969D9FF - C:\windows\SysWOW64\npmproxy.dll - Microsoft® Windows® Operating System
==== Chromium Look ======================
Google Chrome Version: 43.0.2357.130
Tampermonkey - Marvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo
==== Chromium Fix ======================
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markit00.re-markit.co_0.localstorage deleted successfully
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markit00.re-markit.co_0.localstorage-journal deleted successfully
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage deleted successfully
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal deleted successfully
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage deleted successfully
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage-journal deleted successfully
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.msn.com/?pc=MSSE"
"Default_Search_URL"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Default_Page_URL"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://www.google.com"
"Default_Page_URL"="hxxp://www.google.com"
"Search Page"="hxxp://www.google.com"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Start Page"="hxxp://www.msn.com/?pc=MSSE"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="hxxp://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="hxxp://go.microsoft.com/fwlink/?LinkId=69157"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="hxxp://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="hxxp://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
==== Reset Google Chrome ======================
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
==== shortcuts on Users Desktops ======================
C:\Users\Gast\Desktop\SpeedFan.lnk - C:\Program Files (x86)\SpeedFan\speedfan.exe
C:\Users\Marvin\Desktop\CoDWaW.lnk - C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaW.exe
C:\Users\Marvin\Desktop\ComboFix - Verknüpfung.lnk -
C:\Users\Marvin\Desktop\iDevice Manager.lnk - C:\Program Files (x86)\Software4u\iDevice Manager\Software4u.IDeviceManager.exe
C:\Users\Marvin\Desktop\TuneUp Utilities - Startoberfläche.lnk -
C:\Users\Marvin\Desktop\Antivirus\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Users\Marvin\Desktop\Sonstiges\Drucker\Epson Easy Photo Print.lnk - C:\Program Files (x86)\EPSON Software\Easy Photo Print\EPQuicker.exe
C:\Users\Marvin\Desktop\Sonstiges\Drucker\EPSON Scan.lnk - C:\Windows\twain_32\escndv\escndv.exe
C:\Users\Marvin\Desktop\Sonstiges\Fotobearbeitung\GIMP 2.lnk - C:\Program Files\GIMP 2\bin\gimp-2.8.exe
C:\Users\Marvin\Desktop\Sonstiges\Fotobearbeitung\PhotoScape.lnk - C:\Program Files (x86)\PhotoScape\PhotoScape.exe
C:\Users\Marvin\Desktop\Sonstiges\Fotobearbeitung\Snipping Tool.lnk -
C:\Users\Marvin\Desktop\Sonstiges\Games\CoDWaW - Verknüpfung.lnk -
C:\Users\Marvin\Desktop\Sonstiges\Games\Steam.lnk - C:\Program Files (x86)\Steam\Steam.exe
C:\Users\Marvin\Desktop\Sonstiges\Games\TeamSpeak 3 Client.lnk - C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\Audacity.lnk - C:\Program Files (x86)\Audacity\audacity.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\ImgBurn.lnk - C:\Program Files (x86)\ImgBurn\ImgBurn.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\IrfanView.lnk - C:\Program Files (x86)\IrfanView\i_view32.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\Microsoft Excel 2010.lnk - C:\windows\Installer\{90140000-0011-0000-0000-0000000FF1CE}\xlicons.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\Spotify.lnk - C:\Users\Marvin\AppData\Roaming\Spotify\spotify.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\Windows Live Movie Maker.lnk - C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\iPhone-Programme\CopyTrans Control Center.lnk - C:\Users\Marvin\AppData\Roaming\WindSolutions\CopyTransControlCenter\Applications\CopyTransControlCenter.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\iPhone-Programme\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\iPhone-Programme\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\Users\Marvin\Desktop\Sonstiges\Programme\iPhone-Programme\mp3DirectCut.lnk - C:\Program Files (x86)\mp3DirectCut\mp3DirectCut.exe
C:\Users\Marvin\Desktop\Sonstiges\Windows\Windows Crack (Office)\Microsoft Toolkit - Verknüpfung.lnk -
C:\Users\Marvin\Desktop\System\CCleaner.lnk - C:\Program Files\CCleaner\CCleaner64.exe
C:\Users\Marvin\Desktop\System\CPUID CPU-Z.lnk - C:\Program Files\CPUID\CPU-Z\cpuz.exe
C:\Users\Marvin\Desktop\System\HitmanPro.lnk - C:\Program Files (x86)\HitmanPro\HitmanPro.exe
C:\Users\Marvin\Desktop\System\Malwarebytes Anti-Malware.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
==== shortcuts on All Users Desktop ======================
C:\Users\Public\Desktop\DAEMON Tools Lite.lnk - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe
C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\FreeStudioManager.exe
C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe
C:\Users\Public\Desktop\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Public\Desktop\iBackupBot for iTunes.lnk - C:\Program Files (x86)\VOWSoft iPod Software\iBackupBot for iTunes\iBackupBot.exe
C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\Users\Public\Desktop\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Public\Desktop\Safari.lnk - C:\windows\Installer\{C779648B-410E-4BBA-B75B-5815BCEFE71D}\SafariIco.exe
C:\Users\Public\Desktop\Samsung Control Center.lnk - C:\Program Files (x86)\Samsung\Samsung Control Center\ControlCenter.exe
C:\Users\Public\Desktop\Skype.lnk - C:\windows\Installer\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\SkypeIcon.exe
==== shortcuts in Users Start Menu ======================
C:\Users\Marvin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk - C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk - C:\Program Files\Internet Explorer\iexplore.exe
==== shortcuts in All Users Start Menu ======================
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk - C:\windows\Installer\{AC76BA86-7AD7-1031-7B44-AA1000000001}\SC_Reader.ico
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk - C:\Program Files (x86)\Microsoft Security Client\msseces.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk - C:\windows\Installer\{C779648B-410E-4BBA-B75B-5815BCEFE71D}\SafariIco.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\CPU-Z.lnk - C:\Program Files\CPUID\CPU-Z\cpuz.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Edit CPU-Z Config File.lnk - C:\Program Files\CPUID\CPU-Z\cpuz.ini
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Uninstall CPU-Z.lnk - C:\Program Files\CPUID\CPU-Z\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\DVDVideoSoft Free Studio.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\FreeStudioManager.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Free YouTube to MP3 Converter.lnk - C:\Program Files (x86)\DVDVideoSoft\Free YouTube to MP3 Converter\FreeYouTubeToMP3Converter.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Log Report.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\DVSSysReport.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Premium Membership.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\PremiumMembershipOffer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft\Uninstall.lnk - C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\Uninstall.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro\HitmanPro 3.7 entfernen.lnk - C:\Program Files (x86)\HitmanPro\HitmanPro.exe /uninstall
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro\HitmanPro.lnk - C:\Program Files (x86)\HitmanPro\HitmanPro.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iDevice Manager\iDevice Manager deinstallieren.lnk - C:\Program Files (x86)\Software4u\iDevice Manager\unins000.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iDevice Manager\iDevice Manager im Internet.lnk - C:\Program Files (x86)\Software4u\iDevice Manager\iDevice Manager - Website.url
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iDevice Manager\iDevice Manager.lnk - C:\Program Files (x86)\Software4u\iDevice Manager\Software4u.IDeviceManager.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes\Über iTunes.lnk -
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk - C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\Silverlight.Configuration.exe
==== shortcuts in Quick Launch ======================
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
C:\Users\Gast\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk - C:\windows\Installer\{C779648B-410E-4BBA-B75B-5815BCEFE71D}\SafariIco.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk - C:\Program Files (x86)\PhotoScape\PhotoScape.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\CCleaner.lnk - C:\Program Files (x86)\CCleaner\CCleaner64.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\TeamSpeak 3 Client.lnk - C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Microsoft Word.lnk - C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Spotify.lnk - C:\Users\Marvin\AppData\Roaming\Spotify\spotify.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk - C:\windows\explorer.exe
C:\Users\Marvin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1
==== Reset IE Proxy ======================
Value(s) before fix:
"ProxyEnable"=dword:00000000
Value(s) after fix:
"ProxyEnable"=dword:00000000
==== Deleting Registry Keys ======================
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A747D90C74DB9A2419E5EC6B1BBBC711 deleted successfully
HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C09D747A-BD47-42A9-915E-CEB6B1BB7C11} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\A747D90C74DB9A2419E5EC6B1BBBC711 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GoogleChromeAutoLaunch_46F1CB28F09B935A713F72D4B90FE680 deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent deleted successfully
==== Empty IE Cache ======================
C:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Gast\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Marvin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
==== Empty FireFox Cache ======================
C:\Users\Gast\AppData\Local\Mozilla\Firefox\Profiles\vn2c9pwe.default\Cache emptied successfully
C:\Users\Marvin\AppData\Local\Mozilla\Firefox\Profiles\gsf1j48l.default\cache2 emptied successfully
==== Empty Chrome Cache ======================
C:\Users\Marvin\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
==== C:\zoek_backup content ======================
C:\zoek_backup (files=181 folders=57 49919527 bytes)
==== Empty Temp Folders ======================
C:\Users\Default\AppData\Local\temp emptied successfully
C:\Users\Default User\AppData\Local\temp emptied successfully
C:\Users\Gast\AppData\Local\temp emptied successfully
C:\Users\Marvin\AppData\Local\Temp will be emptied at reboot
C:\Users\Public\AppData\Local\temp emptied successfully
C:\windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\windows\Temp will be emptied at reboot
==== After Reboot ======================
==== Empty Temp Folders ======================
C:\windows\Temp successfully emptied
C:\Users\Marvin\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== EOF on 30.06.2015 at 16:50:15,82 ====================== Viele der Werbungen innerhalb einer Seite sind nun nicht mehr vorhanden, aber sie sind nicht komplett verschwunden. Beispielsweise gibt es immer noch Werbung über Google-Suchergebnissen "Ads by SaleItCoupon"
Außerdem ist mein ganzes System immer noch ziemlich lahm und hängt hinterher.
Und ich wollte mal fragen wie jetzt so der Stand der Dinge ist, und was genau bedeutet es, wenn diese AppData Dateien gelöscht werden, weil ich habe gesehen, dass da auch Dateien von "normalen" Programmen gelöscht werden. Was hat das für einen Einfluss? Funktionieren jetzt manche meiner Programme nicht mehr? Oder sind diese Dateien sowas wie bei einem Spiel die Fortschrittspeicherung oder wie darf ich mir das vorstellen?
MfG und Danke für die ganze Hilfe, ich weiß diese Seite und die freiwilligen Helfer hier wirklich zu schätzen
Ach ja und mir fällt gerade noch ein, dass wenn ich zum Beispiel bei Spotify Musik höre, dann ist der Ton richtig blechernd im Gegensatz dazu bevor ich die Viren, Trojaner oder was auch immer hatte. Kann das überhaupt damit zusammenhängen? |