|
Plagegeister aller Art und deren Bekämpfung: Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive WerbungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.04.2014, 18:49 | #1 |
| Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Der Windows 7 Rechner meiner Tochter ist Adware und anderer Malware verseucht. Beim Scan mit Malwarbytes wurde folgendes gefunden: mysearchdial, savingsbull, lizardlink, savesense, browsefox, valueapps, zulagames, crossrider, Qone8, awesomehlp, dealply, quickstart, hqtotals, mediaenhance, smartbar, alextb, installcore, advancesystemprotector, snapdo, installbrain, filescout, conduit, adpeak, valueappsplugin, viddyhd, optimuminstaller, cooltech, regcleanerpro, bundleinstaller, optimizerpro, bundlore, domalq, subtab, bandoo, trojan.Dropper.FJ, Supercoolapps, Searchprotect, Backdoor.bot, Skytech, Silenceinstall, WPmanager, searchprotect, pcperformer, Speedanalysis2, Funmoods und adpeak. Ich dachte ich könnte das Problem durch einfaches Deinstallieren über Revo Uninstaller selbst beheben, aber nachdem ich ein VO Package deinstalliert hatte, hatte ich mir fast das ganze System zerschossen. Über Systemwiederherstellung konnte ich es wieder retten und habe fast alles deinstalliert bekommen aber nach der erneuten Deinstallation des VO-Package ging der Revo Uninstaller wieder nicht mehr. So habe ich Malwarebytes laufen lassen. Der zeigte mir das Ausmaß des Elends, weshalb ich mich nach langer Zeit ein zweites Mal an Euch wende. Auch nach der Deinstallation der ganzen Adware hat der Internet Explorer und Google Chrome noch ein „Eigenleben mit Umleitungen und popup Fenstern auf sehr aggressive Werbung. Ich habe jetzt die ersten 3 Schritte befolgt und schicke Euch die Logs von frst.txt und addition.txt. [CODE]# FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014 Ran by xyz (administrator) on xyz on 22-04-2014 18:52:16 Running from C:\Users\xyz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Windows\AsScrPro.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe () C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe () C:\Program Files (x86)\Lizardlink\updateLizardlink.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe () C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe (Jumping Bytes) C:\Program Files (x86)\PureSync\PureSyncTray.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe () C:\Program Files (x86)\Lizardlink\bin\FilterApp_C64.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files (x86)\Lizardlink\bin\Lizardlink.BrowserAdapter.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe () C:\Program Files (x86)\Zula Games\BackgroundHost.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-09-19] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2816808 2011-07-21] (Synaptics Incorporated) HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [98088 2011-07-21] (Synaptics Incorporated) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-22] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS) HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [PureSync] => C:\Program Files (x86)\PureSync\PureSyncTray.exe [906928 2013-12-20] (Jumping Bytes) HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation) AppInit_DLLs: C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL => C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL File Not Found AppInit_DLLs-x32: c:\progra~2\optimi~1\optpro~1.dll => "c:\progra~2\optimi~1\optpro~1.dll" File Not Found GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM} HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} URLSearchHook: HKLM-x32 - appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359 SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - URL hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3319116&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP5C705B91-74C4-49A1-A0D9-25AFC5B7A96E&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM} SearchScopes: HKCU - {10F02070-5C8C-4E0B-9D76-ED5DEC00A416} URL = hxxp://de.wikipedia.org/w/index.php?title=Spezial:Suche&search={searchTerms} SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} SearchScopes: HKCU - {433C345D-C1DE-4AE3-9E63-DFA494815841} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0C0EyBtA0E0DtA0EzzzztN0D0Tzu0CyBzztAtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=923418304&ir= SearchScopes: HKCU - {7F1A9171-10E2-4C11-A42A-253499CDF7C5} URL = hxxp://dict.leo.org/ende?lp=ende&lang=de&searchLoc=0&cmpType=relaxed§Hdr=on&spellToler=on&chinese=both&pinyin=diacritic&search={searchTerms}&relink=on SearchScopes: HKCU - {C177248B-A9BC-4AF0-99CC-32A2CE37D81E} URL = hxxp://www.dict.cc/?s={searchTerms} SearchScopes: HKCU - {DCBF59AF-92DF-4CD7-A341-6F448E532676} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=msd3_14_11_ch&cd=2XzuyEtN2Y1L1Qzu0CzzyCtDtDtDtDyEtAyD0FyCtA0EzzzztN0D0Tzu0SzztDyDtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StByByCyD0AyDyBtCtG0DtA0ByDtG0DzyzzzytGzyyD0FzytGtDzz0FyD0ByBzy0FtAzz0FyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0A0DyEtAtD0AtBtGyDzz0AtCtGtB0DyE0AtGtDyBtCyEtGyEzztBtDyD0AyEtD0EtByCyD2Q&cr=1048254177&ir= BHO: media enhance - {11111111-1111-1111-1111-110411411150} - C:\Program Files (x86)\media enhance\media enhance-bho64.dll No File BHO: HQTotalS - {11111111-1111-1111-1111-110511311172} - C:\Program Files (x86)\HQTotalS\HQTotalS-bho64.dll No File BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.) BHO-x32: SaveSense - {71e129ff-6c2a-4984-818c-7e2c998b8d99} - C:\Users\xyz\AppData\Local\SaveSense\SaveSenseIE.dll No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: ValueApps - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll (Conduit Ltd.) BHO-x32: Zula Games - {A9337080-7CBF-4E3E-80C1-3867BEDD88E0} - C:\Program Files (x86)\Zula Games\ScriptHost.dll (ZulaGames.com) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File Toolbar: HKLM-x32 - appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.) Toolbar: HKLM-x32 - No Name - {3004627E-F8E9-4E8B-909D-316753CBA923} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.updaterss.com/SaveSenseLive Update;version=3 - C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF Plugin-x32: @tools.updaterss.com/SaveSenseLive Update;version=9 - C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Extension: Widget context - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2014-04-22] FF HKLM-x32\...\Firefox\Extensions: [zulagames@ZulaGames.com] - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com FF Extension: Zula Games - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com [2013-10-04] FF HKLM-x32\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com FF Extension: Speed Analysis 2 - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com [2013-10-04] FF HKCU\...\Firefox\Extensions: [zulagames@ZulaGames.com] - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com FF Extension: Zula Games - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com [2013-10-04] FF HKCU\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com FF Extension: Speed Analysis 2 - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com [2013-10-04] Chrome: ======= CHR HomePage: CHR StartupUrls: "hxxp://www.google.de/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Extension: (YouTube) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-15] CHR Extension: (Google-Suche) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-15] CHR Extension: (HQ-Video-Pro-1.9) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm [2014-03-22] CHR Extension: (media enhance) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo [2014-03-22] CHR Extension: (Google Wallet) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-22] CHR Extension: (Widget context) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp [2014-04-22] CHR Extension: (Google Mail) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-15] CHR HKCU\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24] CHR HKLM-x32\...\Chrome\Extension: [gflandjopdloblmlcoiidmncpinmmacn] - C:\Users\xyz\AppData\Roaming\zulagames\zulagames.crx [2013-07-01] CHR HKLM-x32\...\Chrome\Extension: [jainjonnknhmbbkibcbmhihbopigapdm] - C:\Program Files (x86)\Lizardlink\jainjonnknhmbbkibcbmhihbopigapdm.crx [2013-07-01] CHR HKLM-x32\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24] CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-16] ==================== Services (Whitelisted) ================= R2 Level Quality Watcher; C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe [710976 2014-01-27] () R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) S2 savesenselive; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-03-15] (SaveSense) S3 savesenselivem; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-03-15] (SaveSense) R2 Update Lizardlink; C:\Program Files (x86)\Lizardlink\updateLizardlink.exe [350496 2014-04-22] () R2 Util Lizardlink; C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe [350496 2014-04-22] () S2 70e6ca8c; "C:\Windows\system32\rundll32.exe" "c:\progra~2\optimi~1\OptProCrashSvc.dll",ServiceMain ==================== Drivers (Whitelisted) ==================== R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [16768 2011-09-20] (ASUSTek Computer Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-22] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61120 2014-03-22] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-22 18:52 - 2014-04-22 18:52 - 00023395 _____ () C:\Users\xyz\Downloads\FRST.txt 2014-04-22 18:51 - 2014-04-22 18:52 - 00000000 ____D () C:\FRST 2014-04-22 18:51 - 2014-04-22 18:51 - 02061312 _____ (Farbar) C:\Users\xyz\Downloads\FRST64.exe 2014-04-22 18:48 - 2014-04-22 18:48 - 00000494 _____ () C:\Users\xyz\Desktop\defogger_disable.log 2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable 2014-04-22 18:47 - 2014-04-22 18:47 - 00050477 _____ () C:\Users\xyz\Downloads\Defogger.exe 2014-04-22 18:28 - 2014-04-22 18:28 - 00128584 _____ () C:\Users\xyz\Desktop\20140422_1827_malware_scan.txt 2014-04-22 17:06 - 2014-04-22 17:06 - 00000000 ____D () C:\Program Files\SavingsBull 2014-04-22 16:55 - 2014-04-22 16:56 - 00000000 ____D () C:\AdwCleaner 2014-04-22 16:54 - 2014-04-22 16:54 - 01335637 _____ () C:\Users\xyz\Downloads\adwcleaner.exe 2014-04-22 16:51 - 2014-04-22 17:08 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-22 16:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-22 16:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-22 16:51 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-04-22 14:51 - 2014-04-22 14:53 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files\iTunes 2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod 2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7} 2014-04-22 14:31 - 2014-04-22 14:31 - 00000000 ____D () C:\ProgramData\Systweak 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList 2014-04-13 12:00 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-13 12:00 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-13 12:00 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-13 12:00 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-13 11:59 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-13 11:59 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-13 11:59 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-13 11:59 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-13 11:59 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-13 11:59 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-13 11:59 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-13 11:59 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-13 11:59 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-13 11:59 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-13 11:59 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-13 11:59 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-13 11:26 - 2014-04-22 15:21 - 00003108 _____ () C:\Windows\System32\Tasks\RegClean Pro 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97} 2014-03-23 00:42 - 2014-04-22 14:27 - 00000000 ____D () C:\ProgramData\Free Download Manager 2014-03-23 00:41 - 2014-04-22 13:37 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Free Download Manager ==================== One Month Modified Files and Folders ======= 2014-04-22 18:53 - 2013-03-15 17:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-22 18:52 - 2014-04-22 18:52 - 00023395 _____ () C:\Users\xyz\Downloads\FRST.txt 2014-04-22 18:52 - 2014-04-22 18:51 - 00000000 ____D () C:\FRST 2014-04-22 18:51 - 2014-04-22 18:51 - 02061312 _____ (Farbar) C:\Users\xyz\Downloads\FRST64.exe 2014-04-22 18:48 - 2014-04-22 18:48 - 00000494 _____ () C:\Users\xyz\Desktop\defogger_disable.log 2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable 2014-04-22 18:48 - 2014-03-15 20:47 - 00000320 _____ () C:\Windows\Tasks\MySearchDial.job 2014-04-22 18:48 - 2013-01-10 19:09 - 00000000 ____D () C:\Users\xyz 2014-04-22 18:47 - 2014-04-22 18:47 - 00050477 _____ () C:\Users\xyz\Downloads\Defogger.exe 2014-04-22 18:43 - 2014-03-15 20:38 - 00000952 _____ () C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job 2014-04-22 18:40 - 2014-03-15 20:39 - 00000320 _____ () C:\Windows\Tasks\AppCloudUpdater.job 2014-04-22 18:38 - 2014-03-15 20:38 - 00000320 _____ () C:\Windows\Tasks\SaveSense.job 2014-04-22 18:28 - 2014-04-22 18:28 - 00128584 _____ () C:\Users\xyz\Desktop\20140422_1827_malware_scan.txt 2014-04-22 18:20 - 2013-03-15 17:16 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-22 18:13 - 2012-08-22 09:17 - 02047682 _____ () C:\Windows\WindowsUpdate.log 2014-04-22 17:40 - 2014-03-16 18:40 - 00001598 _____ () C:\Windows\Tasks\media enhance-updater.job 2014-04-22 17:40 - 2014-03-16 18:40 - 00001552 _____ () C:\Windows\Tasks\media enhance-codedownloader.job 2014-04-22 17:40 - 2014-03-16 18:40 - 00001452 _____ () C:\Windows\Tasks\media enhance-enabler.job 2014-04-22 17:39 - 2014-03-16 18:39 - 00003122 _____ () C:\Windows\Tasks\media enhance-chromeinstaller.job 2014-04-22 17:39 - 2014-03-16 18:39 - 00002380 _____ () C:\Windows\Tasks\media enhance-firefoxinstaller.job 2014-04-22 17:38 - 2014-03-16 18:38 - 00003102 _____ () C:\Windows\Tasks\HQTotalS-chromeinstaller.job 2014-04-22 17:38 - 2014-03-16 18:38 - 00002540 _____ () C:\Windows\Tasks\HQTotalS-firefoxinstaller.job 2014-04-22 17:38 - 2014-03-16 18:38 - 00001512 _____ () C:\Windows\Tasks\HQTotalS-updater.job 2014-04-22 17:38 - 2014-03-16 18:38 - 00001466 _____ () C:\Windows\Tasks\HQTotalS-codedownloader.job 2014-04-22 17:38 - 2014-03-16 18:38 - 00001366 _____ () C:\Windows\Tasks\HQTotalS-enabler.job 2014-04-22 17:14 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-22 17:14 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-22 17:11 - 2013-10-04 13:22 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\File Scout 2014-04-22 17:08 - 2014-04-22 16:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-22 17:07 - 2009-07-14 04:34 - 00000678 _____ () C:\Windows\win.ini 2014-04-22 17:06 - 2014-04-22 17:06 - 00000000 ____D () C:\Program Files\SavingsBull 2014-04-22 17:06 - 2014-03-15 20:38 - 00000948 _____ () C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job 2014-04-22 17:06 - 2014-02-25 09:58 - 00001792 _____ () C:\Windows\setupact.log 2014-04-22 17:06 - 2013-03-15 17:16 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-22 17:06 - 2013-01-10 19:09 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe 2014-04-22 17:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-22 17:05 - 2014-02-25 09:58 - 00881608 _____ () C:\Windows\PFRO.log 2014-04-22 16:56 - 2014-04-22 16:55 - 00000000 ____D () C:\AdwCleaner 2014-04-22 16:54 - 2014-04-22 16:54 - 01335637 _____ () C:\Users\xyz\Downloads\adwcleaner.exe 2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-22 16:45 - 2014-03-22 15:23 - 54485192 _____ () C:\Windows\system32\SavingsBullFilterService.log 2014-04-22 16:31 - 2012-08-22 09:25 - 00000000 ____D () C:\ProgramData\P4G 2014-04-22 16:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-04-22 16:03 - 2014-03-22 15:22 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro 2014-04-22 16:03 - 2014-03-16 18:38 - 00000000 ____D () C:\Program Files (x86)\SupTab 2014-04-22 16:01 - 2014-03-16 18:37 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-04-22 15:52 - 2014-03-15 20:43 - 00000000 ____D () C:\Program Files (x86)\Mysearchdial 2014-04-22 15:52 - 2014-02-21 23:14 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\mysearchdial 2014-04-22 15:50 - 2014-03-16 18:38 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\SupTab 2014-04-22 15:46 - 2013-10-04 13:23 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\SearchProtect 2014-04-22 15:32 - 2014-03-22 15:22 - 00000000 ____D () C:\Program Files (x86)\PC Speed Maximizer 2014-04-22 15:28 - 2014-03-22 15:20 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\viddyhd 2014-04-22 15:24 - 2011-02-19 06:24 - 00710852 _____ () C:\Windows\system32\perfh007.dat 2014-04-22 15:24 - 2011-02-19 06:24 - 00153300 _____ () C:\Windows\system32\perfc007.dat 2014-04-22 15:24 - 2009-07-14 07:13 - 01650460 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-22 15:21 - 2014-04-13 11:26 - 00003108 _____ () C:\Windows\System32\Tasks\RegClean Pro 2014-04-22 15:17 - 2014-03-15 20:39 - 00000000 ____D () C:\Program Files (x86)\Advanced System Protector 2014-04-22 15:13 - 2014-03-16 18:39 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup 2014-04-22 15:02 - 2014-03-15 20:39 - 00000298 _____ () C:\Windows\Tasks\RegClean Pro_DEFAULT.job 2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-04-22 14:53 - 2014-04-22 14:51 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iTunes 2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod 2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7} 2014-04-22 14:33 - 2014-03-15 20:39 - 00003120 _____ () C:\Windows\System32\Tasks\Advanced System Protector_startup 2014-04-22 14:31 - 2014-04-22 14:31 - 00000000 ____D () C:\ProgramData\Systweak 2014-04-22 14:29 - 2013-10-04 13:23 - 00000000 ____D () C:\Program Files (x86)\Lizardlink 2014-04-22 14:28 - 2013-10-04 13:57 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Systweak 2014-04-22 14:28 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-22 14:27 - 2014-03-23 00:42 - 00000000 ____D () C:\ProgramData\Free Download Manager 2014-04-22 14:27 - 2014-03-15 20:39 - 00000000 ____D () C:\Program Files (x86)\AppSafe 2014-04-22 14:27 - 2013-01-15 00:13 - 00000000 ____D () C:\Program Files (x86)\HP 2014-04-22 14:27 - 2013-01-10 19:57 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com 2014-04-22 14:27 - 2013-01-10 19:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-22 14:27 - 2012-08-22 09:28 - 00000000 ____D () C:\Program Files (x86)\CyberLink 2014-04-22 14:27 - 2011-04-13 04:47 - 00000000 ____D () C:\Program Files (x86)\ASUS 2014-04-22 14:25 - 2014-03-15 20:38 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\SaveSense 2014-04-22 14:24 - 2011-04-13 04:49 - 00000000 ____D () C:\AsusVibeData 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList 2014-04-22 13:37 - 2014-03-23 00:41 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Free Download Manager 2014-04-22 10:58 - 2013-01-10 21:38 - 00000000 ____D () C:\Users\xyz\Documents\Outlook-Dateien 2014-04-18 14:20 - 2014-03-15 20:39 - 00000306 _____ () C:\Windows\Tasks\RegClean Pro_UPDATES.job 2014-04-16 12:07 - 2012-08-22 09:25 - 00002206 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-04-16 11:48 - 2013-01-10 21:18 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-16 11:46 - 2013-08-15 03:01 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-16 11:38 - 2013-01-13 08:13 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97} 2014-04-03 19:15 - 2013-03-15 17:16 - 00004126 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-03 19:15 - 2013-03-15 17:16 - 00003874 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-03 19:14 - 2014-02-25 11:15 - 00002155 _____ () C:\Windows\epplauncher.mif 2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-04-03 09:51 - 2014-04-22 16:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-22 16:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-22 16:51 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 03:16 - 2014-04-13 12:00 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-13 12:00 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-27 20:09 - 2014-03-15 20:38 - 00000110 _____ () C:\Users\xyz\AppData\Roaming\WB.CFG Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.5928.dll Some content of TEMP: ==================== C:\Users\xyz\AppData\Local\Temp\42663uninstall.exe C:\Users\xyz\AppData\Local\Temp\BackupSetup.exe C:\Users\xyz\AppData\Local\Temp\dlLogic.exe C:\Users\xyz\AppData\Local\Temp\IrsoDLL.dll C:\Users\xyz\AppData\Local\Temp\nsk2D6A.exe C:\Users\xyz\AppData\Local\Temp\nsn4DC8.exe C:\Users\xyz\AppData\Local\Temp\nsnC321.exe C:\Users\xyz\AppData\Local\Temp\nst42A1.exe C:\Users\xyz\AppData\Local\Temp\nsyCD6F.exe C:\Users\xyz\AppData\Local\Temp\pcspeedmaxsetup.exe C:\Users\xyz\AppData\Local\Temp\PureSyncInst.exe C:\Users\xyz\AppData\Local\Temp\Quarantine.exe C:\Users\xyz\AppData\Local\Temp\shelper.exe C:\Users\xyz\AppData\Local\Temp\SPSetup.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-02-28 01:12 ==================== End Of Log ============================ Code:
ATTFilter #Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2014 Ran by xyz at 2014-04-22 18:53:11 Running from C:\Users\xyz\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden AMD APP SDK Runtime (Version: 2.5.775.2 - Advanced Micro Devices Inc.) Hidden AMD AVIVO64 Codecs (Version: 11.7.0.10927 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{92015CBE-D397-C3EA-99FC-B03051DE69A4}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.) AppCloudUpdater (HKCU\...\AppCloudUpdater) (Version: - AppCloudUpdater) <==== ATTENTION Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) ccc-utility64 (Version: 2011.0927.2225.38375 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS) HP Unified IO (Version: 1.0.1.95 - HP) Hidden iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) Lizardlink 1.0.0 (HKLM\...\Lizardlink) (Version: 1.0.0 - Lizardlink) <==== ATTENTION MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video easy HD (Version: 5.0.0.99 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) SavingsBull (HKLM\...\Level Quality Watcher) (Version: SavingsBull - SavingsBull) <==== ATTENTION Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.17.0 - Synaptics Incorporated) ==================== Restore Points ========================= 22-04-2014 09:03:06 Revo Uninstaller's restore point - Adobe Flash Player Packages 22-04-2014 09:08:22 Revo Uninstaller's restore point - AsusVibe2.0 22-04-2014 09:10:31 Revo Uninstaller's restore point - NewPlayer 22-04-2014 09:13:05 Revo Uninstaller's restore point - Optimizer Pro v3.2 22-04-2014 09:14:28 Revo Uninstaller's restore point - HQTotalS 22-04-2014 09:15:53 Revo Uninstaller's restore point - IePluginService12.27.0.3326 22-04-2014 09:17:02 Revo Uninstaller's restore point - InstantOn for NB 22-04-2014 09:20:20 Revo Uninstaller's restore point - Lollipop 22-04-2014 09:21:59 Revo Uninstaller's restore point - media enhance 22-04-2014 11:16:55 Revo Uninstaller's restore point - Re-markit 22-04-2014 11:18:38 Revo Uninstaller's restore point - PC Speed Maximizer v3.2 22-04-2014 11:19:57 Revo Uninstaller's restore point - Plants vs Zombies 22-04-2014 11:34:22 Revo Uninstaller's restore point - WPM17.8.0.3442 22-04-2014 11:35:41 Revo Uninstaller's restore point - ViddyHD 22-04-2014 11:37:27 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections 22-04-2014 11:39:22 Revo Uninstaller's restore point - VO Package 22-04-2014 12:10:15 Wiederherstellungsvorgang 22-04-2014 13:03:55 Revo Uninstaller's restore point - Advanced System Protector 22-04-2014 13:07:03 Revo Uninstaller's restore point - Adobe Flash Player Packages 22-04-2014 13:10:00 Revo Uninstaller's restore point - awesomehp uninstaller 22-04-2014 13:11:25 Revo Uninstaller's restore point - File Extractor 22-04-2014 13:13:59 Revo Uninstaller's restore point - DMUninstaller 22-04-2014 13:23:47 Revo Uninstaller's restore point - RegClean Pro 22-04-2014 13:25:57 Revo Uninstaller's restore point - Lollipop 22-04-2014 13:27:32 Revo Uninstaller's restore point - ViddyHD 22-04-2014 13:30:02 Revo Uninstaller's restore point - PC Speed Maximizer v3.2 22-04-2014 13:44:45 Revo Uninstaller's restore point - Search Protect 22-04-2014 13:49:20 Revo Uninstaller's restore point - SupTab 22-04-2014 13:50:55 Revo Uninstaller's restore point - Mysearchdial 22-04-2014 13:52:32 Revo Uninstaller's restore point - WPM17.8.0.3442 22-04-2014 13:59:32 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections 22-04-2014 14:00:35 Revo Uninstaller's restore point - Re-markit 22-04-2014 14:01:51 Revo Uninstaller's restore point - Optimizer Pro v3.2 22-04-2014 14:11:03 Revo Uninstaller's restore point - IePluginService12.27.0.3326 22-04-2014 14:14:36 Revo Uninstaller's restore point - media enhance 22-04-2014 14:20:06 Revo Uninstaller's restore point - VO Package 22-04-2014 14:27:49 Wiederherstellungsvorgang 22-04-2014 14:37:37 Revo Uninstaller's restore point - HQTotalS ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05490B50-D0A0-4A3C-A560-6ACF63DE1E42} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {0A20B86B-C883-4B55-BE5F-6C5B88DFD956} - System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-03-15] (SaveSense) <==== ATTENTION Task: {0B4E379A-4C4A-428E-9BCF-A1135BBA3E4A} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2012-09-27] () Task: {1CCE7D51-38D1-4F66-B7AC-A43176E2120F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-09-30] (ASUSTeK Computer Inc.) Task: {38487E62-185E-4E9B-9FDF-B0AE74EDB917} - System32\Tasks\media enhance-firefoxinstaller => C:\Program Files (x86)\media enhance\media enhance-firefoxinstaller.exe <==== ATTENTION Task: {39ABEFFB-C815-47E0-BC07-1E39AE6B1848} - System32\Tasks\media enhance-enabler => C:\Program Files (x86)\media enhance\media enhance-enabler.exe <==== ATTENTION Task: {3E2E8B1F-6878-402A-87AB-F2EF5FEBADCE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.) Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {4C14D4FC-EFFF-4FC1-BA61-EEFA91392794} - System32\Tasks\USBChargerPlus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2011-09-20] (ASUSTek Computer Inc.) Task: {664914DE-1357-4563-9C3A-4B18A6DF05C4} - System32\Tasks\AppCloudUpdater => C:\Users\xyz\AppData\Roaming\AppCloudUpdater\UpdateProc\UpdateTask.exe [2013-04-12] () Task: {7667AB67-F907-484F-AD77-C667D54EA421} - System32\Tasks\HQTotalS-enabler => C:\Program Files (x86)\HQTotalS\HQTotalS-enabler.exe <==== ATTENTION Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe <==== ATTENTION Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - System32\Tasks\MySearchDial => C:\Users\STEFAN~1\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {89189C02-42C8-456D-B675-7D30954096D1} - System32\Tasks\HQTotalS-firefoxinstaller => C:\Program Files (x86)\HQTotalS\HQTotalS-firefoxinstaller.exe Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: {8FFE3A4C-B16E-4461-A1BC-27379739F580} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22] (ASUS) Task: {90187687-8307-4836-8AD5-B51C0E3B2F1D} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: {9A20F821-8371-4DDF-8F33-7CF248B5D231} - System32\Tasks\HQTotalS-updater => C:\Program Files (x86)\HQTotalS\HQTotalS-updater.exe Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION Task: {AC60D348-CF49-41C1-B4C3-F3EF599304C7} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: {ADEB5A5F-7925-4438-9D2C-28715C5EC582} - System32\Tasks\HQTotalS-codedownloader => C:\Program Files (x86)\HQTotalS\HQTotalS-codedownloader.exe Task: {AF490895-86A7-4FE9-9CC6-9EC88297132C} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-11-22] (ASUS) Task: {B1DB8257-AAA0-4F41-A154-DF52977CE8A6} - System32\Tasks\media enhance-updater => C:\Program Files (x86)\media enhance\media enhance-updater.exe <==== ATTENTION Task: {C410E796-D92D-4AEB-A596-89D282D0DBF8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.) Task: {CA006D69-ECF6-4442-9628-D9F300F1C356} - System32\Tasks\media enhance-chromeinstaller => C:\Program Files (x86)\media enhance\media enhance-chromeinstaller.exe <==== ATTENTION Task: {E22A7D07-EABF-4E3F-B019-C6F7AB546AA0} - System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-03-15] (SaveSense) <==== ATTENTION Task: {E96319AF-4D2F-4DB8-B780-3738A6F8F2E2} - System32\Tasks\HQTotalS-chromeinstaller => C:\Program Files (x86)\HQTotalS\HQTotalS-chromeinstaller.exe Task: {EAD7D671-DBE5-4388-994E-8F508652131C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS) Task: {EB32D426-01C9-4433-875C-580B292A89F0} - System32\Tasks\SaveSense => C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {EDBAD762-5B95-4C13-9FA0-333BACA63683} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-14] (Adobe Systems Incorporated) Task: {F9C0DFA3-7859-4C70-A44F-5E77F9E82EA7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {FC1EFF76-3919-4569-B62C-EABD3C0F34D0} - System32\Tasks\media enhance-codedownloader => C:\Program Files (x86)\media enhance\media enhance-codedownloader.exe <==== ATTENTION Task: {FE3FBFF8-BA1D-4554-A7AA-BA0DCD11606F} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AppCloudUpdater.job => C:\Users\STEFAN~1\AppData\Roaming\APPCLO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HQTotalS-chromeinstaller.job => C:\Program Files (x86)\HQTotalS\HQTotalS-chromeinstaller.exe Task: C:\Windows\Tasks\HQTotalS-codedownloader.job => C:\Program Files (x86)\HQTotalS\HQTotalS-codedownloader.exe Task: C:\Windows\Tasks\HQTotalS-enabler.job => C:\Program Files (x86)\HQTotalS\HQTotalS-enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\HQTotalS-firefoxinstaller.job => C:\Program Files (x86)\HQTotalS\HQTotalS-firefoxinstaller.exe Task: C:\Windows\Tasks\HQTotalS-updater.job => C:\Program Files (x86)\HQTotalS\HQTotalS-updater.exe Task: C:\Windows\Tasks\media enhance-chromeinstaller.job => C:\Program Files (x86)\media enhance\media enhance-chromeinstaller.exe <==== ATTENTION Task: C:\Windows\Tasks\media enhance-codedownloader.job => C:\Program Files (x86)\media enhance\media enhance-codedownloader.exe <==== ATTENTION Task: C:\Windows\Tasks\media enhance-enabler.job => C:\Program Files (x86)\media enhance\media enhance-enabler.exe <==== ATTENTION Task: C:\Windows\Tasks\media enhance-firefoxinstaller.job => C:\Program Files (x86)\media enhance\media enhance-firefoxinstaller.exe <==== ATTENTION Task: C:\Windows\Tasks\media enhance-updater.job => C:\Program Files (x86)\media enhance\media enhance-updater.exe <==== ATTENTION Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\STEFAN~1\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSense.job => C:\Users\STEFAN~1\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION ==================== Loaded Modules (whitelisted) ============= 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2014-01-27 22:45 - 2014-01-27 22:45 - 00710976 _____ () C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe 2013-09-28 06:29 - 2014-04-22 15:09 - 00350496 _____ () C:\Program Files (x86)\Lizardlink\updateLizardlink.exe 2011-10-13 08:19 - 2011-07-21 12:59 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll 2013-10-07 09:14 - 2014-04-22 14:36 - 00350496 _____ () C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe 2014-03-22 14:11 - 2014-03-22 14:11 - 00287008 _____ () C:\Program Files (x86)\Lizardlink\bin\FilterApp_C64.exe 2014-04-13 11:28 - 2014-04-17 22:22 - 00095520 _____ () C:\Program Files (x86)\Lizardlink\bin\Lizardlink.BrowserAdapter.exe 2013-07-01 15:58 - 2013-07-01 15:58 - 00598848 _____ () C:\Program Files (x86)\Zula Games\BackgroundHost.exe 2011-09-30 02:06 - 2011-09-30 02:06 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll 2011-11-22 16:09 - 2011-11-22 16:09 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2011-09-13 22:33 - 2011-09-13 22:33 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll 2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-07-01 15:58 - 2013-07-01 15:58 - 00334144 _____ () C:\Program Files (x86)\Zula Games\ButtonSite.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:AD022376 ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/22/2014 03:38:16 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.16521, Zeitstempel: 0x53115050 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00008a95 ID des fehlerhaften Prozesses: 0xfc8 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/22/2014 02:56:46 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.16521, Zeitstempel: 0x53115050 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00008a95 ID des fehlerhaften Prozesses: 0x12ec Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/22/2014 02:56:15 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399 Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.16521, Zeitstempel: 0x53115050 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00008a95 ID des fehlerhaften Prozesses: 0x15a0 Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0 Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1 Pfad des fehlerhaften Moduls: IEXPLORE.EXE2 Berichtskennung: IEXPLORE.EXE3 Error: (04/22/2014 02:20:59 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000000051da ID des fehlerhaften Prozesses: 0x8ec Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (04/22/2014 02:20:47 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000000051da ID des fehlerhaften Prozesses: 0x1610 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (04/22/2014 02:20:40 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000000051da ID des fehlerhaften Prozesses: 0x1488 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (04/22/2014 02:20:28 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000000051da ID des fehlerhaften Prozesses: 0x1294 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (04/22/2014 02:20:22 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000000051da ID des fehlerhaften Prozesses: 0x1760 Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0 Pfad der fehlerhaften Anwendung: explorer.exe1 Pfad des fehlerhaften Moduls: explorer.exe2 Berichtskennung: explorer.exe3 Error: (04/22/2014 02:20:16 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000000051da ID des fehlerhaften Prozesses: 0x1644 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 Error: (04/22/2014 02:20:07 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4 Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000000051da ID des fehlerhaften Prozesses: 0x1564 Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0 Pfad der fehlerhaften Anwendung: Explorer.EXE1 Pfad des fehlerhaften Moduls: Explorer.EXE2 Berichtskennung: Explorer.EXE3 System errors: ============= Error: (04/22/2014 05:06:41 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Optimizer Pro Crash Monitor erreicht. Error: (04/22/2014 05:05:30 PM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (04/22/2014 04:33:13 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Optimizer Pro Crash Monitor erreicht. Error: (04/22/2014 04:32:02 PM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (04/22/2014 04:29:17 PM) (Source: DCOM) (User: ) Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} Error: (04/22/2014 04:25:29 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Optimizer Pro Crash Monitor erreicht. Error: (04/22/2014 04:05:05 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Optimizer Pro Crash Monitor erreicht. Error: (04/22/2014 04:03:45 PM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (04/22/2014 03:47:21 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/22/2014 03:47:21 PM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Microsoft Office Sessions: ========================= Error: (04/22/2014 03:38:16 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399jscript9.dll11.0.9600.1652153115050c000000500008a95fc801cf5e301007beccC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll5b80c3c3-ca23-11e3-88dd-c860000435f6 Error: (04/22/2014 02:56:46 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399jscript9.dll11.0.9600.1652153115050c000000500008a9512ec01cf5e2a40ee0e83C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll8f5e6a71-ca1d-11e3-a5ec-c860000435f6 Error: (04/22/2014 02:56:15 PM) (Source: Application Error)(User: ) Description: IEXPLORE.EXE11.0.9600.1652153114399jscript9.dll11.0.9600.1652153115050c000000500008a9515a001cf5e2a2e7dc5c3C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll7c914c07-ca1d-11e3-a5ec-c860000435f6 Error: (04/22/2014 02:20:59 PM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da8ec01cf5e254eaece06C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll8f6a7da0-ca18-11e3-8ac2-c860000435f6 Error: (04/22/2014 02:20:47 PM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da161001cf5e254a383982C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll887f7dd4-ca18-11e3-8ac2-c860000435f6 Error: (04/22/2014 02:20:40 PM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da148801cf5e2545d24ea0C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll83ff63d0-ca18-11e3-8ac2-c860000435f6 Error: (04/22/2014 02:20:28 PM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da129401cf5e253e5fa065C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll7cb2cb98-ca18-11e3-8ac2-c860000435f6 Error: (04/22/2014 02:20:22 PM) (Source: Application Error)(User: ) Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da176001cf5e253ab5c239C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll790db02d-ca18-11e3-8ac2-c860000435f6 Error: (04/22/2014 02:20:16 PM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da164401cf5e2537619597C:\Windows\Explorer.EXEC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll75c0a7ac-ca18-11e3-8ac2-c860000435f6 Error: (04/22/2014 02:20:07 PM) (Source: Application Error)(User: ) Description: Explorer.EXE6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da156401cf5e25324b84e1C:\Windows\Explorer.EXEC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll70aa96f6-ca18-11e3-8ac2-c860000435f6 ==================== Memory info =========================== Percentage of memory in use: 35% Total physical RAM: 6048.05 MB Available physical RAM: 3905.56 MB Total Pagefile: 12094.28 MB Available Pagefile: 9360.5 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:195.35 GB) (Free:126.65 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Data) (Fixed) (Total:245.41 GB) (Free:210.98 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 496B9619) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=195 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=245 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-04-22 20:07:15 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.01.0 465,76GB Running: Gmer-19357.exe; Driver: C:\Users\STEFAN~1\AppData\Local\Temp\uxlyypob.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800031f8000 45 bytes [00, 00, 0A, 02, 4D, 50, 72, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575 fffff800031f802f 17 bytes [00, 30, E0, E7, 0B, 80, FA, ...] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet) ---- EOF - GMER 2.1 ----
__________________ Gruß Volker Geändert von caiphi (22.04.2014 um 19:44 Uhr) Grund: Ergänzung Gmer.log, malwarebytes. log passte nicht mehr rein |
22.04.2014, 19:25 | #2 |
/// the machine /// TB-Ausbilder | Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Revo Uninstaller - Download - Filepony Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION Mit Revo auch Moderat die Reste entfernen lassen. Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
23.04.2014, 07:08 | #3 |
| Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Vielen Dank für die schnelle Antwort
__________________Den Revo Uninstaller habe ich schon arbeiten lassen bis er nicht mehr konnte. Bei der Deinstallation des VO Package ist er kaputt gegangen. Er hat fast alle der 60 installierten Programme verloren. Er zeigt mir nur noch zwei installierte Programme an, der Rest des Rechners scheint unbeeinträchtigt. Eine Neuinstallation änderte daran nichts. Die normale Deinstallation von Windows funktioniert. Ich habe aber inzwischen alles Deinstalliert, was mit suspekt erschien. Hier die Logs von mbam, adwcleaner, JRT und FRST Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 22.04.2014 Suchlauf-Zeit: 23:44:20 Logdatei: mbam_2.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.22.07 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: xyz Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 255140 Verstrichene Zeit: 25 Min, 50 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.Savingsbull, C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe, 2324, Löschen bei Neustart, [d22e20e042bea65aed383cca8084847c] Module: 0 (No malicious items detected) Registrierungsschlüssel: 187 PUP.Optional.Savingsbull, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Level Quality Watcher, In Quarantäne, [d22e20e042bea65aed383cca8084847c], PUP.Optional.SaveSense.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\savesenselive, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], PUP.Optional.SaveSense.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\savesenselivem, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SAVESENSELIVE.EXE, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SAVESENSELIVE.EXE, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\APPID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\APPID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}, In Quarantäne, [2fd129d725db1ce40896ca83c33fcd33], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}, In Quarantäne, [2fd129d725db1ce40896ca83c33fcd33], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{4A36AF02-3E2F-47DD-A102-784D22E8C2B8}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B71BC738-1C95-4784-B6AF-5B0964B895D9}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B71BC738-1C95-4784-B6AF-5B0964B895D9}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{4A36AF02-3E2F-47DD-A102-784D22E8C2B8}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], PUP.Optional.ValueApps.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], PUP.Optional.ValueApps.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A9337080-7CBF-4E3E-80C1-3867BEDD88E0}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{886634B3-7045-443A-A52B-E83AD1A90391}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\TYPELIB\{115D21BE-07D8-44B8-871E-EAFE1C1A6F10}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{115D21BE-07D8-44B8-871E-EAFE1C1A6F10}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\Zula Games.Tool.1, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\Zula Games.Tool, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.Tool, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.Tool.1, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\Zula Games.ScriptHostObject.1, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\Zula Games.ScriptHostObject, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.ScriptHostObject, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A9337080-7CBF-4E3E-80C1-3867BEDD88E0}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.ScriptHostObject.1, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A9337080-7CBF-4E3E-80C1-3867BEDD88E0}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ZuluGames, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A9337080-7CBF-4E3E-80C1-3867BEDD88E0}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F63AAEDC-3602-49EF-AA45-262380A98980}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C9A54DFE-051F-49C5-9FC7-ECB81DC6C69F}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8050556E-4AD3-40BD-B338-7DBB0D5C10C8}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9011F634-B91C-400D-8CA2-E9E9A1FCC725}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E171D5FB-6763-4100-87CD-5F918979FBEA}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8050556E-4AD3-40BD-B338-7DBB0D5C10C8}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9011F634-B91C-400D-8CA2-E9E9A1FCC725}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E171D5FB-6763-4100-87CD-5F918979FBEA}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C9A54DFE-051F-49C5-9FC7-ECB81DC6C69F}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.SaveSense.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{71E129FF-6C2A-4984-818C-7E2C998B8D99}, In Quarantäne, [2dd333cdbf41936d2863d44345bd19e7], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{71E129FF-6C2A-4984-818C-7E2C998B8D99}, In Quarantäne, [2dd333cdbf41936d2863d44345bd19e7], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{219046AE-358F-4CF1-B1FD-2B4DE83642A8}, In Quarantäne, [c63a22deaa562bd5480dbc91e2200af6], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{11577C71-9E04-4A42-ACC5-9C7F240BF4FE}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2D017725-74A0-4513-913D-2939ADF6D0F3}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{458BD324-E5D0-412C-954D-EDFD69A59ED9}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9ADA5C62-B227-45A9-9D77-E5609A43E943}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B5445928-B77D-474B-84F6-6F1323CA5701}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{BE6C7021-0352-4A7E-8A5B-46126353049E}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D94BA844-0355-4F02-97F2-6856CD94FE66}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2D017725-74A0-4513-913D-2939ADF6D0F3}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{458BD324-E5D0-412C-954D-EDFD69A59ED9}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9ADA5C62-B227-45A9-9D77-E5609A43E943}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B5445928-B77D-474B-84F6-6F1323CA5701}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BE6C7021-0352-4A7E-8A5B-46126353049E}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D94BA844-0355-4F02-97F2-6856CD94FE66}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{11577C71-9E04-4A42-ACC5-9C7F240BF4FE}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{2A16BB3D-56EA-472B-A8E8-7BB49ABDB37D}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{2A16BB3D-56EA-472B-A8E8-7BB49ABDB37D}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D2C54F93-A898-437F-AE89-7BDD918954A5}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{1B0DA3F5-D96D-483D-8BEF-224BA1B67620}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{1B0DA3F5-D96D-483D-8BEF-224BA1B67620}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\Zula Games.Navbar.1, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\Zula Games.Navbar, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.Navbar, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.Navbar.1, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\CLSID\{D2C54F93-A898-437F-AE89-7BDD918954A5}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.OneClickCtrl.9, In Quarantäne, [7a867d83718fe11f09799c0a72918878], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine, In Quarantäne, [e21e966a867a8977b8cad1d519ea6b95], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine.1.0, In Quarantäne, [3dc3fc0421dfa15f9be7d9cd0ef5a858], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.Update3WebControl.3, In Quarantäne, [867ae31d847cb24e88fa1c8a010251af], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync, In Quarantäne, [a45c837da9579769dea47e28d82b41bf], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync.1.0, In Quarantäne, [2bd5ea16a45c39c78ef4fea8be45ef11], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreClass, In Quarantäne, [6d93c9378f71659b275b6d39b54ebe42], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreClass.1, In Quarantäne, [e8186f91c7395da388fa268037ccba46], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass, In Quarantäne, [629ecc34e020c04085fd5551d72ce719], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass.1, In Quarantäne, [768ab84845bbee12077ba204867de020], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine, In Quarantäne, [3ac61ee2d729ab552e54c2e4b251fa06], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine.1.0, In Quarantäne, [56aacb3514ec38c86e14970f31d20ef2], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine, In Quarantäne, [e21e0df3689837c9daa8a006d72cb14f], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [619fea1629d741bf4f33584e8b78768a], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [a55bce3259a77888f48e1690df2410f0], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [a25eab55e21ed62ae69cb2f46e9551af], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher, In Quarantäne, [e719ae52a25e5fa13f43d4d261a2e51b], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher.1.0, In Quarantäne, [da26b050b050a95700829e0842c1cb35], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService, In Quarantäne, [1ae623dda15f946cc6bc505662a14cb4], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [1be5c13fec1422de275bedb92ed505fb], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine, In Quarantäne, [09f7f709936dab559ae80d9961a27987], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine.1.0, In Quarantäne, [a957ed13e41cc040ed9505a19073f907], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback, In Quarantäne, [857b97691de3a55b3949d8ceb251c13f], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [f20ef010b84834ccc6bc9b0b0bf89c64], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc, In Quarantäne, [cd332fd15da39b65add5c0e642c16e92], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [c43c08f85da39c645131d0d649bab848], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\Zula Games.BackgroundHostObject, In Quarantäne, [0000748cd22e05fbc04bb1ee689bbe42], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\Zula Games.BackgroundHostObject.1, In Quarantäne, [d0300ff11fe1ce320dfea5fa6b9854ac], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\APPID\SaveSenseLive.exe, In Quarantäne, [b44c9b65ce323dc38ff28e1806fd41bf], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [5aa6639d8e72748c79f7f67ef70b1ee2], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [f60a37c997694bb520502e4645bd728e], PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [46ba8977a15f13ed69eee8bbec1714ec], PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\awesomehpSoftware, In Quarantäne, [52aea759ae5268987db767172dd57f81], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\SaveSenseLive, In Quarantäne, [5ea2946c44bca65a8dfafaac37cca858], PUP.Optional.SavingsBull.A, HKLM\SOFTWARE\WOW6432NODE\SavingsbullFilter, In Quarantäne, [02fec937ba46e61ac2674a3326dc936d], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLive.OneClickCtrl.9, In Quarantäne, [dd2367995ba56997d4ae4d59748f58a8], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine, In Quarantäne, [c43cba46ba46857b483a980e58ab58a8], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine.1.0, In Quarantäne, [aa5639c7b947a060dda5f1b5f80bf60a], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLive.Update3WebControl.3, In Quarantäne, [6d93f709f80804fcf78bdaccbe4533cd], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync, In Quarantäne, [5ea221df847ce21e275b83238e75c23e], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync.1.0, In Quarantäne, [ed133ec2738dc13f4d35f0b6689bb44c], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreClass, In Quarantäne, [3cc4e31d57a9f40cc1c19c0aa75c837d], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreClass.1, In Quarantäne, [4fb1c739a060b64ae59d9115a261c43c], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass, In Quarantäne, [f709639d6d9316eaf78b2e78a06352ae], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass.1, In Quarantäne, [b749827e639db0501969555159aa6b95], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine, In Quarantäne, [9967d62aee1257a990f2d9cdf2112ad6], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine.1.0, In Quarantäne, [936da957a060718f255dedb9bb48dc24], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine, In Quarantäne, [6a966f9113edc838582abee820e3a858], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [ca3613ed27d955ababd74165bd46a759], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [2ad67b855da3d72988fa2c7ae91ac838], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [fe021de3ab556f915f2396107b88cd33], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher, In Quarantäne, [20e0916f54ac41bff0926343f310ec14], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher.1.0, In Quarantäne, [c63a4eb2be42ac549ae84066956e728e], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService, In Quarantäne, [679935cb33cd7a86fe846a3c20e311ef], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [32cef808629e8b75eb97149213f0cc34], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine, In Quarantäne, [1ee2956b23dd847ce999bfe749ba966a], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine.1.0, In Quarantäne, [7789ec14d12f6d931e640b9b20e3c937], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback, In Quarantäne, [53ad54ac5ba5649c265c6145fd06827e], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [7789f40c1ee27d83c7bb673f3bc8847c], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc, In Quarantäne, [52ae0ff1649c1ae6364c0d99946f738d], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [1be50000d82898681270aff7ff0425db], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.BackgroundHostObject, In Quarantäne, [e51b0df304fc3bc532d99c039172659b], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.BackgroundHostObject.1, In Quarantäne, [45bbea16e31d38c8a9624a55679cd12f], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\SaveSenseLive.exe, In Quarantäne, [768a6c9435cbed13661bb1f57390c13f], PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\gflandjopdloblmlcoiidmncpinmmacn, In Quarantäne, [996715eb7c840cf4f715a4fbd1322fd1], PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pelmeidfhdlhlbjimpabfcbnnojbboma, In Quarantäne, [b947956b2fd11be5fa13a1d4867c48b8], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [28d8fb059d63ca3675fb78fcd032dc24], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [57a930d0eb15659b2b457400ec16bc44], PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [1de350b026da9a66f95ef9aa946fc53b], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.updaterss.com/SaveSenseLive Update;version=3, In Quarantäne, [25db2ad65fa1847c275e95117d860ff1], PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.updaterss.com/SaveSenseLive Update;version=9, In Quarantäne, [31cf926e738d6e92166f2b7bbc47d729], PUP.Optional.HQTotalS.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQTotalS, In Quarantäne, [47b9946c67997b85ab5e8aebdc2613ed], PUP.Optional.MediaEnhance.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\media enhance, In Quarantäne, [5ca4ac54f60a5ba5c36a1d5b11f131cf], PUP.Optional.MySearchDial.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\mysearchdial, In Quarantäne, [728e7888f010bf41d1be4751798aa858], PUP.Optional.SaveSense.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SaveSenseLive, In Quarantäne, [b0505ba57789e51bd5af089e2dd6a957], PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [44bce11fff0153ad0817cce0a45f02fe], PUP.Optional.HQTotalS.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQTotalS, In Quarantäne, [49b748b8e020718f3ccd7afb19e9c040], PUP.Optional.MediaEnhance.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\media enhance, In Quarantäne, [0ef22fd160a0956b121bafc912f009f7], PUP.Optional.SavingsBull.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Savings Bull, In Quarantäne, [f9079f6113edda265fc7bfbe8082e41c], PUP.Optional.ValueApps.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\ValueApps, In Quarantäne, [1be514ec639dcb353997ea97ee144db3], PUP.Optional.AlexaTB.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DISTROMATIC\Toolbars, In Quarantäne, [c937b44c1de39f61d9489c021ae9a65a], PUP.Optional.InstallCore.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [639d58a8718fda262d2cb5cc9171d62a], PUP.Optional.InstallCore.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [3bc531cf3ec252ae276480177192c53b], PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [7d83a15f817f58a840310272b74bd030], PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [b54bd32d3fc1b0508be6bcb8738f0000], PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\freeven, In Quarantäne, [0000fd039e62d828dcfc393e12f0748c], PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\HQplustotalS, In Quarantäne, [df2117e918e825db09d6195b43bfc23e], PUP.Optional.Qone8, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [eb15b14f6c94ea16e076adf6d62d56aa], PUP.Optional.AdvancedSystemProtector.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\Advanced System Protector, In Quarantäne, [ac548e72867ab14fa79d3e5f649f8a76], PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A18D16ED-27B2-4B83-B70C-15E73F099546}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A18D16ED-27B2-4B83-B70C-15E73F099546}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A18D16ED-27B2-4B83-B70C-15E73F099546}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{998745A3-2AE4-488D-8092-B98FB20A00C2}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C1424421-D274-491E-9D47-11C8D8CB5F9A}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SavingsBull.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Level Quality Watcher, In Quarantäne, [ae52a957f40cd42c8e151b490ef4c838], Registrierungswerte: 3 PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{3004627E-F8E9-4E8B-909D-316753CBA923}, In Quarantäne, [22def50bcc3414ec0b4966e738cab749], PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{3004627E-F8E9-4E8B-909D-316753CBA923}, mysearchdial Toolbar, In Quarantäne, [22def50bcc3414ec0b4966e738cab749] PUP.Optional.InstallCore.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0X2O1C0R2R1R, In Quarantäne, [3bc531cf3ec252ae276480177192c53b] Registrierungsdaten: 17 PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[54accd3387797987a8776ab8ad57fe02] PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}),Ersetzt,[e7195ca46c94e21e69b8ce54956f857b] PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[52aec93700003dc34cd0f82a4cb817e9] PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[02fe43bd52ae15eb25fee63cae56bd43] PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[aa56c23e3fc1659b3ca284a7b1533ec2] PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[07f930d0f40c33cdec335fc329db41bf] PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|Tabs, hxxp://start.mysearchdial.com/?f=2&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0C0EyBtA0E0DtA0EzzzztN0D0Tzu0CyBzztAtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=923418304&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=2&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0C0EyBtA0E0DtA0EzzzztN0D0Tzu0CyBzztAtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=923418304&ir=),Ersetzt,[788822de4cb457a941b773aea064916f] PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}),Ersetzt,[26da60a0907016ea68b956cc26de748c] PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[7090ee121fe1aa5668b471b1c63ec838] PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[58a8cd33d030cf311b086cb61aeafd03] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[16ea58a85aa65aa69a44cf5cc1435ca4] PUP.Optional.Snapdo, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[857b2dd32cd4b05060ee65c6d1339f61] PUP.Optional.Awesomehp.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[7c847e82fb0510f0e13c78aa46be8e72] PUP.Optional.Snapdo, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[946ce21e1ae6cc34a9a43bf0d72dc23e] PUP.Optional.Snapdo, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[c23ea65adf21d52b54fc41ea16eebf41] PUP.Optional.Snapdo, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[8b75956bcd335ea2ff52c66525df867a] PUP.Optional.SnapDo.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[6e920cf4e21ec937ae394fd21ce8e818] Ordner: 60 Adware.InstallBrain, C:\ProgramData\IBUpdaterService, In Quarantäne, [5ea27b85ba469f61cf8198d9f50e12ee], PUP.Optional.Zulagames.A, C:\Users\xyz\AppData\Roaming\zulagames, In Quarantäne, [7789e21e8a764db3dd2ca9f621e2db25], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\mz, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced System Protector, In Quarantäne, [946c3ac6d52b15ebada97be5d52d6a96], PUP.Optional.AdvancedSystemProtector.A, C:\Users\xyz\AppData\Roaming\Systweak\Advanced System Protector, In Quarantäne, [22de2ed20ff1e41c1f378dd309f90ef2], PUP.Optional.MySearchDial.A, C:\Users\xyz\AppData\Roaming\mysearchdial, In Quarantäne, [13ed36cae719639d72fbabb545bdf808], PUP.Optional.FileScout.A, C:\Users\xyz\AppData\Roaming\File Scout, In Quarantäne, [52aed729bb454bb5138099c7a062c63a], PUP.Optional.RegCleanerPro.A, C:\Users\xyz\AppData\Roaming\Systweak\RegClean Pro, In Quarantäne, [ad53c0406b95e21e9b5e5808bc462bd5], PUP.Optional.Conduit.A, C:\ProgramData\Conduit\IE, In Quarantäne, [7090cb35639d2fd115f2bfa2ce34dd23], PUP.Optional.MySearchDial.A, C:\Program Files (x86)\Mysearchdial, In Quarantäne, [e0208779659bcb3500d898c9b250b050], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\CrashReports, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Download, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Install, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Offline, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Offline\{912F06AE-3B00-48A0-98A9-F26EC1DDCB2E}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive, In Quarantäne, [817fcd33fb057d838c610160b44e03fd], PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update, In Quarantäne, [817fcd33fb057d838c610160b44e03fd], PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update\Log, In Quarantäne, [817fcd33fb057d838c610160b44e03fd], PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], PUP.Optional.SaveSense.A, C:\Users\xyz\AppData\Local\SaveSenseLive, In Quarantäne, [689824dcdb255ba519d94d14ea186997], PUP.Optional.SaveSense.A, C:\Users\xyz\AppData\Local\SaveSenseLive\CrashReports, In Quarantäne, [689824dcdb255ba519d94d14ea186997], PUP.Optional.Conduit, C:\Users\xyz\AppData\Local\TBHostSupport, In Quarantäne, [4db3ee12639dda264aaed78a1be714ec], PUP.Optional.Adpeak, C:\Program Files\Level Quality Watcher\v1.01, Löschen bei Neustart, [a75920e0e818fa06b2adfa68936f936d], PUP.Optional.ValueAppsplugin.A, C:\Program Files (x86)\Conduit\ValueApps, In Quarantäne, [ed1357a9b24e7e8279feb3af26dc17e9], PUP.Optional.ValueAppsplugin.A, C:\Program Files (x86)\Conduit\ValueApps\IE, In Quarantäne, [ed1357a9b24e7e8279feb3af26dc17e9], PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\64, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\userCode, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\actions, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\popupResource, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.SavingsBull.A, C:\Program Files\SavingsBull, In Quarantäne, [ae52a957f40cd42c8e151b490ef4c838], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\userCode, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\actions, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\popupResource, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0, In Quarantäne, [2bd5c937e21e4eb2da161d4a14ee20e0], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_deghekbbihbapplmbffglehkdhkeibbm_0, In Quarantäne, [06fa13ed49b7ec14a488600842c06f91], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], Dateien: 310 PUP.Optional.Savingsbull, C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe, Löschen bei Neustart, [d22e20e042bea65aed383cca8084847c], PUP.Optional.SaveSense.A, C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], PUP.Optional.ValueApps.A, C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll, In Quarantäne, [6898629edd232dd37df532e705fdf30d], PUP.Optional.ZuluGames, C:\Program Files (x86)\Zula Games\ScriptHost.dll, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], PUP.Optional.ValueApps.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\MonPrx.dll, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], PUP.Optional.ViddyHD.A, C:\Users\xyz\AppData\Roaming\532d8d0bcd6da1a357004531\532d8d0bcd6da1a357004531.exe, In Quarantäne, [ab5503fd669a06fa7840162d9d6433cd], PUP.Optional.SearchProtect.A, C:\Users\xyz\AppData\Local\Temp\nsk2D6A.exe, In Quarantäne, [867a21df16ea5ca4c7e30f15748db44c], PUP.Optional.Conduit.A, C:\Users\xyz\AppData\Local\Conduit\CT3312331\appbarioDEAutoUpdateHelper.exe, In Quarantäne, [59a7a06026da47b9c265a47a659bed13], PUP.Optional.SmartBar, C:\Windows\Installer\MSI1C54.tmp, In Quarantäne, [36cac43c37c99868c94afa349070f907], PUP.Optional.SmartBar.A, C:\Windows\Installer\242a0866.msi, In Quarantäne, [c63a5ca4c83832ce82519394c73949b7], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_deghekbbihbapplmbffglehkdhkeibbm_0.localstorage, In Quarantäne, [c838ab55827ecc346d939dd6a85a6c94], PUP.Optional.QuickStart.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx, In Quarantäne, [7888d52bb24e857be443462d19e9669a], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0.localstorage, In Quarantäne, [7c84a65a32ce5ea2aca3f0833fc35fa1], PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-chromeinstaller.job, In Quarantäne, [32cec43cd927e11f0404db9ad0323bc5], PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-codedownloader.job, In Quarantäne, [40c006faec1424dc6a9e8de85ea48b75], PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-enabler.job, In Quarantäne, [36ca1ee2aa5658a80800453032d0817f], PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-firefoxinstaller.job, In Quarantäne, [f60aac54639d5ea238d08aeb0ef4867a], PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-updater.job, In Quarantäne, [ea16e11f986856aac543bdb83fc323dd], PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-chromeinstaller.job, In Quarantäne, [b24e30d0649ca15f4fdd572140c2ea16], PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-codedownloader.job, In Quarantäne, [a759748cdc243bc5cf5d1b5dbe44d927], PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-enabler.job, In Quarantäne, [dc2410f024dce61abc70a7d125ddfe02], PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-firefoxinstaller.job, In Quarantäne, [79870ff1dc243bc5e9433e3ac43e4cb4], PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-updater.job, In Quarantäne, [7c84d030aa561ee230fc4d2b31d1de22], PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [4bb5a35da25ee11fb95a0378cd35ae52], PUP.Optional.RegCleanerPro.J, C:\Windows\Tasks\RegClean Pro_UPDATES.job, In Quarantäne, [db2513ed9f612bd5ffba186b04fe24dc], Adware.InstallBrain, C:\ProgramData\IBUpdaterService\repository.xml, In Quarantäne, [5ea27b85ba469f61cf8198d9f50e12ee], PUP.Optional.RegCleanPro.A, C:\Windows\Tasks\RegClean Pro_DEFAULT.job, In Quarantäne, [887830d0956b31cfd250c1d5ce35f20e], PUP.Optional.SpeedAnalysis2.A, C:\Users\xyz\AppData\Roaming\speedanalysis.ico, In Quarantäne, [a060c13fe719c13f85fed9bf758ea55b], PUP.Optional.Zulagames.A, C:\Users\xyz\AppData\Roaming\zulagames\zulagames.crx, In Quarantäne, [7789e21e8a764db3dd2ca9f621e2db25], PUP.Optional.Zulagames.A, C:\Users\xyz\AppData\Roaming\zulagames\icon.ico, In Quarantäne, [7789e21e8a764db3dd2ca9f621e2db25], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\background.html, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon128.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\AddonsFramework.Typelib.dll, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\BackgroundHost.exe, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\BackgroundHost64.exe, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\BackgroundHostPS.dll, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\bg.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\ButtonSite.dll, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\ButtonSite64.dll, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\config.xml, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\content.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon16.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon18.ico, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon18.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon24.ico, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon24.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon32.ico, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon32.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon48.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\jquery-1.9.1.min.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\json2.min.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\uninstall.exe, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\updater.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\updaterWrapper.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\zulagames.rdf, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\mz\background.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\mz\content.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], PUP.Optional.FunMoods.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage, In Quarantäne, [0bf579879c64cd337946edb3c241946c], PUP.Optional.SaveSense, C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job, In Quarantäne, [1fe1c43cdf21778985bba7ff867d0ff1], PUP.Optional.SaveSense, C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job, In Quarantäne, [916fe41cb54b89773d03c0e608fbc838], PUP.Optional.AdvancedSystemProtector.A, C:\Users\xyz\AppData\Roaming\Systweak\Advanced System Protector\Settings.db, In Quarantäne, [22de2ed20ff1e41c1f378dd309f90ef2], PUP.Optional.FileScout.A, C:\Users\xyz\AppData\Roaming\File Scout\uninst.exe, In Quarantäne, [52aed729bb454bb5138099c7a062c63a], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_de.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_el.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_en-GB.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_en.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_es-419.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_es.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_et.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fa.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fi.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fil.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_gu.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_hi.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_hr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_hu.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_id.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_it.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_iw.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ja.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_kn.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ko.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_lt.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_lv.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ml.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_mr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ms.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_nl.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_no.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_pl.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_pt-BR.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_pt-PT.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ro.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdate.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_am.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ar.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_bg.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_bn.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ca.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_cs.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sk.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sl.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sv.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sw.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ta.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_te.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_th.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_tr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_uk.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ur.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_vi.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_zh-CN.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_zh-TW.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psuser.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHelper.msi, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_da.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_is.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ru.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update\Log\SaveSenseLive.log, In Quarantäne, [817fcd33fb057d838c610160b44e03fd], PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\config.dat, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\info.dat, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\STTL.DAT, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\TTL.DAT, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], PUP.Optional.Conduit, C:\Users\xyz\AppData\Local\TBHostSupport\TBHostSupport.dll, In Quarantäne, [4db3ee12639dda264aaed78a1be714ec], PUP.Optional.Conduit, C:\Users\xyz\AppData\Local\TBHostSupport\TBHostSupport_0.dll, In Quarantäne, [4db3ee12639dda264aaed78a1be714ec], PUP.Optional.Adpeak, C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher32.exe, In Quarantäne, [a75920e0e818fa06b2adfa68936f936d], PUP.Optional.ValueAppsplugin.A, C:\Program Files (x86)\Conduit\ValueApps\IE\uninstaller.exe, In Quarantäne, [ed1357a9b24e7e8279feb3af26dc17e9], PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\settings.json, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\ValueApps.exe, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\64\settings.json, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\64\tmpresp.tmp, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\background.html, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\chromeCoreFilesIndex.txt, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\crossriderManifest.json, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\manifest.json, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\popup.html, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\manifest.xml, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins.json, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\102_dealply_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\103_intext_5_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\104_jollywallet_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\13_CrossriderAppUtils.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\14_CrossriderUtils.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\155_ibario_pops_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\177_crossriderDashboard.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\17_jQuery.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\182_openUrl.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\183_tabsWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\184_noproblemppc_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\190_pops_5_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\191_ciuvo_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\195_icm_convertmedia_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\19_CHAppAPIWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\1_base.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\207_dbWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\21_debug.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\220_icm_base_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\226_set_campaign_id_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\22_resources.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\246_setup.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\28_initializer.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\47_resources_background.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\4_jquery_1_7_1.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\64_appApiMessage.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\72_appApiValidation.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\78_CrossriderInfo.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\7_hooks.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\80_CHPopupAppAPI.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\91_monetizationLoader.js.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\93_superfish_no_coupons_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\97_resourceApiWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\9_search_engine_hook.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\userCode\background.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\userCode\extension.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\icon128.png, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\icon16.png, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\icon48.png, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\actions\1.png, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\background.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\main.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\platformVersion.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\chrome.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\cookie.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\message.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\monitor.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\pageAction.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\pageActionBG.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\app_api.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\bg_app_api.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\consts.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\cookie_store.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\crossriderAPI.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\delegate.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\events.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\extensionDataStore.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\installer.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\logFile.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\logging.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\onBGDocumentLoad.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\reports.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\storageWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\updateManager.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\util.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\xhr.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\popupResource\newPopup.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\popupResource\popup.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], PUP.Optional.SavingsBull.A, C:\Program Files\SavingsBull\uninstaller.exe, In Quarantäne, [ae52a957f40cd42c8e151b490ef4c838], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\background.html, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\chromeCoreFilesIndex.txt, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\crossriderManifest.json, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\manifest.json, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\popup.html, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\manifest.xml, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins.json, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\1.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\102.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\103.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\104.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\119.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\13.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\14.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\17.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\177.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\179.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\180.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\182.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\183.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\19.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\191.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\207.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\21.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\22.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\223.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\231.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\232.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\242.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\246.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\28.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\4.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\47.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\64.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\72.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\78.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\80.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\91.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\93.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\97.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\userCode\background.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\userCode\extension.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\icon128.png, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\icon16.png, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\icon48.png, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\actions\1.png, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\background.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\main.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\platformVersion.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\chrome.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\cookie.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\message.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\monitor.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\pageAction.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\pageActionBG.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\app_api.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\bg_app_api.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\consts.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\cookie_store.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\crossriderAPI.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\delegate.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\events.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\extensionDataStore.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\installer.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\logFile.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\logging.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\onBGDocumentLoad.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\reports.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\storageWrapper.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\updateManager.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\util.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\xhr.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\popupResource\newPopup.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\popupResource\popup.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0\15, In Quarantäne, [2bd5c937e21e4eb2da161d4a14ee20e0], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000041.ldb, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000043.ldb, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000098.log, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\CURRENT, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\LOCK, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\LOG, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\LOG.old, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\MANIFEST-000096, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_deghekbbihbapplmbffglehkdhkeibbm_0\14, In Quarantäne, [06fa13ed49b7ec14a488600842c06f91], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\000041.ldb, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\000043.ldb, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\000098.log, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\CURRENT, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\LOCK, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\LOG, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\LOG.old, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\MANIFEST-000096, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.201 - Bericht erstellt am 22/04/2014 um 23:58:48 # Aktualisiert 22/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : xyz - STEFANIE # Gestartet von : C:\Users\xyz\Downloads\adwcleaner (1).exe # Option : Suchen ***** [ Dienste ] ***** Dienst Gefunden : 70e6ca8c ***** [ Dateien / Ordner ] ***** Datei Gefunden : \END Datei Gefunden : C:\END Datei Gefunden : C:\Users\xyz\AppData\Roaming\aps.uninstall.scan.results Datei Gefunden : C:\Users\xyz\Desktop\AppSafe.lnk Datei Gefunden : C:\Windows\System32\Tasks\Advanced System Protector_startup Datei Gefunden : C:\Windows\System32\Tasks\APSnotifierPP1 Datei Gefunden : C:\Windows\System32\Tasks\APSnotifierPP2 Datei Gefunden : C:\Windows\System32\Tasks\APSnotifierPP3 Datei Gefunden : C:\Windows\System32\Tasks\MySearchDial Datei Gefunden : C:\Windows\System32\Tasks\RegClean Pro Datei Gefunden : C:\Windows\System32\Tasks\SaveSense Datei Gefunden : C:\Windows\Tasks\APSnotifierPP1.job Datei Gefunden : C:\Windows\Tasks\APSnotifierPP2.job Datei Gefunden : C:\Windows\Tasks\APSnotifierPP3.job Datei Gefunden : C:\Windows\Tasks\MySearchDial.job Datei Gefunden : C:\Windows\Tasks\SaveSense.job Ordner Gefunden : C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp Ordner Gefunden C:\Program Files (x86)\Advanced System Protector Ordner Gefunden C:\Program Files (x86)\appbarioDE Ordner Gefunden C:\Program Files (x86)\AppSafe Ordner Gefunden C:\Program Files (x86)\Conduit Ordner Gefunden C:\Program Files (x86)\MyPC Backup Ordner Gefunden C:\Program Files (x86)\Optimizer Pro Ordner Gefunden C:\Program Files (x86)\PC Speed Maximizer Ordner Gefunden C:\Program Files (x86)\SupTab Ordner Gefunden C:\Program Files\Level Quality Watcher Ordner Gefunden C:\ProgramData\Activeris Ordner Gefunden C:\ProgramData\Conduit Ordner Gefunden C:\ProgramData\Partner Ordner Gefunden C:\ProgramData\Systweak Ordner Gefunden C:\Users\xyz\AppData\Local\Conduit Ordner Gefunden C:\Users\xyz\AppData\Local\NativeMessaging Ordner Gefunden C:\Users\xyz\AppData\Local\Tuguu_SL Ordner Gefunden C:\Users\xyz\AppData\Local\WhiteListing Ordner Gefunden C:\Users\xyz\AppData\LocalLow\appbarioDE Ordner Gefunden C:\Users\xyz\AppData\LocalLow\Conduit Ordner Gefunden C:\Users\xyz\AppData\Roaming\AppCloudUpdater Ordner Gefunden C:\Users\xyz\AppData\Roaming\AppSafe Ordner Gefunden C:\Users\xyz\AppData\Roaming\PerformerSoft Ordner Gefunden C:\Users\xyz\AppData\Roaming\SearchProtect Ordner Gefunden C:\Users\xyz\AppData\Roaming\SpeedAnalysis2 Ordner Gefunden C:\Users\xyz\AppData\Roaming\SupTab Ordner Gefunden C:\Users\xyz\AppData\Roaming\Systweak Ordner Gefunden C:\Users\xyz\AppData\Roaming\viddyhd Ordner Gefunden C:\Users\xyz\Documents\Optimizer Pro ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Daten Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\optimi~1\optpro~1.dll Daten Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL Schlüssel Gefunden : HKCU\Software\Alexa Internet Schlüssel Gefunden : HKCU\Software\AnyProtect Schlüssel Gefunden : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\appbarioDE Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gefunden : HKCU\Software\AppSafe Schlüssel Gefunden : HKCU\Software\Conduit Schlüssel Gefunden : HKCU\Software\distromatic Schlüssel Gefunden : HKCU\Software\installedbrowserextensions Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{525BA996-1CE4-4677-91C5-9FC4EAD2D245} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{525BA996-1CE4-4677-91C5-9FC4EAD2D245} Schlüssel Gefunden : HKCU\Software\Optimizer Pro Schlüssel Gefunden : HKCU\Software\pc speed maximizer Schlüssel Gefunden : HKCU\Software\performersoft llc Schlüssel Gefunden : HKCU\Software\systweak Schlüssel Gefunden : [x64] HKCU\Software\Alexa Internet Schlüssel Gefunden : [x64] HKCU\Software\AnyProtect Schlüssel Gefunden : [x64] HKCU\Software\AppSafe Schlüssel Gefunden : [x64] HKCU\Software\Conduit Schlüssel Gefunden : [x64] HKCU\Software\distromatic Schlüssel Gefunden : [x64] HKCU\Software\installedbrowserextensions Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gefunden : [x64] HKCU\Software\Optimizer Pro Schlüssel Gefunden : [x64] HKCU\Software\pc speed maximizer Schlüssel Gefunden : [x64] HKCU\Software\performersoft llc Schlüssel Gefunden : [x64] HKCU\Software\systweak Schlüssel Gefunden : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gefunden : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Schlüssel Gefunden : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C} Schlüssel Gefunden : HKLM\Software\appbarioDE Schlüssel Gefunden : HKLM\Software\AppSafe Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{525BA996-1CE4-4677-91C5-9FC4EAD2D245} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\speedupmypc Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66} Schlüssel Gefunden : HKLM\Software\Conduit Schlüssel Gefunden : HKLM\Software\installedbrowserextensions Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4C180B6-0C26-4E0F-B4B9-1D7EF346F3D5} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASAPI32 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASMANCS Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{525BA996-1CE4-4677-91C5-9FC4EAD2D245} Schlüssel Gefunden : HKLM\Software\supWPM Schlüssel Gefunden : HKLM\Software\systweak Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\installedbrowserextensions Schlüssel Gefunden : [x64] HKLM\SOFTWARE\LevelQualityWatcher Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5} Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [speedanalysis02@SpeedAnalysis.com] Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [zulagames@ZulaGames.com] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{525BA996-1CE4-4677-91C5-9FC4EAD2D245}] Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{525BA996-1CE4-4677-91C5-9FC4EAD2D245}] Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [speedanalysis02@SpeedAnalysis.com] Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [zulagames@ZulaGames.com] Wert Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}] ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms} -\\ Google Chrome v34.0.1847.116 [ Datei : C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gefunden [Extension] : booedmolknjekdopkepjjeckmjkdpfgl Gefunden [Extension] : deghekbbihbapplmbffglehkdhkeibbm Gefunden [Extension] : dgjkhjdcljddbedokogakmmdjgnbeanf Gefunden [Extension] : flpcjncodpafbgdpnkljologafpionhb Gefunden [Extension] : gflandjopdloblmlcoiidmncpinmmacn Gefunden [Extension] : jainjonnknhmbbkibcbmhihbopigapdm Gefunden [Extension] : lekgiimbfodefdaoofhlckefjbgpeilo Gefunden [Extension] : ombmmloebnfnpehgjnmkcgoegfachobp Gefunden [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma ************************* AdwCleaner[R0].txt - [26531 octets] - [22/04/2014 16:56:01] AdwCleaner[R1].txt - [10510 octets] - [22/04/2014 23:58:48] ########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [10571 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by xyz on 23.04.2014 at 2:58:02,62 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F816170D-C994-4B74-B9A4-234C3838C9EB} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{10F02070-5C8C-4E0B-9D76-ED5DEC00A416} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DCBF59AF-92DF-4CD7-A341-6F448E532676} ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 23.04.2014 at 3:13:30,56 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Bin gespannt wie es aussieht!!
__________________ |
23.04.2014, 07:12 | #4 |
| Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Hier die FRST Log Datei und die Addition.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014 Ran by xyz (administrator) on STEFANIE on 23-04-2014 07:39:23 Running from C:\Users\xyz\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\system32\atiesrxx.exe (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (AMD) C:\Windows\system32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe (ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Jumping Bytes) C:\Program Files (x86)\PureSync\PureSyncTray.exe (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-09-19] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2816808 2011-07-21] (Synaptics Incorporated) HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [98088 2011-07-21] (Synaptics Incorporated) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-22] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS) HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [PureSync] => C:\Program Files (x86)\PureSync\PureSyncTray.exe [906928 2013-12-20] (Jumping Bytes) HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation) HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [6277912 2014-03-18] (Piriform Ltd) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - URL hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3319116&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP5C705B91-74C4-49A1-A0D9-25AFC5B7A96E&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKCU - {433C345D-C1DE-4AE3-9E63-DFA494815841} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin SearchScopes: HKCU - {7F1A9171-10E2-4C11-A42A-253499CDF7C5} URL = hxxp://dict.leo.org/ende?lp=ende&lang=de&searchLoc=0&cmpType=relaxed§Hdr=on&spellToler=on&chinese=both&pinyin=diacritic&search={searchTerms}&relink=on SearchScopes: HKCU - {C177248B-A9BC-4AF0-99CC-32A2CE37D81E} URL = hxxp://www.dict.cc/?s={searchTerms} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Extension: Widget context - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2014-04-22] Chrome: ======= CHR HomePage: CHR StartupUrls: "hxxp://www.google.de/"]},"sync_promo":{"show_on_first_run_allowed":false},"translate_accepted_count":{"en":0,"nl":0,"und":0},"translate_blocked_languages":["de"],"translate_denied_count":{"en":39,"nl":3,"und":4},"translate_whitelists":{},"webkit":{"webprefs":{"allow_running_insecure_content" CHR Extension: (YouTube) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-15] CHR Extension: (Google Search) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-15] CHR Extension: (Google Wallet) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-22] CHR Extension: (No Name) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp [2014-04-22] CHR Extension: (Gmail) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-15] CHR HKCU\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24] CHR HKLM-x32\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24] ==================== Services (Whitelisted) ================= R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [16768 2011-09-20] (ASUSTek Computer Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61120 2014-03-22] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-23 07:39 - 2014-04-23 07:39 - 00012857 _____ () C:\Users\xyz\Downloads\FRST.txt 2014-04-23 02:58 - 2014-04-23 02:58 - 00000000 ____D () C:\Windows\ERUNT 2014-04-23 00:53 - 2014-04-23 04:05 - 00014744 _____ () C:\Windows\WindowsUpdate.log 2014-04-23 00:00 - 2014-04-23 00:00 - 01016261 _____ (Thisisu) C:\Users\xyz\Downloads\JRT.exe 2014-04-22 23:57 - 2014-04-22 23:58 - 01345435 _____ () C:\Users\xyz\Downloads\adwcleaner (1).exe 2014-04-22 23:14 - 2014-04-22 23:14 - 00003284 _____ () C:\Windows\System32\Tasks\{324FD7F0-E2EE-4055-8CE7-EB756A000476} 2014-04-22 23:08 - 2014-04-22 23:08 - 00001266 _____ () C:\Users\xyz\Desktop\Revo Uninstaller.lnk 2014-04-22 23:07 - 2014-04-22 23:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\xyz\Downloads\revosetup.exe 2014-04-22 22:58 - 2014-04-22 23:48 - 00000274 _____ () C:\Windows\Tasks\AppSafe.job 2014-04-22 22:58 - 2014-04-22 23:04 - 00003010 _____ () C:\Windows\System32\Tasks\AppSafe 2014-04-22 19:54 - 2014-04-23 07:38 - 00000000 ____D () C:\Users\xyz\Desktop\log Dateien 2014-04-22 18:54 - 2014-04-22 18:54 - 00380416 _____ () C:\Users\xyz\Downloads\Gmer-19357.exe 2014-04-22 18:51 - 2014-04-23 07:39 - 00000000 ____D () C:\FRST 2014-04-22 18:51 - 2014-04-22 18:51 - 02061312 _____ (Farbar) C:\Users\xyz\Downloads\FRST64.exe 2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable 2014-04-22 18:47 - 2014-04-22 18:47 - 00050477 _____ () C:\Users\xyz\Downloads\Defogger.exe 2014-04-22 16:55 - 2014-04-23 02:55 - 00000000 ____D () C:\AdwCleaner 2014-04-22 16:54 - 2014-04-22 16:54 - 01335637 _____ () C:\Users\xyz\Downloads\adwcleaner.exe 2014-04-22 16:51 - 2014-04-22 23:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-22 16:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-22 16:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-22 16:51 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-04-22 14:51 - 2014-04-22 14:53 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files\iTunes 2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod 2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7} 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList 2014-04-13 12:00 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-13 12:00 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-13 12:00 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-13 12:00 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-13 11:59 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-13 11:59 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-13 11:59 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-13 11:59 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-13 11:59 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-13 11:59 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-13 11:59 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-13 11:59 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-13 11:59 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-13 11:59 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-13 11:59 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-13 11:59 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97} ==================== One Month Modified Files and Folders ======= 2014-04-23 07:39 - 2014-04-23 07:39 - 00012857 _____ () C:\Users\xyz\Downloads\FRST.txt 2014-04-23 07:39 - 2014-04-22 18:51 - 00000000 ____D () C:\FRST 2014-04-23 07:38 - 2014-04-22 19:54 - 00000000 ____D () C:\Users\xyz\Desktop\log Dateien 2014-04-23 07:25 - 2014-04-23 00:53 - 00014744 _____ () C:\Windows\WindowsUpdate.log 2014-04-23 07:20 - 2013-03-15 17:16 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-23 06:53 - 2013-03-15 17:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-23 04:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-23 02:58 - 2014-04-23 02:58 - 00000000 ____D () C:\Windows\ERUNT 2014-04-23 02:55 - 2014-04-22 16:55 - 00000000 ____D () C:\AdwCleaner 2014-04-23 00:58 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-23 00:58 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-23 00:50 - 2013-03-15 17:16 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-23 00:50 - 2013-01-10 19:09 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe 2014-04-23 00:50 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-23 00:00 - 2014-04-23 00:00 - 01016261 _____ (Thisisu) C:\Users\xyz\Downloads\JRT.exe 2014-04-22 23:58 - 2014-04-22 23:57 - 01345435 _____ () C:\Users\xyz\Downloads\adwcleaner (1).exe 2014-04-22 23:51 - 2014-04-22 16:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-22 23:48 - 2014-04-22 22:58 - 00000274 _____ () C:\Windows\Tasks\AppSafe.job 2014-04-22 23:45 - 2014-03-22 15:16 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\532d8d0bcd6da1a357004531 2014-04-22 23:14 - 2014-04-22 23:14 - 00003284 _____ () C:\Windows\System32\Tasks\{324FD7F0-E2EE-4055-8CE7-EB756A000476} 2014-04-22 23:08 - 2014-04-22 23:08 - 00001266 _____ () C:\Users\xyz\Desktop\Revo Uninstaller.lnk 2014-04-22 23:08 - 2013-01-10 19:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-22 23:07 - 2014-04-22 23:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\xyz\Downloads\revosetup.exe 2014-04-22 23:04 - 2014-04-22 22:58 - 00003010 _____ () C:\Windows\System32\Tasks\AppSafe 2014-04-22 22:55 - 2012-08-22 09:25 - 00002224 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-04-22 21:01 - 2013-03-23 17:29 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-22 21:01 - 2013-01-10 19:56 - 00000000 ____D () C:\Program Files\CCleaner 2014-04-22 18:54 - 2014-04-22 18:54 - 00380416 _____ () C:\Users\xyz\Downloads\Gmer-19357.exe 2014-04-22 18:51 - 2014-04-22 18:51 - 02061312 _____ (Farbar) C:\Users\xyz\Downloads\FRST64.exe 2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable 2014-04-22 18:48 - 2013-01-10 19:09 - 00000000 ____D () C:\Users\xyz 2014-04-22 18:47 - 2014-04-22 18:47 - 00050477 _____ () C:\Users\xyz\Downloads\Defogger.exe 2014-04-22 17:07 - 2009-07-14 04:34 - 00000678 _____ () C:\Windows\win.ini 2014-04-22 16:54 - 2014-04-22 16:54 - 01335637 _____ () C:\Users\xyz\Downloads\adwcleaner.exe 2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-22 16:45 - 2014-03-22 15:23 - 54485192 _____ () C:\Windows\system32\SavingsBullFilterService.log 2014-04-22 16:31 - 2012-08-22 09:25 - 00000000 ____D () C:\ProgramData\P4G 2014-04-22 16:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-04-22 16:01 - 2014-03-16 18:37 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-04-22 15:24 - 2011-02-19 06:24 - 00710852 _____ () C:\Windows\system32\perfh007.dat 2014-04-22 15:24 - 2011-02-19 06:24 - 00153300 _____ () C:\Windows\system32\perfc007.dat 2014-04-22 15:24 - 2009-07-14 07:13 - 01650460 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-04-22 14:53 - 2014-04-22 14:51 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iTunes 2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod 2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7} 2014-04-22 14:28 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-22 14:27 - 2014-03-23 00:42 - 00000000 ____D () C:\ProgramData\Free Download Manager 2014-04-22 14:27 - 2013-01-15 00:13 - 00000000 ____D () C:\Program Files (x86)\HP 2014-04-22 14:27 - 2013-01-10 19:57 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com 2014-04-22 14:27 - 2012-08-22 09:28 - 00000000 ____D () C:\Program Files (x86)\CyberLink 2014-04-22 14:27 - 2011-04-13 04:47 - 00000000 ____D () C:\Program Files (x86)\ASUS 2014-04-22 14:24 - 2011-04-13 04:49 - 00000000 ____D () C:\AsusVibeData 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList 2014-04-22 13:37 - 2014-03-23 00:41 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Free Download Manager 2014-04-22 10:58 - 2013-01-10 21:38 - 00000000 ____D () C:\Users\xyz\Documents\Outlook-Dateien 2014-04-16 11:48 - 2013-01-10 21:18 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-16 11:46 - 2013-08-15 03:01 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-16 11:38 - 2013-01-13 08:13 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97} 2014-04-03 19:15 - 2013-03-15 17:16 - 00004126 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-03 19:15 - 2013-03-15 17:16 - 00003874 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-03 19:14 - 2014-02-25 11:15 - 00002155 _____ () C:\Windows\epplauncher.mif 2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-04-03 09:51 - 2014-04-22 16:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-22 16:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-22 16:51 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 03:16 - 2014-04-13 12:00 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-13 12:00 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-27 20:09 - 2014-03-15 20:38 - 00000110 _____ () C:\Users\xyz\AppData\Roaming\WB.CFG Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.5928.dll Some content of TEMP: ==================== C:\Users\xyz\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-23 04:15 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2014 Ran by xyz at 2014-04-23 08:48:54 Running from C:\Users\xyz\Desktop\log Dateien Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden AMD APP SDK Runtime (Version: 2.5.775.2 - Advanced Micro Devices Inc.) Hidden AMD AVIVO64 Codecs (Version: 11.7.0.10927 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{92015CBE-D397-C3EA-99FC-B03051DE69A4}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) ccc-utility64 (Version: 2011.0927.2225.38375 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS) HP Unified IO (Version: 1.0.1.95 - HP) Hidden iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden MAGIX Video easy HD (Version: 5.0.0.99 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.17.0 - Synaptics Incorporated) ==================== Restore Points ========================= 22-04-2014 09:03:06 Revo Uninstaller's restore point - Adobe Flash Player Packages 22-04-2014 09:08:22 Revo Uninstaller's restore point - AsusVibe2.0 22-04-2014 09:10:31 Revo Uninstaller's restore point - NewPlayer 22-04-2014 09:13:05 Revo Uninstaller's restore point - Optimizer Pro v3.2 22-04-2014 09:14:28 Revo Uninstaller's restore point - HQTotalS 22-04-2014 09:15:53 Revo Uninstaller's restore point - IePluginService12.27.0.3326 22-04-2014 09:17:02 Revo Uninstaller's restore point - InstantOn for NB 22-04-2014 09:20:20 Revo Uninstaller's restore point - Lollipop 22-04-2014 09:21:59 Revo Uninstaller's restore point - media enhance 22-04-2014 11:16:55 Revo Uninstaller's restore point - Re-markit 22-04-2014 11:18:38 Revo Uninstaller's restore point - PC Speed Maximizer v3.2 22-04-2014 11:19:57 Revo Uninstaller's restore point - Plants vs Zombies 22-04-2014 11:34:22 Revo Uninstaller's restore point - WPM17.8.0.3442 22-04-2014 11:35:41 Revo Uninstaller's restore point - ViddyHD 22-04-2014 11:37:27 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections 22-04-2014 11:39:22 Revo Uninstaller's restore point - VO Package 22-04-2014 12:10:15 Wiederherstellungsvorgang 22-04-2014 13:03:55 Revo Uninstaller's restore point - Advanced System Protector 22-04-2014 13:07:03 Revo Uninstaller's restore point - Adobe Flash Player Packages 22-04-2014 13:10:00 Revo Uninstaller's restore point - awesomehp uninstaller 22-04-2014 13:11:25 Revo Uninstaller's restore point - File Extractor 22-04-2014 13:13:59 Revo Uninstaller's restore point - DMUninstaller 22-04-2014 13:23:47 Revo Uninstaller's restore point - RegClean Pro 22-04-2014 13:25:57 Revo Uninstaller's restore point - Lollipop 22-04-2014 13:27:32 Revo Uninstaller's restore point - ViddyHD 22-04-2014 13:30:02 Revo Uninstaller's restore point - PC Speed Maximizer v3.2 22-04-2014 13:44:45 Revo Uninstaller's restore point - Search Protect 22-04-2014 13:49:20 Revo Uninstaller's restore point - SupTab 22-04-2014 13:50:55 Revo Uninstaller's restore point - Mysearchdial 22-04-2014 13:52:32 Revo Uninstaller's restore point - WPM17.8.0.3442 22-04-2014 13:59:32 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections 22-04-2014 14:00:35 Revo Uninstaller's restore point - Re-markit 22-04-2014 14:01:51 Revo Uninstaller's restore point - Optimizer Pro v3.2 22-04-2014 14:11:03 Revo Uninstaller's restore point - IePluginService12.27.0.3326 22-04-2014 14:14:36 Revo Uninstaller's restore point - media enhance 22-04-2014 14:20:06 Revo Uninstaller's restore point - VO Package 22-04-2014 14:27:49 Wiederherstellungsvorgang 22-04-2014 14:37:37 Revo Uninstaller's restore point - HQTotalS 22-04-2014 21:08:31 Revo Uninstaller's restore point - AppCloudUpdater ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05490B50-D0A0-4A3C-A560-6ACF63DE1E42} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd) Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - \APSnotifierPP2 No Task File <==== ATTENTION Task: {0B4E379A-4C4A-428E-9BCF-A1135BBA3E4A} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2012-09-27] () Task: {1CCE7D51-38D1-4F66-B7AC-A43176E2120F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-09-30] (ASUSTeK Computer Inc.) Task: {3E2E8B1F-6878-402A-87AB-F2EF5FEBADCE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.) Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - \APSnotifierPP1 No Task File <==== ATTENTION Task: {4C14D4FC-EFFF-4FC1-BA61-EEFA91392794} - System32\Tasks\USBChargerPlus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2011-09-20] (ASUSTek Computer Inc.) Task: {5CDD33CE-1114-4D15-A601-881F87353200} - System32\Tasks\AppSafe => C:\Program Files (x86)\AppSafe\AppSafe.exe Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - \Advanced System Protector_startup No Task File <==== ATTENTION Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - \MySearchDial No Task File <==== ATTENTION Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - \RegClean Pro No Task File <==== ATTENTION Task: {8FFE3A4C-B16E-4461-A1BC-27379739F580} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22] (ASUS) Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - \APSnotifierPP3 No Task File <==== ATTENTION Task: {AF490895-86A7-4FE9-9CC6-9EC88297132C} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-11-22] (ASUS) Task: {C410E796-D92D-4AEB-A596-89D282D0DBF8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.) Task: {EAD7D671-DBE5-4388-994E-8F508652131C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS) Task: {EB32D426-01C9-4433-875C-580B292A89F0} - \SaveSense No Task File <==== ATTENTION Task: {EDBAD762-5B95-4C13-9FA0-333BACA63683} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-14] (Adobe Systems Incorporated) Task: {F9C0DFA3-7859-4C70-A44F-5E77F9E82EA7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {FE3FBFF8-BA1D-4554-A7AA-BA0DCD11606F} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AppSafe.job => C:\Program Files (x86)\AppSafe\AppSafe.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2011-10-13 08:19 - 2011-07-21 12:59 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2011-09-30 02:06 - 2011-09-30 02:06 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll 2011-11-22 16:09 - 2011-11-22 16:09 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2011-09-13 22:33 - 2011-09-13 22:33 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:AD022376 ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Error: (04/23/2014 07:36:58 AM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 28% Total physical RAM: 6048.05 MB Available physical RAM: 4294.69 MB Total Pagefile: 12094.28 MB Available Pagefile: 10146.46 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:195.35 GB) (Free:127.96 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Data) (Fixed) (Total:245.41 GB) (Free:210.98 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 496B9619) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=195 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=245 GB) - (Type=07 NTFS) ==================== End Of Log ============================
__________________ Gruß Volker Geändert von caiphi (23.04.2014 um 07:58 Uhr) Grund: Addition.txt ergänzt |
23.04.2014, 14:20 | #5 |
/// the machine /// TB-Ausbilder | Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive WerbungESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.04.2014, 17:37 | #6 |
| Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Eset Scan ist durchgelaufen. Hat keine Threads gefunden. Bei der Deinstallation ist leider auch der Logfile mit gelöscht worden. Reicht Dir die Info, daß nichts gefunden wurde, oder soll ich nochmal laufen lassen (hat ca. 1,5 h gebraucht) Den Logfile des securitychecks hab ich hier Code:
ATTFilter Results of screen317's Security Check version 0.99.82 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Secunia PSI (3.0.0.9016) Adobe Flash Player 13.0.0.182 Google Chrome 33.0.1750.154 Google Chrome 34.0.1847.116 Google Chrome Plugins... ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials msseces.exe Windows Defender MSMpEng.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014 Ran by xyz (administrator) on STEFANIE on 23-04-2014 18:38:13 Running from C:\Users\xyz\Desktop\log Dateien Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\system32\atiesrxx.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (AMD) C:\Windows\system32\atieclxx.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS) C:\Windows\AsScrPro.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Jumping Bytes) C:\Program Files (x86)\PureSync\PureSyncTray.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe (Secunia) C:\Program Files (x86)\Secunia\PSI\PSI_TRAY.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-09-19] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2816808 2011-07-21] (Synaptics Incorporated) HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [98088 2011-07-21] (Synaptics Incorporated) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation) HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-22] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS) HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [PureSync] => C:\Program Files (x86)\PureSync\PureSyncTray.exe [906928 2013-12-20] (Jumping Bytes) HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation) HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [6277912 2014-03-18] (Piriform Ltd) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - URL hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3319116&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP5C705B91-74C4-49A1-A0D9-25AFC5B7A96E&q={searchTerms}&SSPV= SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} SearchScopes: HKCU - {433C345D-C1DE-4AE3-9E63-DFA494815841} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin SearchScopes: HKCU - {7F1A9171-10E2-4C11-A42A-253499CDF7C5} URL = hxxp://dict.leo.org/ende?lp=ende&lang=de&searchLoc=0&cmpType=relaxed§Hdr=on&spellToler=on&chinese=both&pinyin=diacritic&search={searchTerms}&relink=on SearchScopes: HKCU - {C177248B-A9BC-4AF0-99CC-32A2CE37D81E} URL = hxxp://www.dict.cc/?s={searchTerms} BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) FF Extension: Widget context - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2014-04-22] Chrome: ======= CHR HomePage: CHR StartupUrls: "hxxp://www.google.de/" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll () CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation) CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Extension: (YouTube) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-15] CHR Extension: (Google-Suche) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-15] CHR Extension: (Google Wallet) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-22] CHR Extension: (Google Mail) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-15] CHR HKCU\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24] CHR HKLM-x32\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24] ==================== Services (Whitelisted) ================= R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation) R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia) S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia) ==================== Drivers (Whitelisted) ==================== R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [16768 2011-09-20] (ASUSTek Computer Inc.) R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation) R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia) R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61120 2014-03-22] (StdLib) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-23 18:24 - 2014-04-23 18:24 - 17932464 _____ (Adobe Systems Incorporated) C:\Users\xyz\Downloads\flashplayer13_install_win_pi.exe 2014-04-23 18:19 - 2014-04-23 18:19 - 00000000 ____D () C:\Users\xyz\AppData\Local\Secunia PSI 2014-04-23 18:19 - 2014-04-23 18:19 - 00000000 ____D () C:\Program Files (x86)\Secunia 2014-04-23 15:38 - 2014-04-23 15:38 - 00855379 _____ () C:\Users\xyz\Downloads\SecurityCheck.exe 2014-04-23 15:25 - 2014-04-23 15:25 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-23 15:24 - 2014-04-23 15:24 - 02347384 _____ (ESET) C:\Users\xyz\Downloads\esetsmartinstaller_enu.exe 2014-04-23 02:58 - 2014-04-23 02:58 - 00000000 ____D () C:\Windows\ERUNT 2014-04-23 00:53 - 2014-04-23 18:21 - 00089985 _____ () C:\Windows\WindowsUpdate.log 2014-04-22 23:14 - 2014-04-22 23:14 - 00003284 _____ () C:\Windows\System32\Tasks\{324FD7F0-E2EE-4055-8CE7-EB756A000476} 2014-04-22 23:08 - 2014-04-22 23:08 - 00001266 _____ () C:\Users\xyz\Desktop\Revo Uninstaller.lnk 2014-04-22 22:58 - 2014-04-22 23:48 - 00000274 _____ () C:\Windows\Tasks\AppSafe.job 2014-04-22 22:58 - 2014-04-22 23:04 - 00003010 _____ () C:\Windows\System32\Tasks\AppSafe 2014-04-22 19:54 - 2014-04-23 18:38 - 00000000 ____D () C:\Users\xyz\Desktop\log Dateien 2014-04-22 18:51 - 2014-04-23 18:38 - 00000000 ____D () C:\FRST 2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable 2014-04-22 16:55 - 2014-04-23 02:55 - 00000000 ____D () C:\AdwCleaner 2014-04-22 16:51 - 2014-04-23 09:04 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-22 16:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-22 16:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-22 16:51 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-04-22 14:51 - 2014-04-22 14:53 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files\iTunes 2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod 2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7} 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList 2014-04-13 12:00 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-13 12:00 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-13 12:00 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-13 12:00 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-13 11:59 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-13 11:59 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-13 11:59 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-13 11:59 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-13 11:59 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-13 11:59 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-13 11:59 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-13 11:59 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-13 11:59 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-13 11:59 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-13 11:59 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-13 11:59 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-13 11:59 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97} ==================== One Month Modified Files and Folders ======= 2014-04-23 18:38 - 2014-04-22 19:54 - 00000000 ____D () C:\Users\xyz\Desktop\log Dateien 2014-04-23 18:38 - 2014-04-22 18:51 - 00000000 ____D () C:\FRST 2014-04-23 18:27 - 2013-06-20 15:25 - 00000000 ____D () C:\Users\xyz\AppData\Local\Adobe 2014-04-23 18:27 - 2013-03-15 17:16 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-04-23 18:27 - 2013-03-15 17:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-04-23 18:27 - 2013-01-27 17:18 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-04-23 18:27 - 2013-01-27 17:18 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-04-23 18:24 - 2014-04-23 18:24 - 17932464 _____ (Adobe Systems Incorporated) C:\Users\xyz\Downloads\flashplayer13_install_win_pi.exe 2014-04-23 18:21 - 2014-04-23 00:53 - 00089985 _____ () C:\Windows\WindowsUpdate.log 2014-04-23 18:20 - 2013-03-15 17:16 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-23 18:19 - 2014-04-23 18:19 - 00000000 ____D () C:\Users\xyz\AppData\Local\Secunia PSI 2014-04-23 18:19 - 2014-04-23 18:19 - 00000000 ____D () C:\Program Files (x86)\Secunia 2014-04-23 15:38 - 2014-04-23 15:38 - 00855379 _____ () C:\Users\xyz\Downloads\SecurityCheck.exe 2014-04-23 15:25 - 2014-04-23 15:25 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-04-23 15:24 - 2014-04-23 15:24 - 02347384 _____ (ESET) C:\Users\xyz\Downloads\esetsmartinstaller_enu.exe 2014-04-23 10:44 - 2014-01-11 20:00 - 00000000 ____D () C:\Program Files (x86)\MAGIX 2014-04-23 10:38 - 2013-01-10 21:38 - 00000000 ____D () C:\Users\xyz\Documents\Outlook-Dateien 2014-04-23 10:17 - 2011-04-13 04:49 - 00000000 ____D () C:\AsusVibeData 2014-04-23 09:32 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-23 09:32 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-23 09:25 - 2013-03-15 17:16 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-23 09:25 - 2013-01-10 19:09 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe 2014-04-23 09:24 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-23 09:04 - 2014-04-22 16:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-23 04:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-04-23 02:58 - 2014-04-23 02:58 - 00000000 ____D () C:\Windows\ERUNT 2014-04-23 02:55 - 2014-04-22 16:55 - 00000000 ____D () C:\AdwCleaner 2014-04-22 23:48 - 2014-04-22 22:58 - 00000274 _____ () C:\Windows\Tasks\AppSafe.job 2014-04-22 23:45 - 2014-03-22 15:16 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\532d8d0bcd6da1a357004531 2014-04-22 23:14 - 2014-04-22 23:14 - 00003284 _____ () C:\Windows\System32\Tasks\{324FD7F0-E2EE-4055-8CE7-EB756A000476} 2014-04-22 23:08 - 2014-04-22 23:08 - 00001266 _____ () C:\Users\xyz\Desktop\Revo Uninstaller.lnk 2014-04-22 23:08 - 2013-01-10 19:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group 2014-04-22 23:04 - 2014-04-22 22:58 - 00003010 _____ () C:\Windows\System32\Tasks\AppSafe 2014-04-22 22:55 - 2012-08-22 09:25 - 00002224 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-04-22 21:01 - 2013-03-23 17:29 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-04-22 21:01 - 2013-01-10 19:56 - 00000000 ____D () C:\Program Files\CCleaner 2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable 2014-04-22 18:48 - 2013-01-10 19:09 - 00000000 ____D () C:\Users\xyz 2014-04-22 17:07 - 2009-07-14 04:34 - 00000678 _____ () C:\Windows\win.ini 2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-04-22 16:45 - 2014-03-22 15:23 - 54485192 _____ () C:\Windows\system32\SavingsBullFilterService.log 2014-04-22 16:31 - 2012-08-22 09:25 - 00000000 ____D () C:\ProgramData\P4G 2014-04-22 16:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-04-22 16:01 - 2014-03-16 18:37 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live 2014-04-22 15:24 - 2011-02-19 06:24 - 00710852 _____ () C:\Windows\system32\perfh007.dat 2014-04-22 15:24 - 2011-02-19 06:24 - 00153300 _____ () C:\Windows\system32\perfc007.dat 2014-04-22 15:24 - 2009-07-14 07:13 - 01650460 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk 2014-04-22 14:53 - 2014-04-22 14:51 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iTunes 2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files (x86)\iTunes 2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod 2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7} 2014-04-22 14:28 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy 2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy 2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-22 14:27 - 2014-03-23 00:42 - 00000000 ____D () C:\ProgramData\Free Download Manager 2014-04-22 14:27 - 2013-01-15 00:13 - 00000000 ____D () C:\Program Files (x86)\HP 2014-04-22 14:27 - 2013-01-10 19:57 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com 2014-04-22 14:27 - 2012-08-22 09:28 - 00000000 ____D () C:\Program Files (x86)\CyberLink 2014-04-22 14:27 - 2011-04-13 04:47 - 00000000 ____D () C:\Program Files (x86)\ASUS 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList 2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList 2014-04-22 13:37 - 2014-03-23 00:41 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Free Download Manager 2014-04-16 11:48 - 2013-01-10 21:18 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-04-16 11:46 - 2013-08-15 03:01 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-16 11:38 - 2013-01-13 08:13 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp 2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97} 2014-04-03 19:15 - 2013-03-15 17:16 - 00004126 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-03 19:15 - 2013-03-15 17:16 - 00003874 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-03 19:14 - 2014-02-25 11:15 - 00002155 _____ () C:\Windows\epplauncher.mif 2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files\Microsoft Security Client 2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client 2014-04-03 09:51 - 2014-04-22 16:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-22 16:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-22 16:51 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-31 03:16 - 2014-04-13 12:00 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-03-31 03:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-03-31 02:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-03-31 01:57 - 2014-04-13 12:00 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-03-27 20:09 - 2014-03-15 20:38 - 00000110 _____ () C:\Users\xyz\AppData\Roaming\WB.CFG Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.5928.dll Some content of TEMP: ==================== C:\Users\xyz\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-23 04:15 ==================== End Of Log ============================ --- --- --- Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2014 Ran by xyz at 2014-04-23 18:39:17 Running from C:\Users\xyz\Desktop\log Dateien Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2} ==================== Installed Programs ====================== 64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\{28ADCCAD-3C23-44A1-A93F-47AA176F7AD7}) (Version: 13.0.0.182 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.182 - Adobe Systems Incorporated) AMD APP SDK Runtime (Version: 2.5.775.2 - Advanced Micro Devices Inc.) Hidden AMD AVIVO64 Codecs (Version: 11.7.0.10927 - Advanced Micro Devices, Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{92015CBE-D397-C3EA-99FC-B03051DE69A4}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.) Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.) ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) ccc-utility64 (Version: 2011.0927.2225.38375 - Advanced Micro Devices, Inc.) Hidden CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS) HP Unified IO (Version: 1.0.1.95 - HP) Hidden iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.) iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.) MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation) Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) Secunia PSI (3.0.0.9016) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.17.0 - Synaptics Incorporated) ==================== Restore Points ========================= 22-04-2014 11:37:27 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections 22-04-2014 11:39:22 Revo Uninstaller's restore point - VO Package 22-04-2014 12:10:15 Wiederherstellungsvorgang 22-04-2014 13:03:55 Revo Uninstaller's restore point - Advanced System Protector 22-04-2014 13:07:03 Revo Uninstaller's restore point - Adobe Flash Player Packages 22-04-2014 13:10:00 Revo Uninstaller's restore point - awesomehp uninstaller 22-04-2014 13:11:25 Revo Uninstaller's restore point - File Extractor 22-04-2014 13:13:59 Revo Uninstaller's restore point - DMUninstaller 22-04-2014 13:23:47 Revo Uninstaller's restore point - RegClean Pro 22-04-2014 13:25:57 Revo Uninstaller's restore point - Lollipop 22-04-2014 13:27:32 Revo Uninstaller's restore point - ViddyHD 22-04-2014 13:30:02 Revo Uninstaller's restore point - PC Speed Maximizer v3.2 22-04-2014 13:44:45 Revo Uninstaller's restore point - Search Protect 22-04-2014 13:49:20 Revo Uninstaller's restore point - SupTab 22-04-2014 13:50:55 Revo Uninstaller's restore point - Mysearchdial 22-04-2014 13:52:32 Revo Uninstaller's restore point - WPM17.8.0.3442 22-04-2014 13:59:32 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections 22-04-2014 14:00:35 Revo Uninstaller's restore point - Re-markit 22-04-2014 14:01:51 Revo Uninstaller's restore point - Optimizer Pro v3.2 22-04-2014 14:11:03 Revo Uninstaller's restore point - IePluginService12.27.0.3326 22-04-2014 14:14:36 Revo Uninstaller's restore point - media enhance 22-04-2014 14:20:06 Revo Uninstaller's restore point - VO Package 22-04-2014 14:27:49 Wiederherstellungsvorgang 22-04-2014 14:37:37 Revo Uninstaller's restore point - HQTotalS 22-04-2014 21:08:31 Revo Uninstaller's restore point - AppCloudUpdater 23-04-2014 08:53:27 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05490B50-D0A0-4A3C-A560-6ACF63DE1E42} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd) Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - \APSnotifierPP2 No Task File <==== ATTENTION Task: {0B4E379A-4C4A-428E-9BCF-A1135BBA3E4A} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2012-09-27] () Task: {1CCE7D51-38D1-4F66-B7AC-A43176E2120F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-09-30] (ASUSTeK Computer Inc.) Task: {3E2E8B1F-6878-402A-87AB-F2EF5FEBADCE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.) Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - \APSnotifierPP1 No Task File <==== ATTENTION Task: {4C14D4FC-EFFF-4FC1-BA61-EEFA91392794} - System32\Tasks\USBChargerPlus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2011-09-20] (ASUSTek Computer Inc.) Task: {5CDD33CE-1114-4D15-A601-881F87353200} - System32\Tasks\AppSafe => C:\Program Files (x86)\AppSafe\AppSafe.exe Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - \Advanced System Protector_startup No Task File <==== ATTENTION Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - \MySearchDial No Task File <==== ATTENTION Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - \RegClean Pro No Task File <==== ATTENTION Task: {8FFE3A4C-B16E-4461-A1BC-27379739F580} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22] (ASUS) Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - \APSnotifierPP3 No Task File <==== ATTENTION Task: {AF490895-86A7-4FE9-9CC6-9EC88297132C} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-11-22] (ASUS) Task: {C410E796-D92D-4AEB-A596-89D282D0DBF8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.) Task: {EAD7D671-DBE5-4388-994E-8F508652131C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS) Task: {EB32D426-01C9-4433-875C-580B292A89F0} - \SaveSense No Task File <==== ATTENTION Task: {EDBAD762-5B95-4C13-9FA0-333BACA63683} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-23] (Adobe Systems Incorporated) Task: {F9C0DFA3-7859-4C70-A44F-5E77F9E82EA7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {FE3FBFF8-BA1D-4554-A7AA-BA0DCD11606F} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AppSafe.job => C:\Program Files (x86)\AppSafe\AppSafe.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2009-03-02 04:08 - 2009-03-02 04:08 - 00003584 _____ () C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\LogicNP.PropSheetExtensionHelper_x64.dll 2011-10-13 08:19 - 2011-07-21 12:59 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll 2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2011-09-30 02:06 - 2011-09-30 02:06 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll 2011-11-22 16:09 - 2011-11-22 16:09 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll 2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll 2011-09-13 22:33 - 2011-09-13 22:33 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:AD022376 ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" ==================== Faulty Device Manager Devices ============= Name: Teredo Tunneling Pseudo-Interface Description: Microsoft-Teredo-Tunneling-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (04/23/2014 03:37:43 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 03:35:06 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 03:35:02 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 03:35:02 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 03:30:56 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 03:30:50 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 03:30:50 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 03:25:09 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 03:25:04 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/23/2014 03:25:04 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. System errors: ============= Error: (04/23/2014 05:45:01 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "ANGELIKA-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{82D77809-3722-435C-8930-AADF27772196}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (04/23/2014 04:33:57 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "ANGELIKA-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{82D77809-3722-435C-8930-AADF27772196}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (04/23/2014 11:02:28 AM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/23/2014 10:53:04 AM) (Source: Schannel) (User: NT-AUTORITÄT) Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252. Error: (04/23/2014 09:43:04 AM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "ANGELIKA-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{82D77809-3722-435C-8930-AADF27772196}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (04/23/2014 09:24:13 AM) (Source: ACPI) (User: ) Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft. Error: (04/23/2014 07:36:58 AM) (Source: DCOM) (User: ) Description: {995C996E-D918-4A8C-A302-45719A6F4EA7} Microsoft Office Sessions: ========================= Error: (04/23/2014 03:37:43 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe Error: (04/23/2014 03:35:06 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe Error: (04/23/2014 03:35:02 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe Error: (04/23/2014 03:35:02 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe Error: (04/23/2014 03:30:56 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe Error: (04/23/2014 03:30:50 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe Error: (04/23/2014 03:30:50 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe Error: (04/23/2014 03:25:09 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe Error: (04/23/2014 03:25:04 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe Error: (04/23/2014 03:25:04 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe ==================== Memory info =========================== Percentage of memory in use: 31% Total physical RAM: 6048.05 MB Available physical RAM: 4151.73 MB Total Pagefile: 12094.28 MB Available Pagefile: 9947.68 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:195.35 GB) (Free:129.91 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Data) (Fixed) (Total:245.41 GB) (Free:210.98 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 496B9619) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=195 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=245 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Weiterhin werden mir im Revo Uninstaller und auch in der Systemsteuerung nicht mehr alle installierten Programme angezeigt. Dies ist bei der Deinstallation des VO Package passiert!! Hast Du dafür ne Lösung??
__________________ --> Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Geändert von caiphi (23.04.2014 um 17:49 Uhr) Grund: Ergänzung FRST Logs |
24.04.2014, 08:25 | #7 |
| Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Hab den Eset Scan wiederholt und das Logfile beigefügt... Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=bbb357d2aacdc443828761659e627366 # engine=18006 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-24 07:14:41 # local_time=2014-04-24 09:14:41 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 100 94 5012213 149953531 0 0 # scanned=162048 # found=0 # cleaned=0 # scan_time=4916
__________________ Gruß Volker |
24.04.2014, 19:48 | #8 |
/// the machine /// TB-Ausbilder | Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Reicht mir Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - \APSnotifierPP2 No Task File <==== ATTENTION Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - \APSnotifierPP1 No Task File <==== ATTENTION Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - \Advanced System Protector_startup No Task File <==== ATTENTION Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - \MySearchDial No Task File <==== ATTENTION Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - \RegClean Pro No Task File <==== ATTENTION Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - \APSnotifierPP3 No Task File <==== ATTENTION Task: {EB32D426-01C9-4433-875C-580B292A89F0} - \SaveSense No Task File <==== ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
25.04.2014, 09:19 | #9 |
| Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Hallo Schrauber, habe den FRST laufen lassen: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-04-2014 Ran by Stefanie Regener at 2014-04-24 23:24:38 Run:1 Running from C:\Users\Stefanie Regener\Desktop\log Dateien Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - \APSnotifierPP2 No Task File <==== ATTENTION Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - \APSnotifierPP1 No Task File <==== ATTENTION Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - \Advanced System Protector_startup No Task File <==== ATTENTION Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - \MySearchDial No Task File <==== ATTENTION Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - \RegClean Pro No Task File <==== ATTENTION Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - \APSnotifierPP3 No Task File <==== ATTENTION Task: {EB32D426-01C9-4433-875C-580B292A89F0} - \SaveSense No Task File <==== ATTENTION ***************** C:\Windows\system32\GroupPolicy\Machine => Moved successfully. C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06A4AD28-DDF9-47AA-BB59-AD0885D3F010} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06A4AD28-DDF9-47AA-BB59-AD0885D3F010} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E4D962A-67BC-47D3-9033-FD169C1B86FB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E4D962A-67BC-47D3-9033-FD169C1B86FB} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{79A29FDB-3782-4B22-90CC-59A2098B7214} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79A29FDB-3782-4B22-90CC-59A2098B7214} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advanced System Protector_startup => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7D7887FB-D125-4066-9E7A-3A47325E9106} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D7887FB-D125-4066-9E7A-3A47325E9106} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySearchDial => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3 => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB32D426-01C9-4433-875C-580B292A89F0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB32D426-01C9-4433-875C-580B292A89F0} => Key deleted successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSense => Key deleted successfully. The system needed a reboot. ==== End of Fixlog ==== Kannst Du noch was zum Revo Uninstaller sagen (s.o) Melde mich nach der abschließenden Bereinigung nochmal!! Hallo Schrauber, ich habe jetzt alle Anweisung befolgt. Ich denke der Rechner ist wieder sauber. Die von Dir gegebenen Empfehlungen habe ich an den Benutzer des Laptops weitergegeben. Den defekten Revo Uninstaller, der nur noch 4 Programme anzeigte, obwohl ca. 60 vorhanden sind, habe ich zweimal neu installiert, was nichts geändert hat, also habe ich ihn deinstalliert gelassen. Du hast für dieses Problem auch keine Erklärung oder Lösung?? Die Programme sind mit der Deinstallation vom VO Package verschwunden, egal ob ich es mit dem Uninstaller oder mit der Systemsteuerung deinstalliert habe. Falls Du für dieses Problem keine Idee hast, ist der Fall damit abgeschlossen und ich (und meine Tochter) sind Dir sehr dankbar für die kompetente und schnelle Hilfe. Euer Trojaner Board ist eine ausgezeichnete Einrichtung und ich habe Hochachtung vor Eurem Tun, Eurer Begeisterung und Euren Fähigkeiten sowie auch der Konsequenz, mit denen ihr auf selbstverschuldetes Leid (crackz, illegale Software etc.) reagiert. Vielen , vielen Dank!!
__________________ Gruß Volker |
25.04.2014, 19:11 | #10 |
/// the machine /// TB-Ausbilder | Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Sind die Programme nur in der Liste von Revo weg oder auch in der Windows Ansicht der installierten Programme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.04.2014, 19:39 | #11 |
| Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Hallo Schrauber, danke , dass Du Dich noch mal meldest;-)) Im CCleaner sind alle Programme angezeigt, im Systemordner ca 3/4 aller Programme und im Revo nur 4 Programme...Direkt nach der Deinstallation sind alle Programme bis auf zwei verschwunden. Alles was danach installiert wurde erschien auch im Revo! Bisher habe ich nur ein unwichtiges Programm von Aus entdeckt was auch nicht funktioniert. Alles andere incl. MS Office funktioniert. Hast Du ne Idee??
__________________ Gruß Volker |
27.04.2014, 18:16 | #12 |
/// the machine /// TB-Ausbilder | Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Ja, die Adware VO Package hat die Uninstall Liste zerschossen. Da haben mitlerweile mehr Leute das Problem, wir wussten nur nie welche Adware es genau ist. Jetz weiß ich es und kann versuchen das zu beheben. Im Moment ist es nur leider so das wir das nicht mehr ändern können, aber der CCleaner zeigt ja alle an. Also nur Kosmetik.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
29.04.2014, 23:34 | #13 |
| Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Dann lass ich den Revo deinstalliert. Danke für Deine kompetente Hilfe. Gute Arbeit!! ...und sehr nett!!
__________________ Gruß Volker |
01.05.2014, 00:09 | #14 |
/// the machine /// TB-Ausbilder | Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |