|
Plagegeister aller Art und deren Bekämpfung: Windows 7 Rechner wird immer langsamer Malware gefundenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
16.10.2014, 14:20 | #1 |
| Windows 7 Rechner wird immer langsamer Malware gefunden Hallo, ich habe den Rechner eines Freundes zur Überprüfung bekommen. Er sagt sein Rechner sei immer langsamer geworden und es würden sich immer mal irgendwelche Fenster öffnen (kann nicht nachvollziehen was sich da genau geöffnet hat). Ich habe spybot drüber laufen lassen und das Programm hat Malwware gefunden (win.32agent.exq, win32.downloader.gen, dealply). Ich habe diese Malware erstmal drauf gelassen und mich sofort an das Forum hier gewendet. Da ihr mir vor einiger Zeit auch bei meinem Rechnerproblem geholfen habt wende ich mich nun wieder an euch. Bitte um Hilfe. Auf dem Rechner läuft Windows 7 und als Virenwächter ist MS Security Essential installiert. Mfg Coldmorning |
16.10.2014, 14:25 | #2 |
/// the machine /// TB-Ausbilder | Windows 7 Rechner wird immer langsamer Malware gefunden hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
16.10.2014, 16:20 | #3 |
| Windows 7 Rechner wird immer langsamer Malware gefunden vergess den oberen Post habe nicht daran gedacht FRST auf dem Desktop zu starten. Sorry war mein Fehler...
__________________Hier die Logfiles: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-10-2014 02 Ran by Wurzbacher (administrator) on WURZBACHER-HP on 16-10-2014 17:17:25 Running from C:\Users\Wurzbacher\Desktop Loaded Profile: Wurzbacher (Available profiles: Wurzbacher) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (AMD) C:\Windows\System32\atieclxx.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\ndp45-kb2979578-v2-x64.exe (Microsoft Corporation) C:\076d49e37a1731abc51ef97ade3436be\Setup.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2011-06-10] (Synaptics Incorporated) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-09-15] (EasyBits Software AS) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1238016 2013-07-26] (Easybits) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-10-07] (Hewlett-Packard) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 BootExecute: autocheck autochk * sdnclean64.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=ds&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518&type=default&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518 HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=ds&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518&type=default&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=ds&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518&type=default&q={searchTerms} HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=ds&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518&type=default&q={searchTerms} URLSearchHook: HKLM-x32 - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.) URLSearchHook: HKCU - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=sc&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518 SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=ds&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518&type=default&q={searchTerms} SearchScopes: HKLM - {88AEA96D-C839-4D40-9888-4DC0F37C806E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms} SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=ds&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518&type=default&q={searchTerms} SearchScopes: HKLM-x32 - {88AEA96D-C839-4D40-9888-4DC0F37C806E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF SearchScopes: HKLM-x32 - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms} SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3317742&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP3CD6016B-6C2D-4D3F-A933-7579D01B4804&q={searchTerms}&SSPV= SearchScopes: HKCU - {055CBFF5-162B-45DF-946A-E25BBC6CD6EC} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2625848 SearchScopes: HKCU - {1D4E1D3B-7DCB-424A-BB4B-C3E4A43CD2F9} URL = hxxp://search.softonic.com/MOY00009/tb_v1?q={searchTerms}&SearchSource=4&cc=&mi=a01584b1000000000000ccaf78484120&toi=16046&r=14 SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=HPNTDF SearchScopes: HKCU - {31FF37DB-2240-4989-89DF-E2A27A791BAD} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10261&src=kw&q={searchTerms}&locale=de_DE&apn_ptnrs=^AGS&apn_dtid=^YYYYYY^YY^DE&apn_uid=db38021d-3228-4af2-b19e-5e4dceced4f1&apn_sauid=7D851231-A474-45E0-9ECB-20E00174D333 SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKCU - {88AEA96D-C839-4D40-9888-4DC0F37C806E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = SearchScopes: HKCU - {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = hxxp://de.wikipedia.org/wiki/Special:Search?search={searchTerms} SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms} BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: DVDVideoSoftTB DE Toolbar -> {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} -> C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.) BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM-x32 - DVDVideoSoftTB DE Toolbar - {0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff} - C:\Program Files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll (Conduit Ltd.) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-11-04] (EasyBits Software Corp.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WEB.DE MailCheck - C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\Extensions\toolbar@web.de [2014-09-18] FF Extension: No Name - C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\Extensions\trash [2014-09-23] FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com [2014-10-16] Chrome: ======= CHR DefaultSearchKeyword: Default -> conduit.search CHR DefaultSearchURL: Default -> hxxp://search.conduit.com/Results.aspx?ctid=CT3317742&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP3CD6016B-6C2D-4D3F-A933-7579D01B4804&q={searchTerms}&SSPV= CHR DefaultSuggestURL: Default -> hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} CHR Profile: C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-15] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-03] CHR Extension: (Website Logon) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfmogjcijkfeahcajecmmegieipfbdcc [2012-09-17] CHR Extension: (Lightning Newtab) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo [2013-11-10] CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2012-12-22] CHR Extension: (Google Wallet) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31] CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2012-12-22] CHR HKLM-x32\...\Chrome\Extension: [bfmogjcijkfeahcajecmmegieipfbdcc] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-08-18] CHR HKLM-x32\...\Chrome\Extension: [ifohbjbgfchkkfhphahclmkpgejiplfo] - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx [2013-11-10] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed] S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-05-24] (WildTangent) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed] R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20552 2010-07-30] (Devguru Co., Ltd) S3 dgderdrv; C:\Windows\SysWOW64\drivers\dgderdrv.sys [18120 2010-07-30] (Devguru Co., Ltd) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203104 2012-09-19] (DEVGURU Co., LTD.(www.devguru.co.kr)) R3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-16 17:17 - 2014-10-16 17:18 - 00023773 _____ () C:\Users\Wurzbacher\Desktop\FRST.txt 2014-10-16 17:17 - 2014-10-16 17:17 - 00000000 ____D () C:\076d49e37a1731abc51ef97ade3436be 2014-10-16 17:16 - 2014-10-16 17:17 - 02111488 _____ (Farbar) C:\Users\Wurzbacher\Desktop\FRST64.exe 2014-10-16 15:56 - 2014-10-16 15:57 - 00033995 _____ () C:\Users\Wurzbacher\Downloads\Addition.txt 2014-10-16 15:55 - 2014-10-16 17:17 - 00000000 ____D () C:\FRST 2014-10-16 15:55 - 2014-10-16 15:57 - 00031556 _____ () C:\Users\Wurzbacher\Downloads\FRST.txt 2014-10-16 15:54 - 2014-10-16 15:54 - 02111488 _____ (Farbar) C:\Users\Wurzbacher\Downloads\FRST64.exe 2014-10-16 15:50 - 2014-10-16 15:50 - 00001009 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Netzmanager.lnk 2014-10-16 15:50 - 2014-10-16 15:50 - 00001003 _____ () C:\Users\Public\Desktop\Netzmanager.lnk 2014-10-16 15:50 - 2014-10-16 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Netzmanager 2014-10-16 15:50 - 2014-10-16 15:50 - 00000000 ____D () C:\Program Files\Netzmanager 2014-10-16 15:49 - 2014-10-16 15:50 - 00000000 __HDC () C:\ProgramData\{BA58D0EE-89D1-4191-9F19-B6AD920B04F7} 2014-10-16 15:49 - 2014-09-13 03:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 15:49 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-10-16 15:12 - 2014-10-16 15:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-16 14:56 - 2014-10-16 14:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-16 14:56 - 2014-09-26 18:42 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-16 14:56 - 2014-09-26 18:36 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-10-16 14:56 - 2014-09-26 18:36 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-10-16 14:56 - 2014-09-26 18:35 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-10-16 14:55 - 2014-10-16 14:56 - 00004930 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_71-b14.log 2014-10-05 14:20 - 2014-10-05 14:20 - 00002343 _____ () C:\Users\Public\Desktop\English G 21 e-Workbook D1.lnk 2014-10-05 14:20 - 2014-10-05 14:20 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Roaming\Cornelsen 2014-10-05 14:20 - 2014-10-05 14:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cornelsen 2014-10-05 14:20 - 2014-10-05 14:20 - 00000000 ____D () C:\Program Files (x86)\Cornelsen 2014-10-01 16:37 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-10-01 16:37 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-09-24 05:14 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-09-24 05:14 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-09-23 20:36 - 2014-09-23 20:36 - 01032856 _____ () C:\Users\Wurzbacher\Downloads\WhatsApp-Plus---Die-beste-Alternative-zu-WhatsApp-lnstall.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-16 17:17 - 2013-12-21 16:12 - 00001118 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-16 17:17 - 2011-12-12 02:34 - 01620903 _____ () C:\Windows\WindowsUpdate.log 2014-10-16 17:15 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-16 17:15 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-16 17:13 - 2013-08-25 10:52 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-16 17:01 - 2012-10-19 12:32 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-10-16 16:34 - 2013-12-21 18:35 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-16 16:17 - 2013-12-21 16:12 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-16 15:50 - 2013-01-16 19:05 - 00000000 ____D () C:\ProgramData\Netzmanager 2014-10-16 15:49 - 2013-01-16 19:05 - 00000000 __HDC () C:\ProgramData\{87B61FE8-334F-4066-B7AA-68DC81782D4D} 2014-10-16 15:38 - 2012-07-26 20:25 - 00003970 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{AFFA8D60-5546-4ABA-A6F7-88FAD6D8F781} 2014-10-16 15:35 - 2014-09-15 05:01 - 00003315 _____ () C:\Windows\setupact.log 2014-10-16 15:35 - 2013-12-21 18:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-16 15:35 - 2010-11-21 05:47 - 00830050 _____ () C:\Windows\PFRO.log 2014-10-16 15:35 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-16 15:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-10-16 15:07 - 2014-08-16 10:19 - 00000000 ____D () C:\Users\Wurzbacher\Documents\Fotobuch Kroatien-Dateien 2014-10-16 15:04 - 2013-03-15 20:05 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-10-16 15:01 - 2012-07-28 18:07 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-10-16 15:00 - 2012-07-29 13:46 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Local\Adobe 2014-10-16 15:00 - 2012-07-26 18:56 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Roaming\Hewlett-Packard 2014-10-16 15:00 - 2011-12-12 02:36 - 00000000 ____D () C:\Windows\Hewlett-Packard 2014-10-16 15:00 - 2011-02-10 21:23 - 00000000 ____D () C:\SWSetup 2014-10-16 14:59 - 2013-12-21 18:35 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-10-16 14:59 - 2013-12-21 18:35 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-10-16 14:59 - 2013-12-21 18:35 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-10-16 14:56 - 2013-12-31 09:41 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-16 14:56 - 2013-03-15 20:28 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-16 14:52 - 2011-11-04 21:53 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-10-16 14:52 - 2011-11-04 21:53 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-10-16 14:52 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-10-15 05:34 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-10-14 08:27 - 2013-01-13 12:20 - 00003216 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForWurzbacher 2014-10-14 08:27 - 2013-01-13 12:20 - 00000352 _____ () C:\Windows\Tasks\HPCeeScheduleForWurzbacher.job 2014-10-11 17:14 - 2013-03-20 12:36 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-09-29 15:33 - 2012-07-26 15:42 - 00000000 ____D () C:\Users\Wurzbacher 2014-09-25 05:40 - 2013-12-21 16:12 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-09-24 19:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-09-23 21:06 - 2013-11-07 22:23 - 00000000 ____D () C:\Users\Wurzbacher\Documents\Klapp-Kalender-Dateien 2014-09-23 21:06 - 2013-09-04 21:41 - 00000000 ____D () C:\Users\Wurzbacher\Documents\Fotobuch 2-Dateien 2014-09-22 08:42 - 2010-11-21 05:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-09-19 05:10 - 2013-03-29 09:49 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk Some content of TEMP: ==================== C:\Users\Wurzbacher\AppData\Local\Temp\Extract.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-06 11:51 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-10-2014 02 Ran by Wurzbacher at 2014-10-16 17:18:29 Running from C:\Users\Wurzbacher\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} AS: Microsoft Security Essentials (Enabled - Up to date) {F4542E20-6399-F3B9-D5A7-4EE87964D00C} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH) Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated) Adobe Reader XI (11.0.09) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.09 - Adobe Systems Incorporated) Adobe Shockwave Player 11.6 (HKLM-x32\...\Adobe Shockwave Player) (Version: 11.6.1.629 - Adobe Systems, Inc.) AMD APP SDK Runtime (Version: 2.5.709.2 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (HKLM\...\{70F55D70-7E5F-6291-4924-2F7640F19BFE}) (Version: 3.0.838.0 - Advanced Micro Devices, Inc.) AuthenTec TrueAPI (Version: 1.3.0.139 - AuthenTec, Inc.) Hidden Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden Cake Mania (x32 Version: 2.2.0.98 - WildTangent) Hidden Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center (x32 Version: 2011.0817.2216.38121 - Ihr Firmenname) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2011.0817.2216.38121 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2011.0817.2216.38121 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2011.0817.2216.38121 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Profiles Mobile (x32 Version: 2011.0817.2216.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2011.0817.2215.38121 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2011.0817.2216.38121 - Advanced Micro Devices, Inc.) Hidden Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.0.4528 - CyberLink Corp.) CyberLink YouCam (x32 Version: 3.5.0.4528 - CyberLink Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DVDVideoSoftTB DE Toolbar (HKLM-x32\...\DVDVideoSoftTB_DE Toolbar) (Version: 6.9.0.16 - DVDVideoSoftTB DE) English G 21 e-Workbook D1 (HKLM-x32\...\{647491AE-39FF-4475-8FD1-543483B9B237}) (Version: 1.01.0000 - Cornelsen Verlag GmbH) ESU for Microsoft Windows 7 SP1 (HKLM-x32\...\{E96CAA2A-0244-4A2A-8403-0C3C9534778B}) (Version: 2.1.1 - Hewlett-Packard) Evernote v. 4.2.3 (HKLM-x32\...\{F761359C-9CED-45AE-9A51-9D6605CD55C4}) (Version: 4.2.3.22 - Evernote Corp.) Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden Farmscapes (x32 Version: 2.2.0.98 - WildTangent) Hidden FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden Final Drive Fury (x32 Version: 2.2.0.95 - WildTangent) Hidden Fishdom (TM) 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden Free YouTube to MP3 Converter version 3.11.37.1212 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.11.37.1212 - DVDVideoSoft Ltd.) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 37.0.2062.124 - Google Inc.) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden HP Auto (Version: 1.0.12935.3667 - Hewlett-Packard Company) Hidden HP Client Services (Version: 1.1.12938.3539 - Hewlett-Packard) Hidden HP Customer Experience Enhancements (x32 Version: 6.0.1.8 - Hewlett-Packard) Hidden HP Documentation (HKLM-x32\...\{BC6CB499-9F29-4B41-8B8B-FA7248525256}) (Version: 1.1.0.0 - Hewlett-Packard) HP Games (HKLM-x32\...\WildTangent hp Master Uninstall) (Version: 1.0.2.5 - WildTangent) HP Launch Box (HKLM\...\{BF1E75D0-E7AF-4BEA-9FBC-567F0C54BDF9}) (Version: 1.0.12 - Hewlett-Packard Company) HP On Screen Display (HKLM-x32\...\{ED1BD69A-07E3-418C-91F1-D856582581BF}) (Version: 1.3.5 - Hewlett-Packard Company) HP Power Manager (HKLM-x32\...\{E44578C7-4667-4124-8BC2-1161BCA54978}) (Version: 1.4.4 - Hewlett-Packard Company) HP Quick Launch (HKLM-x32\...\{53B17A98-5BF0-40BC-AAFF-850A357975AC}) (Version: 2.7.2 - Hewlett-Packard Company) HP QuickWeb (HKLM-x32\...\{BB4FC2AD-DF12-4EE1-8AA7-2C0A26B5E2FB}) (Version: 3.1.1.10197 - Hewlett-Packard Company) HP Recovery Manager (x32 Version: 2.0.0 - Hewlett-Packard) Hidden HP Security Assistant (HKLM\...\{562608FE-2051-4488-BF22-8CE4C03046AC}) (Version: 1.0.12 - Hewlett-Packard) HP Setup (HKLM-x32\...\{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}) (Version: 9.0.15076.3891 - Hewlett-Packard Company) HP Setup Manager (HKLM-x32\...\{AE856388-AFAD-4753-81DF-D96B19D0A17C}) (Version: 1.2.14901.3869 - Hewlett-Packard Company) HP SimplePass PE 2011 (HKLM-x32\...\{4741965C-AFD0-4D00-81D1-1039F96D4DC3}) (Version: 5.3.0.264 - Hewlett-Packard) HP Software Framework (HKLM-x32\...\{D2462056-BA75-4B2C-8267-DFEA2B6AC4AE}) (Version: 4.6.10.1 - Hewlett-Packard Company) HP Support Assistant (HKLM-x32\...\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}) (Version: 7.4.45.4 - Hewlett-Packard Company) IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6365.0 - IDT) Insaniquarium Deluxe (x32 Version: 2.2.0.97 - WildTangent) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation) Intel(R) Identity Protection Technology 1.1.2.0 (HKLM-x32\...\{C01A86F5-56E7-101F-9BC9-E3F1025EB779}) (Version: 1.1.2.0 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.5.0.1026 - Intel Corporation) Java 7 Update 71 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.710 - Oracle) Java Auto Updater (x32 Version: 2.1.71.14 - Oracle, Inc.) Hidden Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden Jewel Quest II (x32 Version: 2.2.0.97 - WildTangent) Hidden Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Kies (HKLM-x32\...\InstallShield_{D6CD26FD-CD7F-4C86-96A3-EEBFABE5FE47}) (Version: 1.5.3 - Ihr Firmenname) Kies (x32 Version: 1.5.3 - Ihr Firmenname) Hidden Lidl-Fotos (HKLM-x32\...\Lidl-Fotos_is1) (Version: - ) Magic Desktop (HKLM-x32\...\EasyBits Magic Desktop) (Version: 3.0 - EasyBits Software AS) Mahjongg Artifacts (x32 Version: 2.2.0.95 - WildTangent) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Security Client (Version: 4.6.0305.0 - Microsoft Corporation) Hidden Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.6.305.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Mozilla Firefox 33.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0 (x86 de)) (Version: 33.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden Netzmanager (HKLM-x32\...\Netzmanager) (Version: 1.081 - Deutsche Telekom AG) Netzmanager (Version: 1.081 - Deutsche Telekom AG, Marmiko IT-Solutions GmbH) Hidden opensource (x32 Version: 1.0.14960.3876 - Your Company Name) Hidden Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden PX Profile Update (x32 Version: 1.00.1. - AMD) Hidden Ralink RT5390 802.11b/g/n WiFi Adapter (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 3.2.13.0 - Ralink) Ranch Rush 2 - Premium Edition (x32 Version: 2.2.0.98 - WildTangent) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek) Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.85 - Realtek Semiconductor Corp.) SAMSUNG USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.3.1400.0 - SAMSUNG Electronics Co., Ltd.) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.0.12 - Safer-Networking Ltd.) SteuerSparErklärung 2014 (HKLM-x32\...\{A463EB06-22A6-47F5-9593-E52B291EF13E}) (Version: 19.09.86 - Akademische Arbeitsgemeinschaft) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden Synaptics TouchPad Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.11.0 - Synaptics Incorporated) Torchlight (x32 Version: 2.2.0.98 - WildTangent) Hidden Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden Virtual Families (x32 Version: 2.2.0.98 - WildTangent) Hidden Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden Wedding Dash (x32 Version: 2.2.0.95 - WildTangent) Hidden WildTangent Games App für HP (x32 Version: 4.0.11.2 - WildTangent) Hidden Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Wise Registry Cleaner 7.66 (HKLM-x32\...\Wise Registry Cleaner_is1) (Version: - WiseCleaner.com, Inc.) Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 28-09-2014 06:53:19 Windows Update 01-10-2014 15:00:13 Windows Update 05-10-2014 05:44:44 Windows Update 05-10-2014 12:13:05 English G 21 e-Workbook D1 wurde installiert. 09-10-2014 20:18:08 Windows Update 13-10-2014 04:55:44 Windows Update 16-10-2014 12:48:02 Windows Update 16-10-2014 12:54:24 HPSF Applying updates 16-10-2014 12:55:04 Installed Java 7 Update 71 16-10-2014 13:00:21 HPSF Applying updates 16-10-2014 13:33:04 Windows Modules Installer 16-10-2014 15:00:23 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {05976E8C-4AEE-4610-BAAF-CD1E03137CCE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-21] (Google Inc.) Task: {091A80CD-4FAE-4813-B846-EBF345AA8668} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {28F9C140-FCC0-46E7-9370-8794EC30626A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {39DCEF19-8D78-4194-94B4-E9E35C3BF050} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company) Task: {48D768F3-7302-4041-8FE6-FCC7D1F383CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-21] (Google Inc.) Task: {534E0C83-AF82-47AE-8678-4D5512D46420} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-16] (Adobe Systems Incorporated) Task: {77C18D28-2EF1-4F18-82D9-78A9AA153BF4} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2011-09-28] (CyberLink) Task: {7D95CCED-8CCC-4E1F-B677-A1172417F3AA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: {A335A00C-C237-494B-A247-08448D0214EB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2014-09-22] (Hewlett-Packard) Task: {D36E55F1-C478-400C-87E9-0192AFDCF256} - System32\Tasks\HPCeeScheduleForWurzbacher => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15] (Hewlett-Packard) Task: {D702D4EA-09C3-4409-AA2C-1EA76AD4F3C8} - System32\Tasks\Dealply => C:\Users\WURZBA~1\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: {D982EA48-8C0F-4F40-8EDF-05C066D9B6B2} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2013-11-04] (Hewlett-Packard Company) Task: {E2D69B38-CC62-4C76-B9C0-2B7973D5221B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\Dealply.job => C:\Users\WURZBA~1\AppData\Roaming\Dealply\UPDATE~1\UPDATE~1.EXE <==== ATTENTION Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\HPCeeScheduleForWurzbacher.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe ==================== Loaded Modules (whitelisted) ============= 2008-10-24 17:35 - 2008-10-24 17:35 - 00128296 _____ () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe 2011-08-09 17:44 - 2011-08-09 17:44 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2013-03-15 20:05 - 2012-11-13 15:06 - 00108960 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-03-15 20:05 - 2012-11-13 15:06 - 00416160 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-03-15 20:05 - 2012-11-13 15:06 - 00158624 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-03-15 20:05 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-03-15 20:05 - 2012-11-13 15:06 - 00528288 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl 2013-03-15 20:05 - 2012-11-13 15:06 - 00554400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl 2014-09-11 05:32 - 2014-09-11 05:32 - 00172544 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\f34f9ebcfd653494c2b22c4457aff1d9\IsdiInterop.ni.dll 2011-12-12 02:34 - 2011-04-30 01:28 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2014-10-16 15:12 - 2014-10-16 15:12 - 03649648 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) MSCONFIG\startupfolder: C:^Users^Wurzbacher^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Netzmanager.lnk => C:\Windows\pss\Netzmanager.lnk.Startup MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: ApnUpdater => "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" MSCONFIG\startupreg: GoogleChromeAutoLaunch_EC4E7ED9A2326ABB85C0EB16A641017B => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window MSCONFIG\startupreg: HP Quick Launch => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe MSCONFIG\startupreg: HPOSD => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe MSCONFIG\startupreg: HPQuickWebProxy => "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" MSCONFIG\startupreg: KiesTrayAgent => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe MSCONFIG\startupreg: SetDefault => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun MSCONFIG\startupreg: SysTrayApp => C:\Program Files\IDT\WDM\sttray64.exe ========================= Accounts: ========================== Administrator (S-1-5-21-1447600568-1936789412-2989334194-500 - Administrator - Disabled) Gast (S-1-5-21-1447600568-1936789412-2989334194-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-1447600568-1936789412-2989334194-1002 - Limited - Enabled) Wurzbacher (S-1-5-21-1447600568-1936789412-2989334194-1000 - Administrator - Enabled) => C:\Users\Wurzbacher ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (10/16/2014 04:08:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm Explorer.EXE, Version 6.1.7601.17567 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: d44 Startzeit: 01cfe946331e1384 Endzeit: 15 Anwendungspfad: C:\Windows\Explorer.EXE Berichts-ID: e43f54c1-553d-11e4-89e4-ec9a745ccd40 Error: (10/16/2014 03:35:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/16/2014 02:44:54 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/15/2014 05:35:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/15/2014 05:34:22 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/14/2014 08:41:45 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/12/2014 08:51:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/12/2014 06:39:23 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/11/2014 08:58:01 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/11/2014 00:17:16 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (10/12/2014 08:04:14 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (10/09/2014 10:06:20 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst HPWMISVC erreicht. Error: (10/07/2014 01:07:48 PM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst HPWMISVC erreicht. Error: (10/07/2014 00:44:38 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: Der Dienst Windows Update konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden. Error: (10/05/2014 11:19:18 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (10/05/2014 08:23:29 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (10/03/2014 08:00:34 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst HPWMISVC erreicht. Error: (10/01/2014 08:25:25 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (09/28/2014 08:37:19 AM) (Source: Service Control Manager) (EventID: 7011) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst HPWMISVC erreicht. Error: (09/21/2014 03:26:52 PM) (Source: DCOM) (EventID: 10010) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Microsoft Office Sessions: ========================= Error: (10/16/2014 04:08:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Explorer.EXE6.1.7601.17567d4401cfe946331e138415C:\Windows\Explorer.EXEe43f54c1-553d-11e4-89e4-ec9a745ccd40 Error: (10/16/2014 03:35:58 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/16/2014 02:44:54 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/15/2014 05:35:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/15/2014 05:34:22 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/14/2014 08:41:45 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/12/2014 08:51:11 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/12/2014 06:39:23 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/11/2014 08:58:01 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (10/11/2014 00:17:16 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz Percentage of memory in use: 47% Total physical RAM: 6091.86 MB Available physical RAM: 3207.41 MB Total Pagefile: 12181.9 MB Available Pagefile: 9225.63 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:440.99 GB) (Free:375.71 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (Recovery) (Fixed) (Total:20.61 GB) (Free:2.2 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive e: (HP_TOOLS) (Fixed) (Total:3.96 GB) (Free:1.08 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 257422C2) Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=441 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=20.6 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=4 GB) - (Type=0C) ==================== End Of Log ============================ |
17.10.2014, 08:27 | #4 |
/// the machine /// TB-Ausbilder | Windows 7 Rechner wird immer langsamer Malware gefunden hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.10.2014, 13:54 | #5 |
| Windows 7 Rechner wird immer langsamer Malware gefunden Hallo, hier die Combofix Logfile. Habe den Virenwächter und Spybot deaktiviert. Bei Spybot habe ich die Prozesse gekillt um das Programm zu beenden. Mfg Code:
ATTFilter ComboFix 14-10-15.01 - Wurzbacher 17.10.2014 14:41:03.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.6092.3800 [GMT 2:00] ausgeführt von:: c:\users\Wurzbacher\Desktop\ComboFix.exe AV: Microsoft Security Essentials *Disabled/Updated* {4F35CFC4-45A3-FC37-EF17-759A02E39AB1} SP: Microsoft Security Essentials *Disabled/Updated* {F4542E20-6399-F3B9-D5A7-4EE87964D00C} SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\Install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-09-17 bis 2014-10-17 )))))))))))))))))))))))))))))) . . 2014-10-17 12:48 . 2014-10-17 12:48 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-10-17 12:35 . 2014-10-17 12:35 75888 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9AA6C04C-8419-436B-ADE1-382D8D27D55E}\offreg.dll 2014-10-16 15:45 . 2014-07-07 02:06 842240 ----a-w- c:\windows\system32\blackbox.dll 2014-10-16 15:45 . 2014-07-07 01:40 744960 ----a-w- c:\windows\SysWow64\blackbox.dll 2014-10-16 15:45 . 2014-07-07 02:06 1202176 ----a-w- c:\windows\system32\drmv2clt.dll 2014-10-16 15:45 . 2014-07-07 01:40 988160 ----a-w- c:\windows\SysWow64\drmv2clt.dll 2014-10-16 15:45 . 2014-07-07 02:07 14632960 ----a-w- c:\windows\system32\wmp.dll 2014-10-16 15:45 . 2014-07-07 02:06 4120576 ----a-w- c:\windows\system32\mf.dll 2014-10-16 15:45 . 2014-07-07 02:07 782848 ----a-w- c:\windows\system32\wmdrmsdk.dll 2014-10-16 13:55 . 2014-10-16 16:04 -------- d-----w- C:\FRST 2014-10-16 13:51 . 2014-09-29 00:58 3198976 ----a-w- c:\windows\system32\win32k.sys 2014-10-16 13:49 . 2014-07-17 02:07 3722240 ----a-w- c:\windows\system32\mstscax.dll 2014-10-16 12:56 . 2014-10-16 12:56 -------- d-----w- c:\program files (x86)\Common Files\Java 2014-10-16 12:56 . 2014-09-26 16:42 98216 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2014-10-16 12:49 . 2014-09-09 02:05 11578928 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9AA6C04C-8419-436B-ADE1-382D8D27D55E}\mpengine.dll 2014-10-15 07:37 . 2014-09-09 02:05 11578928 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll 2014-10-05 12:20 . 2014-10-05 12:20 -------- d-----w- c:\users\Wurzbacher\AppData\Roaming\Cornelsen 2014-10-05 12:20 . 2014-10-05 12:20 -------- d-----w- c:\program files (x86)\Cornelsen 2014-10-01 17:21 . 2014-09-16 17:28 1188440 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9432379-90AA-4C48-94F6-103FE0B6D20B}\gapaengine.dll 2014-10-01 14:37 . 2014-09-25 02:08 371712 ----a-w- c:\windows\system32\qdvd.dll 2014-10-01 14:37 . 2014-09-25 01:40 519680 ----a-w- c:\windows\SysWow64\qdvd.dll 2014-09-24 03:14 . 2014-09-09 22:11 2048 ----a-w- c:\windows\system32\tzres.dll 2014-09-24 03:14 . 2014-09-09 21:47 2048 ----a-w- c:\windows\SysWow64\tzres.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-10-16 15:01 . 2012-10-19 10:32 103265616 ----a-w- c:\windows\system32\MRT.exe 2014-10-16 12:59 . 2013-12-21 16:35 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-10-16 12:59 . 2013-12-21 16:35 701104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-09-22 06:42 . 2010-11-21 03:27 278152 ------w- c:\windows\system32\MpSigStub.exe 2014-09-16 17:28 . 2013-03-21 16:45 1188440 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll 2014-08-29 17:29 . 2011-03-28 17:36 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2014-08-23 02:07 . 2014-08-27 17:44 404480 ----a-w- c:\windows\system32\gdi32.dll 2014-08-23 01:45 . 2014-08-27 17:44 311808 ----a-w- c:\windows\SysWow64\gdi32.dll 2014-08-01 11:53 . 2014-09-10 19:25 1031168 ----a-w- c:\windows\system32\TSWorkspace.dll 2014-08-01 11:35 . 2014-09-10 19:25 793600 ----a-w- c:\windows\SysWow64\TSWorkspace.dll 2014-07-25 00:35 . 2014-07-25 00:35 875688 ----a-w- c:\windows\SysWow64\msvcr120_clr0400.dll 2014-07-24 21:47 . 2014-07-24 21:47 869544 ----a-w- c:\windows\system32\msvcr120_clr0400.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}"= "c:\program files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}] 2011-05-09 09:49 176936 ----a-w- c:\program files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}"= "c:\program files (x86)\DVDVideoSoftTB_DE\prxtbDVDV.dll" [2011-05-09 176936] . [HKEY_CLASSES_ROOT\clsid\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-11-13 3713032] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2011-09-15 61112] "SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2012-11-13 3825176] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-08-21 959176] "HP Quick Launch"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe" [2012-03-05 578944] "Magic Desktop for HP notification"="c:\programdata\Easybits Magic Desktop for HP\mdhpSUN.exe" [2013-07-26 1238016] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2014-09-26 271744] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "HideFastUserSwitching"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys;c:\windows\SYSNATIVE\drivers\dgderdrv.sys [x] R3 GamesAppIntegrationService;GamesAppIntegrationService;c:\program files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [x] R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys;c:\windows\SYSNATIVE\DRIVERS\NisDrvWFP.sys [x] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\Microsoft Security Client\NisSrv.exe;c:\program files\Microsoft Security Client\NisSrv.exe [x] R3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS;c:\windows\SYSNATIVE\DRIVERS\VSTCNXT6.SYS [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 ssudserd;SAMSUNG Mobile USB Diagnostic Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssudserd.sys [x] R3 TelekomNM6;Telekom Netzmanager Packet Filter Driver;c:\program files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys;c:\program files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [x] R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys;c:\windows\SYSNATIVE\Drivers\TFsExDisk.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;%TsUsbGD.DeviceDesc.Generic%;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S2 AAV UpdateService;AAV UpdateService;c:\program files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe;c:\program files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 ezSharedSvc;Easybits Services for Windows;c:\windows\System32\ezSharedSvcHost.exe;c:\windows\SYSNATIVE\ezSharedSvcHost.exe [x] S2 FPLService;TrueSuiteService;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe [x] S2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [x] S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [x] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [x] S2 HPWMISVC;HPWMISVC;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe;c:\program files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 IconMan_R;IconMan_R;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe;c:\program files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [x] S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [x] S2 Netzmanager Service;Netzmanager Infrastruktur Informationssystem Dienst;c:\program files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe ;c:\program files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [x] S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x] S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys;c:\windows\SYSNATIVE\DRIVERS\clwvd.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-09-25 03:38 1096520 ----a-w- c:\program files (x86)\Google\Chrome\Application\37.0.2062.124\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-10-16 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-21 12:59] . 2014-10-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-21 14:12] . 2014-10-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-21 14:12] . 2014-10-14 c:\windows\Tasks\HPCeeScheduleForWurzbacher.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2011-07-15 03:43] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-09 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-09 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-09 416024] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2014-08-22 1331288] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "NCPluginUpdater"="c:\program files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" [2014-10-07 21720] . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.com/ uLocal Page = c:\windows\system32\blank.htm mDefault_Search_URL = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=ds&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518&type=default&q={searchTerms} mDefault_Page_URL = hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518 mStart Page = hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518 mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=ds&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518&type=default&q={searchTerms} IE: Free YouTube to MP3 Converter - c:\users\Wurzbacher\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\ FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Notify-SDWinLogon - SDWinLogon.dll HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start HKLM_Wow6432Node-ActiveSetup-{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec WebBrowser-{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-Adobe Shockwave Player - c:\windows\system32\Adobe\Shockwave 11\uninstaller.exe AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe AddRemove-{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE} - c:\program files (x86)\InstallShield Installation Information\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}\setup.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-10-17 14:50:05 ComboFix-quarantined-files.txt 2014-10-17 12:50 . Vor Suchlauf: 11 Verzeichnis(se), 401.625.432.064 Bytes frei Nach Suchlauf: 17 Verzeichnis(se), 402.155.110.400 Bytes frei . - - End Of File - - 1F10463E7339D12FE549385B2278EA9C |
18.10.2014, 09:51 | #6 |
/// the machine /// TB-Ausbilder | Windows 7 Rechner wird immer langsamer Malware gefunden Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Windows 7 Rechner wird immer langsamer Malware gefunden |
18.10.2014, 15:47 | #7 |
| Windows 7 Rechner wird immer langsamer Malware gefunden Hallo habe alles durchlaufen lassen, musste die Logs auf mehrere Post aufteilen, da zu groß. hier die Logs: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 18.10.2014 Suchlauf-Zeit: 16:06:13 Logdatei: mbam.txt Administrator: Ja Version: 2.00.3.1025 Malware Datenbank: v2014.10.18.05 Rootkit Datenbank: v2014.10.17.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Wurzbacher Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 325130 Verstrichene Zeit: 15 Min, 58 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 22 PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, In Quarantäne, [37f627ef215b26108d3d5485c939619f], PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, In Quarantäne, [37f627ef215b26108d3d5485c939619f], PUP.Optional.DVDVideoSoftTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}, In Quarantäne, [f03d8294f68677bf0aeeb5e83ac86799], PUP.Optional.DVDVideoSoftTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}, In Quarantäne, [f03d8294f68677bf0aeeb5e83ac86799], PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}, In Quarantäne, [f03d8294f68677bf0aeeb5e83ac86799], PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}, In Quarantäne, [f03d8294f68677bf0aeeb5e83ac86799], PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarantäne, [51dc0c0af18bd264a7cc70346c9601ff], PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [51dc0c0af18bd264a7cc70346c9601ff], PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [51dc0c0af18bd264a7cc70346c9601ff], PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarantäne, [51dc0c0af18bd264a7cc70346c9601ff], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [bb72dc3a91ebc86ea013d5cab2509d63], PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [65c868ae7efe94a235983b386a9aac54], PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\DealPlyLive, In Quarantäne, [2805dd39c7b526108d04d5948183b947], PUP.Optional.DoSearches.A, HKLM\SOFTWARE\WOW6432NODE\dosearchesSoftware, In Quarantäne, [7bb269ad433944f20bf3b9b2c242d729], PUP.Optional.DVDVideoSoftTB.A, HKLM\SOFTWARE\WOW6432NODE\DVDVideoSoftTB_DE, In Quarantäne, [e14c4ec8e8947bbb8f3e9c7f2bd82ad6], PUP.Optional.Elex.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ifohbjbgfchkkfhphahclmkpgejiplfo, In Quarantäne, [1e0fcd49fc80092db84927459f6547b9], PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [8aa370a6493387af309d1c574aba5aa6], PUP.Optional.DealPly.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DealPlyLive, In Quarantäne, [3cf1ba5cbfbdfd39049104658282a759], PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DVDVideoSoftTB_DE, In Quarantäne, [bb7234e23d3fd5613699c5562dd63ec2], PUP.Optional.PriceGong.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [0a238591bcc040f6caa7d577f31044bc], PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\nikpibnbobmbdbheedjfogjlikpgpnhp, In Quarantäne, [c66734e2483495a111b261bce02336ca], PUP.Optional.Qone8, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [d35ac650106c54e24488f182679dd22e], Registrierungswerte: 8 PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}, ò?¦apos;짲ä¬?֮췢ó?½¬, In Quarantäne, [f03d8294f68677bf0aeeb5e83ac86799] PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}, In Quarantäne, [f03d8294f68677bf0aeeb5e83ac86799], PUP.Optional.DVDVideoSoftTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}, DVDVideoSoftTB DE Toolbar, In Quarantäne, [f03d8294f68677bf0aeeb5e83ac86799] PUP.Optional.DVDVideoSoftTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}, In Quarantäne, [f03d8294f68677bf0aeeb5e83ac86799], PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF}, In Quarantäne, [fc314bcbbbc17bbb14e4abf28d751fe1], PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-1447600568-1936789412-2989334194-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}, In Quarantäne, [b17cd83ec4b8cf6704f42d70e71b2dd3], PUP.Optional.DVDVideoSoftTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}, In Quarantäne, [f13c1ff75a22b08661976637f30fd729], PUP.Optional.DVDVideoSoftTB.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{0027da2d-c9f2-4b0b-ae05-e2cd1bdb6cff}, In Quarantäne, [d15cf81e18647bbb0eea3c6121e127d9], Registrierungsdaten: 3 PUP.Optional.DoSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518, Gut: (www.google.com), Schlecht: (hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518),Ersetzt,[b27b15011765c86e37a34ed532d37c84] PUP.Optional.DoSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518, Gut: (www.google.com), Schlecht: (hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518),Ersetzt,[5bd2e036b3c9ca6cfcdd8c979174af51] PUP.Optional.DoSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518, Gut: (www.google.com), Schlecht: (hxxp://www.dosearches.com/?utm_source=b&utm_medium=adks&utm_campaign=rg&utm_content=hp&from=adks&uid=HitachiXHTS545050B9A300_120111PBN408P7H86SZEX&ts=1384110518),Ersetzt,[82ab70a6f18b7eb8ffdbd25141c4837d] Ordner: 119 PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive, In Quarantäne, [ad80d54194e81d1994a73cb0f60c22de], PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update, In Quarantäne, [ad80d54194e81d1994a73cb0f60c22de], PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update\Log, In Quarantäne, [ad80d54194e81d1994a73cb0f60c22de], PUP.Optional.DealPly.A, C:\Users\Wurzbacher\AppData\Roaming\Dealply, In Quarantäne, [ae7f14028cf05ed862da3eae11f14eb2], PUP.Optional.DealPly.A, C:\Users\Wurzbacher\AppData\Roaming\Dealply\UpdateProc, In Quarantäne, [ae7f14028cf05ed862da3eae11f14eb2], PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive, In Quarantäne, [a08d5fb775079e982716b933837fff01], PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\CrashReports, In Quarantäne, [a08d5fb775079e982716b933837fff01], PUP.Optional.OpenCandy, C:\Users\Wurzbacher\AppData\Roaming\OpenCandy, In Quarantäne, [ed4064b25725350176fc8d5f24ded12f], PUP.Optional.OpenCandy, C:\Users\Wurzbacher\AppData\Roaming\OpenCandy\E1F71517B5384D4589AF06567D5A8E2F, In Quarantäne, [ed4064b25725350176fc8d5f24ded12f], PUP.Optional.DealPly.A, C:\Users\Wurzbacher\AppData\Local\DealPlyLive, In Quarantäne, [88a50115b7c591a570201cd00ef44bb5], PUP.Optional.DealPly.A, C:\Users\Wurzbacher\AppData\Local\DealPlyLive\CrashReports, In Quarantäne, [88a50115b7c591a570201cd00ef44bb5], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.MindSpark.A, C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\Allin1Convert_8h, In Quarantäne, [05287b9b601c3afc9c2df302f30f847c], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\bookmarks, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\bookmarks\img, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\extensions, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\extensions\img, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\lastVisited, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\lastVisited\img, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\quickSearch, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\quickSearch\img, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\setup, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\setup\img, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\setup\img\skin_0, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins\img, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins\img\skin_0, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\quickSearch, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\search, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\en, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\es, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\es_419, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr-BE, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr-CA, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr-CH, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr-LU, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\it-CH, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\lt, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\pl, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\pt_BR, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\ru, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\ru-MO, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\tr, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\vi, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\zh_CN, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\zh_TW, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_metadata, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\images, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\de, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\en, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\es, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\fr, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\it, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\ja, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\nl, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\pl, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\pt, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\ru, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\tr, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\zh_CN, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\zh_TW, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\AddedAppDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\DefualtImages, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\DetectedAppDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\EngineFirstTimeDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog\images, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\images, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog\Images, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\Images, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarUntrustedAppsApprovalDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UninstallDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAddedAppDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAppApprovalDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAppPendingDialog, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\EmailNotifier, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\ExternalComponent, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Logs, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\MyStuffApps, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\plugins, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\RadioPlayer, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\AppsMetaData, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\DynamicDialogs, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarHiddenLogin, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarHiddenSettings, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarLogin, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarSettings, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_de, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_de\ToolbarTranslation, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\SearchInNewTab, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\UserDefinedItems, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Program Files (x86)\DVDVideoSoftTB_DE, In Quarantäne, [121bdc3a3d3f20166a8b36dff1129868], Dateien: 430 PUP.OptionalBundleInstaller.A, C:\Users\Wurzbacher\Downloads\Player_Setup.exe, In Quarantäne, [d756c5510775ce6830c39889758bda26], PUP.Optional.Outbrowse, C:\Users\Wurzbacher\Downloads\setup (8).exe, In Quarantäne, [33fa5db90a7272c447ce336756ae629e], PUP.Optional.Outbrowse, C:\Users\Wurzbacher\Downloads\setup (9).exe, In Quarantäne, [dd503dd9abd1cb6b12036f2b17edb34d], PUP.Optional.DomaIQ, C:\Users\Wurzbacher\Downloads\Setup (26).exe, In Quarantäne, [b97439dde99345f147cd7bd6fd0360a0], PUP.Optional.Amonetize.A, C:\Users\Wurzbacher\Downloads\FlashPlayersetup__6802_i441992298_il31.exe, In Quarantäne, [46e71cfa730952e45940b18907f99e62], PUP.Optional.Bandoo, C:\Users\Wurzbacher\Downloads\iLividSetup-r772-n-bc (1).exe, In Quarantäne, [b677b6602d4f6acc2d55c6589f62c63a], PUP.Optional.Bandoo, C:\Users\Wurzbacher\Downloads\iLividSetup-r772-n-bc.exe, In Quarantäne, [d45921f588f465d1344e011dfc0512ee], PUP.Optional.OutBrowse, C:\Users\Wurzbacher\Downloads\Installer (1).exe, In Quarantäne, [a68756c0c2bacb6b34db630720e144bc], PUP.Optional.OutBrowse, C:\Users\Wurzbacher\Downloads\Installer (2).exe, In Quarantäne, [151858be6418bb7bcf404c1ef70a9868], PUP.Optional.OutBrowse, C:\Users\Wurzbacher\Downloads\Installer (3).exe, In Quarantäne, [db5231e5a4d8eb4bd8370d5d2ad76898], PUP.Optional.OutBrowse, C:\Users\Wurzbacher\Downloads\Installer.exe, In Quarantäne, [909d81957c0083b3ed22b7b306fb34cc], PUP.Optional.Outbrowse, C:\Users\Wurzbacher\Downloads\setup (10).exe, In Quarantäne, [8ca129ed245885b1977e2377d52ff10f], PUP.Optional.Outbrowse, C:\Users\Wurzbacher\Downloads\setup (11).exe, In Quarantäne, [c4692aece39935011afb46549d6731cf], Trojan.ELEX, C:\Users\Wurzbacher\Downloads\yet_another_cleaner_mar (1).exe, In Quarantäne, [44e91df933498da974402d2f43be6b95], Trojan.ELEX, C:\Users\Wurzbacher\Downloads\yet_another_cleaner_mar (2).exe, In Quarantäne, [bc711afc6c106ec80ca871eb54ad3fc1], Trojan.ELEX, C:\Users\Wurzbacher\Downloads\yet_another_cleaner_mar.exe, In Quarantäne, [7bb2a96d9ae28da9fcb8d488778aff01], PUP.Optional.DealPly.A, C:\Windows\System32\Tasks\Dealply, In Quarantäne, [c5680610abd1e155fb5f1d12cf34e51b], PUP.Optional.Wajam.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.wajam.com_0.localstorage, In Quarantäne, [36f7fd19de9e52e4f0d8a695cf34619f], PUP.Optional.Wajam.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.wajam.com_0.localstorage-journal, In Quarantäne, [d8556aac6a1277bf5f694fecc53eaa56], PUP.Optional.NewTab.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx, In Quarantäne, [65c830e62b51122455635af45fa4fe02], PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update\Log\DealPlyLive.log, In Quarantäne, [ad80d54194e81d1994a73cb0f60c22de], PUP.Optional.DealPly.A, C:\Users\Wurzbacher\AppData\Roaming\Dealply\UpdateProc\config.dat, In Quarantäne, [ae7f14028cf05ed862da3eae11f14eb2], PUP.Optional.DealPly.A, C:\Users\Wurzbacher\AppData\Roaming\Dealply\UpdateProc\TTL.DAT, In Quarantäne, [ae7f14028cf05ed862da3eae11f14eb2], PUP.Optional.OpenCandy, C:\Users\Wurzbacher\AppData\Roaming\OpenCandy\E1F71517B5384D4589AF06567D5A8E2F\TuneUpUtilities2013_2200218_de-DE.exe, In Quarantäne, [ed4064b25725350176fc8d5f24ded12f], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\h.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\1.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\10040.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\11626.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\1424.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\15240.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\15286.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\15294.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\15724.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\16233.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\16240.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\16675.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\1707.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\1728.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\2229.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\2260.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\3247.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\371.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\3721.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\41.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\4436.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\4489.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\450.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\5952.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\6643.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\6704.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\8049.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\8062.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\8124.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\83.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\a.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\b.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\c.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\d.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\e.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\f.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\g.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\i.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\j.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\k.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\l.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\m.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\mru.xml, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\n.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\o.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\p.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\q.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\r.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\s.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\t.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\u.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\v.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\w.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\wlu.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\x.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\y.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.PriceGong.A, C:\Users\Wurzbacher\AppData\LocalLow\PriceGong\Data\z.txt, In Quarantäne, [9697b6602f4d7abce9fb13dcb34fd828], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\background.html, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\index.html, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\manifest.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\search.html, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\all.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\classification.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\page_flip.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\weather.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\bookmarks\bookmarks.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\bookmarks\img\headerBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\bookmarks\img\logo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\cloud.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\buttonBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\categoryBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\cn_outSideLogo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\cn_uploadLogo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\headerBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\icons.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\logo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\outSideLogo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\searchBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\searchButton.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\searchLeft.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\selected.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\tabsBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\cloud\img\uploadLogo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\extensions\extensions.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\extensions\img\extensionsbtn.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\extensions\img\logo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\lastVisited\lastVisited.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\lastVisited\img\logo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\quickSearch\quickSearch.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\quickSearch\img\headerBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\quickSearch\img\logo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\quickSearch\img\search1.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\quickSearch\img\searchButton.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\setup\setup.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\setup\img\headerBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\setup\img\logo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\setup\img\skin_0\dialBoxStyle.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\setup\img\skin_0\icons.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins\download.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins\remove.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins\skins.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins\img\headerBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins\img\logo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins\img\skin_0\categoryBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\css\skins\img\skin_0\icons.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\blank.gif, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\default-wallpaper.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\game.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\headerBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\icon128.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\icon16.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\icon48.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\ie_logo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\line.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\load.gif, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\main.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\oNewtab.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\photosload.gif, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\search3.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\searchButton.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\shoping.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\submit_buttion.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\uploadpaper.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\wallpaper_buttion.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\weather.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\weatherlogo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\webstore.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\wedo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\quickSearch\linktype.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\quickSearch\logo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\defaultBg.svg, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\defaultBgIco.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\idialog_s.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\ios5_button.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\left.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\loading.gif, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\loading2.gif, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\q_bg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\q_left.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\q_right.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\right.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\titleBg.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\img\skin_0\wedo.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\background.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\easing.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\file.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\FileSaver.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\ga.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\inject.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\jquery-base.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\jquery.autocomplete.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\jquery.sortable.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\wrap.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\xa.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\js\xagainit.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\search\quickSearch.js, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\search\search2.png, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\search\skin_0.css, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\en\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\es\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\es_419\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr-BE\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr-CA\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr-CH\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\fr-LU\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\it-CH\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\lt\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\pl\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\pt_BR\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\ru\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\ru-MO\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\tr\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\vi\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\zh_CN\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_locales\zh_TW\messages.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.Lightning.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifohbjbgfchkkfhphahclmkpgejiplfo\1.3.0.6_0\_metadata\verified_contents.json, In Quarantäne, [fd30b85ea7d559dd26b919f65ea51ce4], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\background.html, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\background.js, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\dvs_freeyoutubedownload.css, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\dvs_freeyoutubedownload.js, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\dvs_logo.ico, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\dvs_logo_128.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\dvs_logo_32.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\dvs_logo_48.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\errorRunProgramm.html, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\manifest.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\np_dvs_plugin.dll, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\options.html, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\options.js, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\page_action.html, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\images\backbar.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\images\download.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\images\fs.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\images\headphone.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\images\logo.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\images\manager.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\images\YoutubeDownloader.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\images\YoutubeToMp3.png, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\de\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\en\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\es\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\fr\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\it\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\ja\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\nl\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\pl\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\pt\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\ru\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\tr\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\zh_CN\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.1_0\_locales\zh_TW\messages.json, In Quarantäne, [a786cb4bafcddb5bb13bc74c689b9a66], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\ldrtbDVDV.dll, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\tbDVDV.dll, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\ThirdPartyComponents.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\toolbar.cfg, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_home_page_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_options_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_privacy_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_refresh_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_shrink_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_upgrade_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_SearchEngines_ebay_search_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_SearchEngines_images_search_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_SearchEngines_news_icon_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_Images_634067677527028750_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_Images_634084059408641250_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_Images_634084059786610000_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_Images_634805357596005627_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_images_634805357830383628_24PX_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_Images_634805365593028749_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_Images_634805365841934999_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_images_634806266238479525_24PX_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_images_634806267538394186_24PX_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_Images_633867336948106250_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_Images_SearchActivationButton-go_but20_gif-General-633937242465431250_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_74_161_CT1616974_Images_633971094131400000_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Options_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_flags_Germany_flag_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Chess_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_PyramidRunner_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_help_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_MarketPlace_6a_472_6a060db5-7b12-4964-8c5d-8c7ba0f8e472_Appearance_634503122680121741_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Clash_N_Slash_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Connect4_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_FinalFortress_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_FlowerQuest_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Go_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_HiddenExpedition_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_MahjonggArtifacts2_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Marbles_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Match4_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_MarketPlace_81_28e_816147d9-d2b0-4dc7-b220-fb7ea1b1228e_Appearance_634726106907093173_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_MarketPlace_97_5e6_9739aadc-99e3-4b66-8c1e-bc6ae6cd55e6_Appearance_634165981520378434_24x24_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___weather_conduit_com_images_weather_Default_drizzle_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___weather_conduit_com_images_weather_Default_foggy_night_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___weather_conduit_com_images_weather_Default_partly_cloudy_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___weather_conduit_com_images_weather_Default_partly_cloudy_night_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___weather_conduit_com_images_weather_Default_sunny_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___weather_conduit_com_images_weather_Default_sunny_night_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_bankimages_commandcomps_block_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_About_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Browse_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Contact_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Hide_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_bankImages_ConduitEngine_ContextMenu_LikeIcon_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_MoreFromPublisher_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_More_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Reversi_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_RiseofAtlantis_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_SheepMe_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_SnowyBearsAdventures_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_SnowyTreasureHunter_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Sudoku_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_TicTacToe_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_about_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_clear_history_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_main_menu_contact_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_flags_holland_flag_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_flags_italy_flag_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_flags_spain_flag_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_flags_uk_flag_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_flags_usa_flag_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_ArcticQuest_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_AtlantisQuest_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Backgammon_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_BistroStars_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_gamesicons_Checkers_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_74_161_CT1616974_Images_633971085913980000_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_74_161_CT1616974_Images_633971087054136250_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_74_161_CT1616974_Images_633971088460386250_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_74_161_CT1616974_Images_633971089234993750_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_74_161_CT1616974_Images_633971089477650000_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_74_161_CT1616974_Images_633971089670306250_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_74_161_CT1616974_Images_633971092504525000_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_48_262_CT2625848_Images_633780109207875000_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Privacy_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Refresh_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Upgrade_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_BankImages_Facebook_Facebook_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_ClientImages_radio_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_Images_ClientResources_mini_browser_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_eula_png.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_bullet_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\CacheIcons\http___storage_conduit_com_images_icons_flags_france_flag_gif.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\RoundedCornersIE9.css, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\DialogsAPI.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\excanvas.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\generalDialogStyle.css, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\PIE.htc, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\RoundedCorners.css, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\settings.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\version.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\AddedAppDialog\app-added.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\AddedAppDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\DefualtImages\icon.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\DetectedAppDialog\app-2go.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\DetectedAppDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\EngineFirstTimeDialog\EngineFirstTimeDialog.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\EngineFirstTimeDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\EngineFirstTimeDialog\right-click.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog\SearchProtector.css, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog\SearchProtector.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog\images\ok-button.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog\images\separation-line.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\NewSearchProtectorDialog\images\warning.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\bubble.css, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\bubble.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\images\information.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\images\x-default-LTR.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\images\x-default-RTL.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-LTR.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-RTL.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog\SearchProtector.css, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog\SearchProtector.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog\Images\info.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog\Images\ok-on.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorDialog\Images\ok.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.css, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.jpg, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\Images\info.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\Images\ok-on.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\SearchProtectorRetakeoverDialog\Images\ok.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.css, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images\app-store-icon.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images\arrow.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images\divider.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images\emailNotifier.gif, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images\facebook.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images\radio.GIF, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images\Thumbs.db, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images\truste_welcome.GIF, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarFirstTimeDialog\images\weather.GIF, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarUntrustedAppsApprovalDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\ToolbarUntrustedAppsApprovalDialog\ToolbarUntrustedAppsApprovalDialog.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAddedAppDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAddedAppDialog\UT-app-dialog-added.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAppApprovalDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAppApprovalDialog\UT-app-dialog-needs-your-approval.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAppPendingDialog\main.html, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Dialogs\UntrustedAppPendingDialog\UT-app-dialog-is-waiting.js, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\EmailNotifier\AccountTypes.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\EmailNotifier\aol.com.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\EmailNotifier\comcast.net.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\EmailNotifier\google.com.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\EmailNotifier\hotmail.com.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\EmailNotifier\yahoo.com.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=GottenApps&locale=de.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=OtherApps&locale=de.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=SharedApps&locale=de.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=Toolbar&locale=de.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\manifest.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin\PriceGongIE.dll, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin\PriceGong_16.png, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\RadioPlayer\IP_Stations_Media_List.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\RadioPlayer\Predefined_Media_List.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\AppsMetaData\data.bck.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\AppsMetaData\data.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\DynamicDialogs\data.bck.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\DynamicDialogs\data.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarHiddenLogin\data.bck.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarHiddenLogin\data.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarHiddenSettings\data.bck.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarHiddenSettings\data.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarLogin\data.bck.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarLogin\data.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarSettings\data.bck.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_CT2625848\ToolbarSettings\data.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_de\ToolbarTranslation\data.bck.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\Repository\conduit_CT2625848_de\ToolbarTranslation\data.txt, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Users\Wurzbacher\AppData\LocalLow\DVDVideoSoftTB_DE\SearchInNewTab\SearchInNewTabContent.xml, In Quarantäne, [e944d93d6a1292a403f1a07560a3c739], PUP.Optional.DVDVideoSoftTB.A, C:\Program Files (x86)\DVDVideoSoftTB_DE\GottenAppsContextMenu.xml, In Quarantäne, [121bdc3a3d3f20166a8b36dff1129868], PUP.Optional.DVDVideoSoftTB.A, C:\Program Files (x86)\DVDVideoSoftTB_DE\ldrtbDVDV.dll, In Quarantäne, [121bdc3a3d3f20166a8b36dff1129868], PUP.Optional.DVDVideoSoftTB.A, C:\Program Files (x86)\DVDVideoSoftTB_DE\OtherAppsContextMenu.xml, In Quarantäne, [121bdc3a3d3f20166a8b36dff1129868], PUP.Optional.DVDVideoSoftTB.A, C:\Program Files (x86)\DVDVideoSoftTB_DE\SharedAppsContextMenu.xml, In Quarantäne, [121bdc3a3d3f20166a8b36dff1129868], PUP.Optional.DVDVideoSoftTB.A, C:\Program Files (x86)\DVDVideoSoftTB_DE\tbDVDV.dll, In Quarantäne, [121bdc3a3d3f20166a8b36dff1129868], PUP.Optional.DVDVideoSoftTB.A, C:\Program Files (x86)\DVDVideoSoftTB_DE\toolbar.cfg, In Quarantäne, [121bdc3a3d3f20166a8b36dff1129868], PUP.Optional.DVDVideoSoftTB.A, C:\Program Files (x86)\DVDVideoSoftTB_DE\ToolbarContextMenu.xml, In Quarantäne, [121bdc3a3d3f20166a8b36dff1129868], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) |
18.10.2014, 15:51 | #8 |
| Windows 7 Rechner wird immer langsamer Malware gefunden Teil 2: Adw Cleaner Code:
ATTFilter # AdwCleaner v4.000 - Bericht erstellt am 18/10/2014 um 16:29:41 # DB v2014-10-17.9 # Aktualisiert 12/10/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Wurzbacher - WURZBACHER-HP # Gestartet von : C:\Users\Wurzbacher\Desktop\AdwCleaner_4.000.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Wurzbacher\AppData\Local\apn Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\Users\Wurzbacher\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Wurzbacher\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB Ordner Gelöscht : C:\Users\Wurzbacher\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Wurzbacher\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\Wurzbacher\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Program Files\Enigma Software Group Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk Datei Gelöscht : C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\11-suche.xml Datei Gelöscht : C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage Datei Gelöscht : C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage Datei Gelöscht : C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal ***** [ Tasks ] ***** Task Gelöscht : Dealply ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Wurzbacher\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk Verknüpfung Desinfiziert : C:\Users\Wurzbacher\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk Verknüpfung Desinfiziert : C:\Users\Wurzbacher\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk Verknüpfung Desinfiziert : C:\Users\Wurzbacher\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT2625848 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D43B3890-80C7-4010-A95D-1E77B5924DC3} Wert Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] Wert Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] Wert Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] Wert Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\EnigmaSoftwareGroup ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.17116 Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] -\\ Mozilla Firefox v33.0 (x86 de) [f24iiy18.default] - Zeile gelöscht : user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml"); [f24iiy18.default] - Zeile gelöscht : user_pref("extensions.toolbar.mindspark._8hMembers_.lastActivePing", "1411497894242"); [f24iiy18.default] - Zeile gelöscht : user_pref("extensions.toolbar.mindspark._8hMembers_.weather.location", "10001"); [f24iiy18.default] - Zeile gelöscht : user_pref("extensions.toolbar.mindspark.lastInstalled", "allin1convert@mindspark.com"); -\\ Google Chrome v37.0.2062.124 ************************* AdwCleaner[R0].txt - [7900 octets] - [18/10/2014 16:28:21] AdwCleaner[S0].txt - [7464 octets] - [18/10/2014 16:29:41] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7524 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.3.3 (10.14.2014:1) OS: Windows 7 Home Premium x64 Ran by Wurzbacher on 18.10.2014 at 16:34:12,22 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{055CBFF5-162B-45DF-946A-E25BBC6CD6EC} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{1D4E1D3B-7DCB-424A-BB4B-C3E4A43CD2F9} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{31FF37DB-2240-4989-89DF-E2A27A791BAD} ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{0E65107A-5170-43D8-8509-00FB1B2DDE97} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{236905AB-8BA7-487D-95A7-65AE84407EA6} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{2D4F8460-07D9-4A83-A2EB-59D9CC4E80E1} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{3AB6F40D-AC73-42C1-BCD7-1DB69FB77F8E} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{3CCDECA6-0582-4B70-A8F1-16F95FD10A6A} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{41D45589-702C-45D4-A46A-764A2E682062} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{4CEA5738-8BF0-42C5-87D4-15E7059F1F40} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{9C02FDA9-EA56-4AF7-9E27-DCBE26616920} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{A3B875F4-EF49-43A0-999B-F0061BFBD8F2} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{A82CB02A-BF74-49F4-B21A-DAD505EB2DC9} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{AF30B0A2-0E60-4427-8798-2FCD6CDC67C9} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{BDC5E501-2559-4C89-BFB4-39A7EDCBDD1E} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{C5FF1657-3381-4FF0-83B1-BE40A442D83E} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{D2243298-A285-4473-91D7-0DC202564E04} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{DB605399-E410-4626-A950-3CAF1EB61733} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{DEE6ED37-4D9D-4CF0-9703-9FEDB0233D7A} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{EE0DC72B-1515-45AB-815D-B5EC05C97B64} Successfully deleted: [Empty Folder] C:\Users\Wurzbacher\appdata\local\{F56AE9B4-9C4F-4531-B945-8A6F04833EA4} ~~~ FireFox Successfully deleted: [Folder] C:\Users\Wurzbacher\AppData\Roaming\mozilla\firefox\profiles\f24iiy18.default\extensions\toolbar@web.de Emptied folder: C:\Users\Wurzbacher\AppData\Roaming\mozilla\firefox\profiles\f24iiy18.default\minidumps [149 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 18.10.2014 at 16:36:47,73 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-10-2014 01 Ran by Wurzbacher (administrator) on WURZBACHER-HP on 18-10-2014 16:37:49 Running from C:\Users\Wurzbacher\Desktop Loaded Profile: Wurzbacher (Available profiles: Wurzbacher) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2011-06-10] (Synaptics Incorporated) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-09-15] (EasyBits Software AS) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1238016 2013-07-26] (Easybits) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-10-07] (Hewlett-Packard) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 BootExecute: autocheck autochk * sdnclean64.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {88AEA96D-C839-4D40-9888-4DC0F37C806E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms} SearchScopes: HKLM-x32 - {88AEA96D-C839-4D40-9888-4DC0F37C806E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms} SearchScopes: HKCU - {88AEA96D-C839-4D40-9888-4DC0F37C806E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms} BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-11-04] (EasyBits Software Corp.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\Extensions\trash [2014-09-23] FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com [2014-10-16] Chrome: ======= CHR DefaultSearchKeyword: Default -> conduit.search CHR DefaultSearchURL: Default -> hxxp://search.conduit.com/Results.aspx?ctid=CT3317742&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP3CD6016B-6C2D-4D3F-A933-7579D01B4804&q={searchTerms}&SSPV= CHR DefaultSuggestURL: Default -> hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} CHR Profile: C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-15] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-03] CHR Extension: (Website Logon) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfmogjcijkfeahcajecmmegieipfbdcc [2012-09-17] CHR Extension: (Google Wallet) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31] CHR HKLM-x32\...\Chrome\Extension: [bfmogjcijkfeahcajecmmegieipfbdcc] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-08-18] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed] S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [254016 2014-10-16] (WildTangent) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed] S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20552 2010-07-30] (Devguru Co., Ltd) S3 dgderdrv; C:\Windows\SysWOW64\drivers\dgderdrv.sys [18120 2010-07-30] (Devguru Co., Ltd) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203104 2012-09-19] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-18 16:37 - 2014-10-18 16:38 - 00017086 _____ () C:\Users\Wurzbacher\Desktop\FRST.txt 2014-10-18 16:37 - 2014-10-18 16:37 - 00000000 ____D () C:\Users\Wurzbacher\Desktop\FRST-OlderVersion 2014-10-18 16:36 - 2014-10-18 16:36 - 00003341 _____ () C:\Users\Wurzbacher\Desktop\JRT.txt 2014-10-18 16:34 - 2014-10-18 16:34 - 00000000 ____D () C:\Windows\ERUNT 2014-10-18 16:31 - 2014-10-18 16:31 - 00007628 _____ () C:\Users\Wurzbacher\Desktop\AdwCleaner[S0].txt 2014-10-18 16:28 - 2014-10-18 16:29 - 00000000 ____D () C:\AdwCleaner 2014-10-18 16:23 - 2014-10-18 16:23 - 00116486 _____ () C:\Users\Wurzbacher\Desktop\mbam.txt 2014-10-18 16:19 - 2014-10-18 16:19 - 00000000 ____D () C:\Users\Wurzbacher\Desktop\logs alt 2014-10-18 16:01 - 2014-10-18 16:31 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-18 16:01 - 2014-10-18 16:01 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-18 16:01 - 2014-10-18 16:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-18 16:01 - 2014-10-18 16:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-18 16:01 - 2014-10-18 16:01 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-18 16:01 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-18 16:01 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-18 16:01 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-18 15:59 - 2014-10-18 15:59 - 01705698 _____ (Thisisu) C:\Users\Wurzbacher\Downloads\JRT.exe 2014-10-18 15:59 - 2014-10-18 15:59 - 01705698 _____ (Thisisu) C:\Users\Wurzbacher\Desktop\JRT.exe 2014-10-18 15:59 - 2014-10-18 15:58 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Wurzbacher\Desktop\mbam-setup-2.0.3.1025.exe 2014-10-18 15:59 - 2014-10-18 15:58 - 01976320 _____ () C:\Users\Wurzbacher\Desktop\AdwCleaner_4.000.exe 2014-10-18 15:58 - 2014-10-18 15:58 - 01976320 _____ () C:\Users\Wurzbacher\Downloads\AdwCleaner_4.000.exe 2014-10-18 15:57 - 2014-10-18 15:58 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Wurzbacher\Downloads\mbam-setup-2.0.3.1025.exe 2014-10-17 18:14 - 2013-12-21 11:39 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-10-17 18:14 - 2013-12-21 09:56 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-10-17 18:04 - 2014-09-20 07:18 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-17 18:04 - 2014-09-20 07:17 - 02236928 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-17 18:04 - 2014-09-20 07:17 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 19280896 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-17 18:04 - 2014-09-20 07:15 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-17 18:04 - 2014-09-20 07:15 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-10-17 18:04 - 2014-09-20 07:15 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 13757952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 01762816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-10-17 18:04 - 2014-09-20 05:56 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-10-17 18:04 - 2014-09-20 05:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-10-17 18:04 - 2014-09-20 05:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-10-17 18:04 - 2014-09-20 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-17 18:04 - 2014-09-20 05:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-10-17 18:04 - 2014-09-20 04:43 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-10-17 18:04 - 2014-09-20 04:35 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-10-17 14:50 - 2014-10-17 14:50 - 00017649 _____ () C:\ComboFix.txt 2014-10-17 14:39 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-10-17 14:39 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-10-17 14:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-10-17 14:38 - 2014-10-17 14:50 - 00000000 ____D () C:\Qoobox 2014-10-17 14:38 - 2014-10-17 14:49 - 00000000 ____D () C:\Windows\erdnt 2014-10-17 14:36 - 2014-10-17 14:37 - 05583559 ____R (Swearware) C:\Users\Wurzbacher\Desktop\ComboFix.exe 2014-10-16 17:45 - 2014-07-07 04:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-10-16 17:45 - 2014-07-07 04:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2014-10-16 17:45 - 2014-07-07 04:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-10-16 17:45 - 2014-07-07 04:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2014-10-16 17:45 - 2014-07-07 04:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2014-10-16 17:45 - 2014-07-07 03:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2014-10-16 17:45 - 2014-07-07 03:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2014-10-16 17:44 - 2014-08-19 05:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2014-10-16 17:44 - 2014-08-19 05:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2014-10-16 17:44 - 2014-08-19 05:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2014-10-16 17:44 - 2014-08-19 05:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2014-10-16 17:44 - 2014-08-19 05:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2014-10-16 17:44 - 2014-08-19 05:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2014-10-16 17:44 - 2014-08-19 05:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2014-10-16 17:44 - 2014-08-19 05:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2014-10-16 17:44 - 2014-08-19 05:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2014-10-16 17:44 - 2014-08-19 05:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2014-10-16 17:44 - 2014-08-19 04:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2014-10-16 17:44 - 2014-08-19 04:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2014-10-16 17:44 - 2014-08-19 04:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2014-10-16 17:44 - 2014-07-07 04:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-10-16 17:44 - 2014-07-07 04:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-10-16 17:44 - 2014-07-07 04:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-10-16 17:44 - 2014-07-07 04:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2014-10-16 17:44 - 2014-07-07 04:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2014-10-16 17:44 - 2014-07-07 04:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-10-16 17:44 - 2014-07-07 04:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2014-10-16 17:44 - 2014-07-07 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-10-16 17:44 - 2014-07-07 03:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2014-10-16 17:44 - 2014-07-07 03:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2014-10-16 17:44 - 2014-07-07 03:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2014-10-16 17:44 - 2014-07-07 03:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-10-16 17:44 - 2014-07-07 03:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-10-16 17:44 - 2014-07-07 03:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-10-16 17:44 - 2014-07-07 03:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2014-10-16 17:44 - 2014-07-07 03:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2014-10-16 17:44 - 2014-07-07 03:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2014-10-16 17:44 - 2014-06-28 02:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2014-10-16 17:44 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2014-10-16 17:44 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2014-10-16 17:16 - 2014-10-18 16:37 - 02112000 _____ (Farbar) C:\Users\Wurzbacher\Desktop\FRST64.exe 2014-10-16 15:56 - 2014-10-16 15:57 - 00033995 _____ () C:\Users\Wurzbacher\Downloads\Addition.txt 2014-10-16 15:55 - 2014-10-18 16:37 - 00000000 ____D () C:\FRST 2014-10-16 15:55 - 2014-10-16 15:57 - 00031556 _____ () C:\Users\Wurzbacher\Downloads\FRST.txt 2014-10-16 15:54 - 2014-10-16 15:54 - 02111488 _____ (Farbar) C:\Users\Wurzbacher\Downloads\FRST64.exe 2014-10-16 15:51 - 2014-09-29 02:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-16 15:50 - 2014-10-16 15:50 - 00001009 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Netzmanager.lnk 2014-10-16 15:50 - 2014-10-16 15:50 - 00001003 _____ () C:\Users\Public\Desktop\Netzmanager.lnk 2014-10-16 15:50 - 2014-10-16 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Netzmanager 2014-10-16 15:50 - 2014-10-16 15:50 - 00000000 ____D () C:\Program Files\Netzmanager 2014-10-16 15:50 - 2014-10-10 04:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-10-16 15:50 - 2014-10-10 04:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-10-16 15:50 - 2014-10-10 04:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-10-16 15:50 - 2014-09-18 04:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-10-16 15:50 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-10-16 15:50 - 2014-09-04 07:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-16 15:50 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2014-10-16 15:50 - 2014-07-17 03:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-10-16 15:50 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-10-16 15:50 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-10-16 15:50 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-10-16 15:50 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-10-16 15:50 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-10-16 15:50 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-10-16 15:50 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-10-16 15:50 - 2014-06-19 00:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-16 15:49 - 2014-10-16 15:50 - 00000000 __HDC () C:\ProgramData\{BA58D0EE-89D1-4191-9F19-B6AD920B04F7} 2014-10-16 15:49 - 2014-09-13 03:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 15:49 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-16 15:49 - 2014-07-17 04:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-16 15:49 - 2014-07-17 04:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-10-16 15:49 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll 2014-10-16 15:49 - 2014-07-17 03:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-10-16 15:49 - 2014-07-17 03:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2014-10-16 15:49 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-10-16 15:49 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-10-16 15:49 - 2014-07-17 03:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-16 15:49 - 2014-07-17 03:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-16 15:12 - 2014-10-16 15:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-16 14:56 - 2014-10-16 14:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-16 14:56 - 2014-09-26 18:42 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-16 14:56 - 2014-09-26 18:36 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-10-16 14:56 - 2014-09-26 18:36 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-10-16 14:56 - 2014-09-26 18:35 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-10-16 14:55 - 2014-10-16 14:56 - 00004930 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_71-b14.log 2014-10-05 14:20 - 2014-10-05 14:20 - 00002343 _____ () C:\Users\Public\Desktop\English G 21 e-Workbook D1.lnk 2014-10-05 14:20 - 2014-10-05 14:20 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Roaming\Cornelsen 2014-10-05 14:20 - 2014-10-05 14:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cornelsen 2014-10-05 14:20 - 2014-10-05 14:20 - 00000000 ____D () C:\Program Files (x86)\Cornelsen 2014-10-01 16:37 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-10-01 16:37 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-09-24 05:14 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-09-24 05:14 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-09-23 20:36 - 2014-09-23 20:36 - 01032856 _____ () C:\Users\Wurzbacher\Downloads\WhatsApp-Plus---Die-beste-Alternative-zu-WhatsApp-lnstall.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-18 16:35 - 2011-12-12 02:34 - 01915510 _____ () C:\Windows\WindowsUpdate.log 2014-10-18 16:34 - 2013-12-21 18:35 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-18 16:30 - 2014-09-15 05:01 - 00003875 _____ () C:\Windows\setupact.log 2014-10-18 16:30 - 2013-12-21 16:12 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-18 16:30 - 2010-11-21 05:47 - 01033074 _____ () C:\Windows\PFRO.log 2014-10-18 16:30 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-18 16:29 - 2012-07-26 20:25 - 00001005 _____ () C:\Users\Wurzbacher\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-10-18 16:29 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-18 16:29 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-18 16:17 - 2013-12-21 16:12 - 00001118 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-17 16:50 - 2011-11-04 13:32 - 00002476 ____N () C:\Users\Public\Desktop\WildTangent Games App - hp.lnk 2014-10-17 16:50 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-10-17 16:23 - 2012-07-26 20:25 - 00003970 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{AFFA8D60-5546-4ABA-A6F7-88FAD6D8F781} 2014-10-17 16:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-10-17 14:48 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-10-16 21:20 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-10-16 19:25 - 2012-07-28 14:13 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Local\CrashDumps 2014-10-16 19:23 - 2011-11-04 13:32 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games 2014-10-16 19:02 - 2011-11-04 21:53 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-10-16 19:02 - 2011-11-04 21:53 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-10-16 19:02 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-10-16 17:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-10-16 17:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-10-16 17:23 - 2009-07-14 06:45 - 00267816 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-16 17:21 - 2014-05-06 20:00 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-10-16 17:13 - 2013-08-25 10:52 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-16 17:01 - 2012-10-19 12:32 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-10-16 15:50 - 2013-01-16 19:05 - 00000000 ____D () C:\ProgramData\Netzmanager 2014-10-16 15:49 - 2013-01-16 19:05 - 00000000 __HDC () C:\ProgramData\{87B61FE8-334F-4066-B7AA-68DC81782D4D} 2014-10-16 15:35 - 2013-12-21 18:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-16 15:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-10-16 15:07 - 2014-08-16 10:19 - 00000000 ____D () C:\Users\Wurzbacher\Documents\Fotobuch Kroatien-Dateien 2014-10-16 15:04 - 2013-03-15 20:05 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-10-16 15:01 - 2012-07-28 18:07 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-10-16 15:00 - 2012-07-29 13:46 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Local\Adobe 2014-10-16 15:00 - 2012-07-26 18:56 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Roaming\Hewlett-Packard 2014-10-16 15:00 - 2011-12-12 02:36 - 00000000 ____D () C:\Windows\Hewlett-Packard 2014-10-16 15:00 - 2011-02-10 21:23 - 00000000 ____D () C:\SWSetup 2014-10-16 14:59 - 2013-12-21 18:35 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-10-16 14:59 - 2013-12-21 18:35 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-10-16 14:59 - 2013-12-21 18:35 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-10-16 14:56 - 2013-12-31 09:41 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-16 14:56 - 2013-03-15 20:28 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-15 05:34 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-10-14 08:27 - 2013-01-13 12:20 - 00003216 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForWurzbacher 2014-10-14 08:27 - 2013-01-13 12:20 - 00000352 _____ () C:\Windows\Tasks\HPCeeScheduleForWurzbacher.job 2014-10-11 17:14 - 2013-03-20 12:36 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-09-29 15:33 - 2012-07-26 15:42 - 00000000 ____D () C:\Users\Wurzbacher 2014-09-25 05:40 - 2013-12-21 16:12 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-09-24 19:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-09-23 21:06 - 2013-11-07 22:23 - 00000000 ____D () C:\Users\Wurzbacher\Documents\Klapp-Kalender-Dateien 2014-09-23 21:06 - 2013-09-04 21:41 - 00000000 ____D () C:\Users\Wurzbacher\Documents\Fotobuch 2-Dateien 2014-09-22 08:42 - 2010-11-21 05:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-09-19 05:10 - 2013-03-29 09:49 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk Some content of TEMP: ==================== C:\Users\Wurzbacher\AppData\Local\Temp\Quarantine.exe C:\Users\Wurzbacher\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-06 11:51 ==================== End Of Log ============================ --- --- --- |
19.10.2014, 08:37 | #9 |
/// the machine /// TB-Ausbilder | Windows 7 Rechner wird immer langsamer Malware gefundenESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.10.2014, 16:03 | #10 |
| Windows 7 Rechner wird immer langsamer Malware gefunden Hallo, hier die Logfiles: Eset: Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not read file from internet.ESETSmartInstaller@High as downloader log: Can not read file from internet.Can not read file from internet.ESETSmartInstaller@High as downloader log: Can not read file from internet.Can not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internet# product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=e2e100028ca8294e827d5b7ca38b965f # engine=20673 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-10-19 02:51:56 # local_time=2014-10-19 04:51:56 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Microsoft Security Essentials' # compatibility_mode=5895 16777213 100 100 3351106 55040032 0 0 # scanned=205905 # found=8 # cleaned=0 # scan_time=7352 sh=8992F72873D09212597E582A16F8D9BC60E6A22A ft=1 fh=e21391a34e842ffc vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Common Files\DVDVideoSoft\TB\ConduitInstaller.exe.vir" sh=97BCCD25561F44E9B13F05F6EEF083C9CE9BA529 ft=1 fh=641f1fb3d2e699c4 vn="Win32/Toolbar.Conduit.Y evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir" sh=E5AD99CE7C7362CA566156033ECB0F04F9437CA7 ft=1 fh=f45d83e01e1c8734 vn="Win32/Toolbar.Conduit.Q evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Wurzbacher\AppData\Local\Conduit\CT2625848\DVDVideoSoftTB_DEAutoUpdateHelper.exe.vir" sh=440BFDE1ED4E92F73052C8538FB044E39A18B94E ft=0 fh=0000000000000000 vn="HTML/ScrInject.B.Gen Virus" ac=I fn="C:\Users\Wurzbacher\AppData\Local\Mozilla\Firefox\Profiles\f24iiy18.default\cache2\entries\D3AACBD7306232F304FF5CA346189696D4717D43" sh=E8CD33623287C08C7CC3662A042E45522654BB30 ft=1 fh=7cd3b160b0dbd4bd vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Wurzbacher\Downloads\FreeYouTubeToMP3Converter.exe" sh=039C44D0FE8A6B6C47EB1DDBE62130862524A986 ft=1 fh=5fb54a730ae6b941 vn="Win32/OutBrowse.J evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Wurzbacher\Downloads\setup (7).exe" sh=3FC35E289E5453DE540D7F487F0202D49A4F8328 ft=1 fh=43e035895a955c83 vn="Variante von Win32/Adware.AddLyrics.A Anwendung" ac=I fn="C:\Users\Wurzbacher\Downloads\Update.exe" sh=729DD555EED31B11A34555096C580D3BAE14197E ft=1 fh=eab023279151abbd vn="Variante von Win32/WinloadSDA.G evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Wurzbacher\Downloads\WhatsApp-Plus---Die-beste-Alternative-zu-WhatsApp-lnstall.exe" Security Check: Code:
ATTFilter Results of screen317's Security Check version 0.99.87 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Spybot - Search & Destroy Wise Registry Cleaner 7.66 Java 7 Update 71 Java version out of Date! Adobe Flash Player 15.0.0.189 Adobe Reader XI Mozilla Firefox (33.0) Google Chrome 37.0.2062.120 Google Chrome 37.0.2062.124 ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe Spybot Teatimer.exe is disabled! `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-10-2014 01 Ran by Wurzbacher (administrator) on WURZBACHER-HP on 19-10-2014 16:57:59 Running from C:\Users\Wurzbacher\Desktop Loaded Profile: Wurzbacher (Available profiles: Wurzbacher) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 10 Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (HP) C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (AMD) C:\Windows\System32\atiesrxx.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (AMD) C:\Windows\System32\atieclxx.exe () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe (EasyBits Software AS) C:\Windows\SysWOW64\ezSharedSvcHost.exe (Hewlett-Packard Company) C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (HP) C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe (Deutsche Telekom AG) C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Easybits) C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2799912 2011-06-10] (Synaptics Incorporated) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation) HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-09-15] (EasyBits Software AS) HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [578944 2012-03-05] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Magic Desktop for HP notification] => C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe [1238016 2013-07-26] (Easybits) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-10-07] (Hewlett-Packard) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.) HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Policies\system: [DisableLockWorkstation] 0 HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Policies\system: [DisableChangePassword] 0 HKU\S-1-5-21-1447600568-1936789412-2989334194-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 BootExecute: autocheck autochk * sdnclean64.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {88AEA96D-C839-4D40-9888-4DC0F37C806E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms} SearchScopes: HKLM-x32 - {88AEA96D-C839-4D40-9888-4DC0F37C806E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms} SearchScopes: HKCU - {88AEA96D-C839-4D40-9888-4DC0F37C806E} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-111076-19270-3/4?mpre=hxxp://www.ebay.de/sch/i.html?_nkw={searchTerms} BHO: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard) BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: TrueSuite Website Log On -> {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} -> C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File ShellExecuteHooks-x32: EasyBits ShellExecute Hook - {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll [52920 2011-11-04] (EasyBits Software Corp.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll No File FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll () FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\searchplugins\webde-suche.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Wurzbacher\AppData\Roaming\Mozilla\Firefox\Profiles\f24iiy18.default\Extensions\trash [2014-09-23] FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com [2014-10-16] Chrome: ======= CHR DefaultSearchKeyword: Default -> conduit.search CHR DefaultSearchURL: Default -> hxxp://search.conduit.com/Results.aspx?ctid=CT3317742&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SP3CD6016B-6C2D-4D3F-A933-7579D01B4804&q={searchTerms}&SSPV= CHR DefaultSuggestURL: Default -> hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms} CHR Profile: C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-15] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-03] CHR Extension: (Website Logon) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfmogjcijkfeahcajecmmegieipfbdcc [2012-09-17] CHR Extension: (Google Wallet) - C:\Users\Wurzbacher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31] CHR HKLM-x32\...\Chrome\Extension: [bfmogjcijkfeahcajecmmegieipfbdcc] - C:\Program Files (x86)\HP SimplePass 2011\tschrome.crx [2011-08-18] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] () R2 ezSharedSvc; C:\Windows\SysWOW64\ezSharedSvcHost.exe [514232 2010-04-23] (EasyBits Software AS) [File not signed] S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [254016 2014-10-16] (WildTangent) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation) R2 Netzmanager Service; C:\Program Files\Netzmanager\NMInfraIS2\Netzmanager_Service.exe [2635776 2012-07-20] (Deutsche Telekom AG) [File not signed] R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 dgderdrv; C:\Windows\System32\drivers\dgderdrv.sys [20552 2010-07-30] (Devguru Co., Ltd) S3 dgderdrv; C:\Windows\SysWOW64\drivers\dgderdrv.sys [18120 2010-07-30] (Devguru Co., Ltd) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation) R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation) S3 ssudserd; C:\Windows\System32\DRIVERS\ssudserd.sys [203104 2012-09-19] (DEVGURU Co., LTD.(www.devguru.co.kr)) S3 TelekomNM6; C:\Program Files\Netzmanager\NMInfraIS2\Driver\TelekomNM6.sys [45664 2010-09-16] (Deutsche Telekom AG AG, Marmiko IT-Solutions GmbH) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-19 16:56 - 2014-10-19 16:56 - 00001065 _____ () C:\Users\Wurzbacher\Desktop\checkup.txt 2014-10-19 16:53 - 2014-10-19 16:53 - 00854417 _____ () C:\Users\Wurzbacher\Desktop\SecurityCheck.exe 2014-10-19 14:40 - 2014-10-19 14:40 - 02347384 _____ (ESET) C:\Users\Wurzbacher\Downloads\esetsmartinstaller_deu.exe 2014-10-18 16:38 - 2014-10-18 16:38 - 00027942 _____ () C:\Users\Wurzbacher\Desktop\Addition.txt 2014-10-18 16:37 - 2014-10-19 16:58 - 00017434 _____ () C:\Users\Wurzbacher\Desktop\FRST.txt 2014-10-18 16:37 - 2014-10-18 16:37 - 00000000 ____D () C:\Users\Wurzbacher\Desktop\FRST-OlderVersion 2014-10-18 16:36 - 2014-10-18 16:36 - 00003341 _____ () C:\Users\Wurzbacher\Desktop\JRT.txt 2014-10-18 16:34 - 2014-10-18 16:34 - 00000000 ____D () C:\Windows\ERUNT 2014-10-18 16:31 - 2014-10-18 16:31 - 00007628 _____ () C:\Users\Wurzbacher\Desktop\AdwCleaner[S0].txt 2014-10-18 16:28 - 2014-10-18 16:29 - 00000000 ____D () C:\AdwCleaner 2014-10-18 16:23 - 2014-10-18 16:23 - 00116486 _____ () C:\Users\Wurzbacher\Desktop\mbam.txt 2014-10-18 16:19 - 2014-10-18 16:19 - 00000000 ____D () C:\Users\Wurzbacher\Desktop\logs alt 2014-10-18 16:01 - 2014-10-19 14:37 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-10-18 16:01 - 2014-10-18 16:01 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-10-18 16:01 - 2014-10-18 16:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-10-18 16:01 - 2014-10-18 16:01 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-10-18 16:01 - 2014-10-18 16:01 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-10-18 16:01 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-10-18 16:01 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-10-18 16:01 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-10-18 15:59 - 2014-10-18 15:59 - 01705698 _____ (Thisisu) C:\Users\Wurzbacher\Downloads\JRT.exe 2014-10-18 15:59 - 2014-10-18 15:59 - 01705698 _____ (Thisisu) C:\Users\Wurzbacher\Desktop\JRT.exe 2014-10-18 15:59 - 2014-10-18 15:58 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Wurzbacher\Desktop\mbam-setup-2.0.3.1025.exe 2014-10-18 15:59 - 2014-10-18 15:58 - 01976320 _____ () C:\Users\Wurzbacher\Desktop\AdwCleaner_4.000.exe 2014-10-18 15:58 - 2014-10-18 15:58 - 01976320 _____ () C:\Users\Wurzbacher\Downloads\AdwCleaner_4.000.exe 2014-10-18 15:57 - 2014-10-18 15:58 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Wurzbacher\Downloads\mbam-setup-2.0.3.1025.exe 2014-10-17 18:14 - 2013-12-21 11:39 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-10-17 18:14 - 2013-12-21 09:56 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-10-17 18:04 - 2014-09-20 07:18 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-10-17 18:04 - 2014-09-20 07:17 - 02236928 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-10-17 18:04 - 2014-09-20 07:17 - 01407488 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 19280896 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 15399424 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 03959296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 02655232 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-10-17 18:04 - 2014-09-20 07:16 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-10-17 18:04 - 2014-09-20 07:15 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-10-17 18:04 - 2014-09-20 07:15 - 00451584 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-10-17 18:04 - 2014-09-20 07:15 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 14368768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 13757952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 02861568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 02055168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 01762816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 01180672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-10-17 18:04 - 2014-09-20 05:57 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-10-17 18:04 - 2014-09-20 05:56 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-10-17 18:04 - 2014-09-20 05:56 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-10-17 18:04 - 2014-09-20 05:56 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-10-17 18:04 - 2014-09-20 05:38 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-10-17 18:04 - 2014-09-20 05:33 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-10-17 18:04 - 2014-09-20 04:43 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2014-10-17 18:04 - 2014-09-20 04:35 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2014-10-17 14:50 - 2014-10-17 14:50 - 00017649 _____ () C:\ComboFix.txt 2014-10-17 14:39 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-10-17 14:39 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-10-17 14:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe 2014-10-17 14:39 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe 2014-10-17 14:38 - 2014-10-17 14:50 - 00000000 ____D () C:\Qoobox 2014-10-17 14:38 - 2014-10-17 14:49 - 00000000 ____D () C:\Windows\erdnt 2014-10-17 14:36 - 2014-10-17 14:37 - 05583559 ____R (Swearware) C:\Users\Wurzbacher\Desktop\ComboFix.exe 2014-10-16 17:45 - 2014-07-07 04:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2014-10-16 17:45 - 2014-07-07 04:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll 2014-10-16 17:45 - 2014-07-07 04:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll 2014-10-16 17:45 - 2014-07-07 04:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll 2014-10-16 17:45 - 2014-07-07 04:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll 2014-10-16 17:45 - 2014-07-07 03:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll 2014-10-16 17:45 - 2014-07-07 03:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll 2014-10-16 17:44 - 2014-08-19 05:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2014-10-16 17:44 - 2014-08-19 05:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2014-10-16 17:44 - 2014-08-19 05:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2014-10-16 17:44 - 2014-08-19 05:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll 2014-10-16 17:44 - 2014-08-19 05:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2014-10-16 17:44 - 2014-08-19 05:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2014-10-16 17:44 - 2014-08-19 05:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe 2014-10-16 17:44 - 2014-08-19 05:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll 2014-10-16 17:44 - 2014-08-19 05:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll 2014-10-16 17:44 - 2014-08-19 05:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe 2014-10-16 17:44 - 2014-08-19 04:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll 2014-10-16 17:44 - 2014-08-19 04:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2014-10-16 17:44 - 2014-08-19 04:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys 2014-10-16 17:44 - 2014-07-07 04:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-10-16 17:44 - 2014-07-07 04:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe 2014-10-16 17:44 - 2014-07-07 04:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe 2014-10-16 17:44 - 2014-07-07 04:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2014-10-16 17:44 - 2014-07-07 04:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2014-10-16 17:44 - 2014-07-07 04:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2014-10-16 17:44 - 2014-07-07 04:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2014-10-16 17:44 - 2014-07-07 04:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2014-10-16 17:44 - 2014-07-07 04:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll 2014-10-16 17:44 - 2014-07-07 03:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys 2014-10-16 17:44 - 2014-07-07 03:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2014-10-16 17:44 - 2014-07-07 03:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2014-10-16 17:44 - 2014-07-07 03:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2014-10-16 17:44 - 2014-07-07 03:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2014-10-16 17:44 - 2014-07-07 03:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-10-16 17:44 - 2014-07-07 03:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-10-16 17:44 - 2014-07-07 03:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe 2014-10-16 17:44 - 2014-07-07 03:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe 2014-10-16 17:44 - 2014-07-07 03:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll 2014-10-16 17:44 - 2014-06-28 02:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2014-10-16 17:44 - 2014-06-28 02:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2014-10-16 17:44 - 2014-06-28 02:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll 2014-10-16 17:16 - 2014-10-18 16:37 - 02112000 _____ (Farbar) C:\Users\Wurzbacher\Desktop\FRST64.exe 2014-10-16 15:56 - 2014-10-16 15:57 - 00033995 _____ () C:\Users\Wurzbacher\Downloads\Addition.txt 2014-10-16 15:55 - 2014-10-19 16:58 - 00000000 ____D () C:\FRST 2014-10-16 15:55 - 2014-10-16 15:57 - 00031556 _____ () C:\Users\Wurzbacher\Downloads\FRST.txt 2014-10-16 15:54 - 2014-10-16 15:54 - 02111488 _____ (Farbar) C:\Users\Wurzbacher\Downloads\FRST64.exe 2014-10-16 15:51 - 2014-09-29 02:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-10-16 15:50 - 2014-10-16 15:50 - 00001009 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Netzmanager.lnk 2014-10-16 15:50 - 2014-10-16 15:50 - 00001003 _____ () C:\Users\Public\Desktop\Netzmanager.lnk 2014-10-16 15:50 - 2014-10-16 15:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Netzmanager 2014-10-16 15:50 - 2014-10-16 15:50 - 00000000 ____D () C:\Program Files\Netzmanager 2014-10-16 15:50 - 2014-10-10 04:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-10-16 15:50 - 2014-10-10 04:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2014-10-16 15:50 - 2014-10-10 04:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-10-16 15:50 - 2014-09-18 04:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2014-10-16 15:50 - 2014-09-18 03:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2014-10-16 15:50 - 2014-09-04 07:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll 2014-10-16 15:50 - 2014-09-04 07:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll 2014-10-16 15:50 - 2014-07-17 03:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2014-10-16 15:50 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL 2014-10-16 15:50 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL 2014-10-16 15:50 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL 2014-10-16 15:50 - 2014-07-09 04:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL 2014-10-16 15:50 - 2014-07-09 04:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL 2014-10-16 15:50 - 2014-07-09 03:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL 2014-10-16 15:50 - 2014-07-09 00:38 - 00419992 _____ () C:\Windows\system32\locale.nls 2014-10-16 15:50 - 2014-07-09 00:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls 2014-10-16 15:50 - 2014-06-19 00:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll 2014-10-16 15:50 - 2014-06-19 00:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll 2014-10-16 15:49 - 2014-10-16 15:50 - 00000000 __HDC () C:\ProgramData\{BA58D0EE-89D1-4191-9F19-B6AD920B04F7} 2014-10-16 15:49 - 2014-09-13 03:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll 2014-10-16 15:49 - 2014-09-13 03:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2014-10-16 15:49 - 2014-07-17 04:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-10-16 15:49 - 2014-07-17 04:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-10-16 15:49 - 2014-07-17 04:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-10-16 15:49 - 2014-07-17 03:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll 2014-10-16 15:49 - 2014-07-17 03:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2014-10-16 15:49 - 2014-07-17 03:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2014-10-16 15:49 - 2014-07-17 03:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-10-16 15:49 - 2014-07-17 03:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-10-16 15:49 - 2014-07-17 03:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys 2014-10-16 15:49 - 2014-07-17 03:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys 2014-10-16 15:12 - 2014-10-16 15:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-10-16 14:56 - 2014-10-16 14:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2014-10-16 14:56 - 2014-09-26 18:42 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-10-16 14:56 - 2014-09-26 18:36 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-10-16 14:56 - 2014-09-26 18:36 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-10-16 14:56 - 2014-09-26 18:35 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-10-16 14:55 - 2014-10-16 14:56 - 00004930 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_71-b14.log 2014-10-05 14:20 - 2014-10-05 14:20 - 00002343 _____ () C:\Users\Public\Desktop\English G 21 e-Workbook D1.lnk 2014-10-05 14:20 - 2014-10-05 14:20 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Roaming\Cornelsen 2014-10-05 14:20 - 2014-10-05 14:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cornelsen 2014-10-05 14:20 - 2014-10-05 14:20 - 00000000 ____D () C:\Program Files (x86)\Cornelsen 2014-10-01 16:37 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll 2014-10-01 16:37 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll 2014-09-24 05:14 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2014-09-24 05:14 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2014-09-23 20:36 - 2014-09-23 20:36 - 01032856 _____ () C:\Users\Wurzbacher\Downloads\WhatsApp-Plus---Die-beste-Alternative-zu-WhatsApp-lnstall.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-19 16:34 - 2013-12-21 18:35 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-10-19 16:17 - 2013-12-21 16:12 - 00001118 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-10-19 16:17 - 2013-12-21 16:12 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-10-19 15:58 - 2011-12-12 02:34 - 01976898 _____ () C:\Windows\WindowsUpdate.log 2014-10-19 14:44 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-10-19 14:44 - 2009-07-14 06:45 - 00031856 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-10-19 14:36 - 2014-09-15 05:01 - 00004099 _____ () C:\Windows\setupact.log 2014-10-19 14:36 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-10-18 18:56 - 2012-07-26 20:25 - 00003970 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{AFFA8D60-5546-4ABA-A6F7-88FAD6D8F781} 2014-10-18 17:07 - 2013-01-13 12:20 - 00000352 _____ () C:\Windows\Tasks\HPCeeScheduleForWurzbacher.job 2014-10-18 16:42 - 2013-03-20 12:36 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt 2014-10-18 16:42 - 2013-01-13 12:20 - 00003216 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForWurzbacher 2014-10-18 16:42 - 2012-07-28 18:07 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log 2014-10-18 16:30 - 2010-11-21 05:47 - 01033074 _____ () C:\Windows\PFRO.log 2014-10-18 16:29 - 2012-07-26 20:25 - 00001005 _____ () C:\Users\Wurzbacher\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2014-10-17 16:50 - 2011-11-04 13:32 - 00002476 ____N () C:\Users\Public\Desktop\WildTangent Games App - hp.lnk 2014-10-17 16:50 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-10-17 16:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-10-17 14:48 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini 2014-10-16 21:20 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2014-10-16 19:25 - 2012-07-28 14:13 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Local\CrashDumps 2014-10-16 19:23 - 2011-11-04 13:32 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games 2014-10-16 19:02 - 2011-11-04 21:53 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-10-16 19:02 - 2011-11-04 21:53 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-10-16 19:02 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-10-16 17:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism 2014-10-16 17:49 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism 2014-10-16 17:23 - 2009-07-14 06:45 - 00267816 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-10-16 17:21 - 2014-05-06 20:00 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-10-16 17:13 - 2013-08-25 10:52 - 00000000 ____D () C:\Windows\system32\MRT 2014-10-16 17:01 - 2012-10-19 12:32 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-10-16 15:50 - 2013-01-16 19:05 - 00000000 ____D () C:\ProgramData\Netzmanager 2014-10-16 15:49 - 2013-01-16 19:05 - 00000000 __HDC () C:\ProgramData\{87B61FE8-334F-4066-B7AA-68DC81782D4D} 2014-10-16 15:35 - 2013-12-21 18:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-10-16 15:34 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-10-16 15:07 - 2014-08-16 10:19 - 00000000 ____D () C:\Users\Wurzbacher\Documents\Fotobuch Kroatien-Dateien 2014-10-16 15:04 - 2013-03-15 20:05 - 00000000 ____D () C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-10-16 15:00 - 2012-07-29 13:46 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Local\Adobe 2014-10-16 15:00 - 2012-07-26 18:56 - 00000000 ____D () C:\Users\Wurzbacher\AppData\Roaming\Hewlett-Packard 2014-10-16 15:00 - 2011-12-12 02:36 - 00000000 ____D () C:\Windows\Hewlett-Packard 2014-10-16 15:00 - 2011-02-10 21:23 - 00000000 ____D () C:\SWSetup 2014-10-16 14:59 - 2013-12-21 18:35 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-10-16 14:59 - 2013-12-21 18:35 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-10-16 14:59 - 2013-12-21 18:35 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-10-16 14:56 - 2013-12-31 09:41 - 00000000 ____D () C:\ProgramData\Oracle 2014-10-16 14:56 - 2013-03-15 20:28 - 00000000 ____D () C:\Program Files (x86)\Java 2014-10-15 05:34 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-09-29 15:33 - 2012-07-26 15:42 - 00000000 ____D () C:\Users\Wurzbacher 2014-09-25 05:40 - 2013-12-21 16:12 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-09-24 19:25 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache 2014-09-23 21:06 - 2013-11-07 22:23 - 00000000 ____D () C:\Users\Wurzbacher\Documents\Klapp-Kalender-Dateien 2014-09-23 21:06 - 2013-09-04 21:41 - 00000000 ____D () C:\Users\Wurzbacher\Documents\Fotobuch 2-Dateien 2014-09-22 08:42 - 2010-11-21 05:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-09-19 05:10 - 2013-03-29 09:49 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk Some content of TEMP: ==================== C:\Users\Wurzbacher\AppData\Local\Temp\Quarantine.exe C:\Users\Wurzbacher\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-10-06 11:51 ==================== End Of Log ============================ --- --- --- Wie sieht's aus ist noch was an Malware drauf? Mfg |
20.10.2014, 10:50 | #11 |
/// the machine /// TB-Ausbilder | Windows 7 Rechner wird immer langsamer Malware gefunden Java updaten. Download Ordner leeren. Revo Uninstaller - Download - Filepony damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren. Dann: https://support.mozilla.org/de/kb/fi...einfach-loesen Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
20.10.2014, 13:48 | #12 |
| Windows 7 Rechner wird immer langsamer Malware gefunden Hallo, habe alles in der Reihenfolge abgearbeitet. Leider habe ich die fixlog.txt gelöscht als ich delfix gestartet habe sorry. Jetzt funktioniert wieder alles. Danke für die schnelle und unkomplizierte Hilfe. kann geschlossen werden |
21.10.2014, 08:36 | #13 |
/// the machine /// TB-Ausbilder | Windows 7 Rechner wird immer langsamer Malware gefunden Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |