![]() |
|
Log-Analyse und Auswertung: Pricemeter und andere SoftwareWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Pricemeter und andere Software Hallo zusammen, seit kurzem lief die Pricemeter und andere unerwünschte Software auf meinem Rechner. Zunächst habe ich versucht, diese Software über die Systemsteuerung zu löschen. Dies blieb jedoch ohne Erfolg. Ich bin nun nach der Anleitung "PriceMeter Virus entfernen" vorgegangen. Hier die Log-Files. Vorab schon mal vielen Dank für Eure Hilfe. Grüße Thorsten mbam Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 20.12.2014 Suchlauf-Zeit: 20:46:34 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2014.12.20.05 Rootkit Datenbank: v2014.12.14.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Barbara Kleere Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 337264 Verstrichene Zeit: 6 Min, 54 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 2 PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Local\PriceMeter\pricemeterw.exe, 2400, Löschen bei Neustart, [44d1dd88790321158ecbd5b6827f5da3] PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe, 2952, Löschen bei Neustart, [bc5940256c1065d1ec5143e58083fd03] Module: 1 PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdate.dll, Löschen bei Neustart, [bc5940256c1065d1ec5143e58083fd03], Registrierungsschlüssel: 72 PUP.Optional.Snapdo.T, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [24f181e43943ce680331e82924dfb54b], PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [24f181e43943ce680331e82924dfb54b], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickCtrl.9, In Quarantäne, [997c9fc689f33df923fa4745d52e2cd4], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine, In Quarantäne, [8c89fc69e09ca690eb32a7e5fc07c33d], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0, In Quarantäne, [44d1b7ae3f3d66d047d65f2d09faf10f], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.Update3WebControl.3, In Quarantäne, [37de244196e665d108140f7dd92a56aa], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync, In Quarantäne, [4fc62c3917653ff754c91a72b54e4db3], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0, In Quarantäne, [68ad96cf9be164d29e7f4f3d34cf9c64], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass, In Quarantäne, [de377ce9dca0ea4ce934602cab587b85], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass.1, In Quarantäne, [0a0b94d11e5ec86e58c58408df24ab55], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass, In Quarantäne, [52c323428cf0a591cc51167627dc1fe1], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass.1, In Quarantäne, [66afd88d344834028c91f29aac57e61a], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine, In Quarantäne, [27eeca9b7a0244f23de0deaee1228a76], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0, In Quarantäne, [37def372c0bc3204c459d5b7f80b847c], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine, In Quarantäne, [ea2b74f1fd7f59ddd548008cde256d93], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [060fb0b5186442f459c4ddafad56619f], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [8491f174e993c47237e6a2ea06fd8c74], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [9d785a0bbfbdab8b7e9fc6c633d02bd5], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc, In Quarantäne, [e33232339fdd41f57da07d0f699ac040], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [db3a263f2e4eb87ebc6155377a894ab6], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher, In Quarantäne, [38dd6302621a74c278a50785f3109d63], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0, In Quarantäne, [3ed7c2a3fb81f541a37ae3a9ad56bf41], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService, In Quarantäne, [5db8d095b9c33105af6e13794cb7e31d], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0, In Quarantäne, [49cc77eeed8f40f6bc61eaa263a01ee2], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine, In Quarantäne, [71a46ef76b111224e13c018b7c87b749], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0, In Quarantäne, [31e4095c5a226fc7eb32513b4bb8f907], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback, In Quarantäne, [e1342045e597b5818c91d3b91ee513ed], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [e82d204584f8181e0c117f0d956eb947], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc, In Quarantäne, [93824025d5a73df9e73691fbda299d63], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0, In Quarantäne, [58bdef768eeec076829bee9e25de7888], PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\DealPlyLive, In Quarantäne, [33e2c0a50676a4926fdce4cc758f649c], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickCtrl.9, In Quarantäne, [3cd9f2735f1df343ac715f2dc142eb15], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine, In Quarantäne, [8e87dd88493347ef30edc2ca867dc63a], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0, In Quarantäne, [32e3e283007cc571120b7d0fe71ce41c], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.Update3WebControl.3, In Quarantäne, [24f140251b6193a3d14b4d3f6c9701ff], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync, In Quarantäne, [3dd84b1a1765d4623de0325a0af9f50b], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0, In Quarantäne, [ff16481dcfad1a1ca776820a20e33ac6], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass, In Quarantäne, [b85dbbaa295357df7f9e2963966d8878], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass.1, In Quarantäne, [92834c1999e30f271607602cd1328080], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass, In Quarantäne, [20f5f174621a9e98f9247a12f40f36ca], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass.1, In Quarantäne, [1500dc8924587abc23fa6b2112f1ea16], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine, In Quarantäne, [c84df075d9a32b0bed304b4133d056aa], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0, In Quarantäne, [5db81a4b166671c50c1196f6e41f54ac], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine, In Quarantäne, [41d4b8ad324a93a3e03d3d4f2ad9946c], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [6ca979ec245870c6011c96f61fe4c63a], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [bd58e085f18b10263ae3beced82b0af6], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [5abb0f5625574bebfc21404c768de31d], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc, In Quarantäne, [73a2560f78041026ac715b314fb45fa1], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [29ec70f582fa6fc7829b068608fb48b8], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher, In Quarantäne, [73a25c09a7d52412011c14788e753ac6], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0, In Quarantäne, [789de77eafcd092d41dc414b7a8947b9], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService, In Quarantäne, [ab6ac2a38af2e650a97474187e859a66], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0, In Quarantäne, [13027ee7710ba6906db0028ac63d8f71], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine, In Quarantäne, [1afbc69f3745e2540716c0cc12f107f9], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0, In Quarantäne, [26ef4025b5c760d6e9341874fd0611ef], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback, In Quarantäne, [bc59df86c6b6d95d5ac31379bd465ca4], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [0015e3825a220c2a65b8622acf349f61], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc, In Quarantäne, [32e3362f4d2f64d277a6b6d6a55e7b85], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0, In Quarantäne, [69ac0d58b4c8a29498852e5eeb18bf41], PUP.Optional.PriceMeter.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\PriceMeter, In Quarantäne, [02134b1a81fb6bcb8c98cebe22e1ee12], PUP.Optional.StormWatchApp.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\StormWatchApp, In Quarantäne, [1ff62e372f4d4ee85eb12a361de6e818], PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, In Quarantäne, [c0557fe62854f34366d201cf25dfa25e], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\PRICEMETERLIVEUPDATE.EXE, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\PRICEMETERLIVEUPDATE.EXE, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{89449F37-4AB2-46ED-A566-BB3A7797701B}, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89449F37-4AB2-46ED-A566-BB3A7797701B}, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{89449F37-4AB2-46ED-A566-BB3A7797701B}, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F509ADC2-B40E-470F-A7B7-45191486B5CB}, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F509ADC2-B40E-470F-A7B7-45191486B5CB}, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{F509ADC2-B40E-470F-A7B7-45191486B5CB}, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4211E851-747F-4470-923D-6EF683EE79CA}, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{74930D00-2198-46FE-B6BC-FEEC60C666C9}, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], Registrierungswerte: 5 PUP.Optional.PriceMeter.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PriceMeterW, "C:\Users\Barbara Kleere\AppData\Local\PriceMeter\pricemeterw.exe", In Quarantäne, [44d1dd88790321158ecbd5b6827f5da3] PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [6da8b7ae98e49d99b39333357b8840c0] PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [c64fc89d1c6079bd3c0aff697e8533cd] PUP.Optional.Snapdo.T, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [7b9a5c095d1f3afc4d9489e8cc3736ca] PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, ShoppingHelper, In Quarantäne, [c0557fe62854f34366d201cf25dfa25e] Registrierungsdaten: 7 PUP.Optional.SnapDo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGak,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGak,&q={searchTerms}),Ersetzt,[c055e67fa0dc979f78757febf60f28d8] PUP.Optional.SnapDo.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}),Ersetzt,[73a2293c92ea46f02ac62b3f7d8803fd] PUP.Optional.SnapDo.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxaDFFkTCxbn60Xc_GtEpZywM72yoB2qaKdRCwNYAUk1eH0N47rzStEGiRySkJs,, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxaDFFkTCxbn60Xc_GtEpZywM72yoB2qaKdRCwNYAUk1eH0N47rzStEGiRySkJs,),Ersetzt,[92835e0743393cfa47aa7af0e91c619f] PUP.Optional.SnapDo.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}),Ersetzt,[2ce9eb7a5c20f6407a756bff828320e0] PUP.Optional.SnapDo.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}),Ersetzt,[849170f558240f2739b93634030242be] PUP.Optional.SnapDo.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}),Ersetzt,[987dc4a1ccb0d06680735416699c26da] PUP.Optional.SnapDo.A, HKU\S-1-5-21-249174616-3516237891-290196828-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q={searchTerms}),Ersetzt,[8a8b9cc9205cb383f5f9bab0fa0bf50b] Ordner: 14 PUP.Optional.VOPackage, C:\Users\Barbara Kleere\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage, In Quarantäne, [dc393f26afcdd95dbc87b3be09fa837d], PUP.Optional.OpenCandy, C:\Users\Barbara Kleere\AppData\Roaming\OpenCandy, In Quarantäne, [f5200f56304ca591840edd44c73c23dd], PUP.Optional.OpenCandy, C:\Users\Barbara Kleere\AppData\Roaming\OpenCandy\906ABE6AB58A41B7BCD5BA22258D91E2, In Quarantäne, [f5200f56304ca591840edd44c73c23dd], PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Roaming\PriceMeterUpdater, In Quarantäne, [45d05f06e696e05675c72afe06fd8d73], PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Roaming\PriceMeterUpdater\UpdateProc, In Quarantäne, [45d05f06e696e05675c72afe06fd8d73], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate, Löschen bei Neustart, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\CrashReports, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update, Löschen bei Neustart, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0, Löschen bei Neustart, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Download, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Install, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Offline, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Offline\{CF4F21D4-5CA9-4A73-91E7-90BB2A0697F0}, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Local\PriceMeter, Löschen bei Neustart, [8f862c393d3f3ef899a72dfb63a03cc4], Dateien: 83 PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Local\PriceMeter\pricemeterw.exe, Löschen bei Neustart, [44d1dd88790321158ecbd5b6827f5da3], PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Roaming\OpenCandy\906ABE6AB58A41B7BCD5BA22258D91E2\pm.exe, In Quarantäne, [a86d2d382c50b0868da7464146bbf808], PUP.Optional.Bestop, C:\Users\Barbara Kleere\AppData\Local\Temp\ICReinstall_FlvPlayerSetup.exe, In Quarantäne, [a075fb6a89f3b5812eec1a4a12f3b54b], PUP.Optional.FlvPlayer, C:\Users\Barbara Kleere\AppData\Local\Temp\is135831044\6CF59B58_stp.EXE, In Quarantäne, [df3665002a52ac8a4dde23aad230bb45], PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Local\PriceMeter\pricemeter.exe, In Quarantäne, [cf4676ef0b7140f64c0d0f7c0bf6de22], PUP.Optional.VOPackage, C:\Users\Barbara Kleere\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage\Configure.lnk, In Quarantäne, [dc393f26afcdd95dbc87b3be09fa837d], PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\pricemetertask, In Quarantäne, [d3424f16403c49ed2a41245290739e62], PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore, In Quarantäne, [3adb89dce5973cfa214c1c5a956e4db3], PUP.Optional.PriceMeter.A, C:\Windows\System32\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA, In Quarantäne, [af66263fd8a40b2bc9a4265007fcef11], PUP.Optional.VOPackage.A, C:\Users\Barbara Kleere\AppData\Roaming\VOPackage\VOPackage.exe, In Quarantäne, [f2232f36522a41f530116c1616ed7888], PUP.Optional.PriceMeter.A, C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job, In Quarantäne, [f520cf96790391a564ba8a02ef14f10f], PUP.Optional.PriceMeter.A, C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job, In Quarantäne, [2ce92045b1cb37ff51cd3359b84b30d0], PUP.Optional.WebSearch.A, C:\Users\Barbara Kleere\AppData\Roaming\Mozilla\Firefox\Profiles\hbfpzoq7.default\searchplugins\Web Search.xml, In Quarantäne, [e134353046361224c066f09f5ea550b0], PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Roaming\PriceMeterUpdater\UpdateProc\config.dat, In Quarantäne, [45d05f06e696e05675c72afe06fd8d73], PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Roaming\PriceMeterUpdater\UpdateProc\info.dat, In Quarantäne, [45d05f06e696e05675c72afe06fd8d73], PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Roaming\PriceMeterUpdater\UpdateProc\STTL.DAT, In Quarantäne, [45d05f06e696e05675c72afe06fd8d73], PUP.Optional.PriceMeter.A, C:\Users\Barbara Kleere\AppData\Roaming\PriceMeterUpdater\UpdateProc\TTL.DAT, In Quarantäne, [45d05f06e696e05675c72afe06fd8d73], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe, Löschen bei Neustart, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_de.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_el.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_en-GB.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_en.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_es-419.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_es.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_et.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fa.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fi.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fil.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fr.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_gu.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hi.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hr.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hu.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_id.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_it.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_iw.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ja.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_kn.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ko.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_lt.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_lv.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ml.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_mr.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ms.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_nl.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_no.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pl.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pt-BR.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pt-PT.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ro.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdate.dll, Löschen bei Neustart, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_am.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ar.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_bg.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_bn.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ca.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_cs.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sk.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sl.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sr.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sv.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sw.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ta.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_te.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_th.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_tr.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_uk.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ur.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_vi.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_zh-CN.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_zh-TW.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdate.exe, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateBroker.exe, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateHandler.exe, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateHelper.msi, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateOnDemand.exe, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\psmachine.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\psuser.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_da.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_is.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ru.dll, In Quarantäne, [bc5940256c1065d1ec5143e58083fd03], PUP.Optional.SnapDo.A, C:\Users\Barbara Kleere\AppData\Roaming\Mozilla\Firefox\Profiles\hbfpzoq7.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIwXmXQDOIeUFf-euUxUBJPsRzHBzgFHD3KQ9Jv4j2TB347SF3La3zBGa4,&q=");), Ersetzt,[b362e97c512b48ee3c1f149931d4768a] Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) AdwCleaner Code:
ATTFilter # AdwCleaner v4.105 - Bericht erstellt am 20/12/2014 um 21:01:53 # Aktualisiert 08/12/2014 von Xplode # Database : 2014-12-16.1 [Live] # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Barbara Kleere - BÜRO_EG # Gestartet von : C:\Users\Barbara Kleere\Desktop\AdwCleaner_4.105.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\PriceMeterLiveUpdate Ordner Gelöscht : C:\Users\Barbara Kleere\AppData\Local\PriceMeterLiveUpdate Ordner Gelöscht : C:\Users\Barbara Kleere\AppData\Local\CrashRpt Ordner Gelöscht : C:\Users\Barbara Kleere\AppData\Roaming\pdfforge Ordner Gelöscht : C:\Users\Barbara Kleere\AppData\Roaming\VOPackage ***** [ Tasks ] ***** Task Gelöscht : pricemetertask ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\PriceMeterLiveUpdate.exe Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=3 Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=9 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{126C78A0-36E7-4697-A3AB-32706144398B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{8D73A258-9787-4AE7-9232-41036673FD0E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00A154AE-6C33-4F1E-9057-242350540936} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{126C78A0-36E7-4697-A3AB-32706144398B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30D1E30D-B7F5-4C7A-8EDA-9F02966538A8} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{41C35ADE-DEDA-439F-8140-D53F2C76C963} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{45F8961E-1314-421E-9F00-BDDE18CF8EA0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4825ACAD-F495-4CDD-9603-9C91BABB2B88} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5B60D1C0-453A-485D-AE91-61FAC9203719} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8D73A258-9787-4AE7-9232-41036673FD0E} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9D24562E-40EC-4E46-B57C-700352059B55} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B1F29F0C-2EC8-487B-97C2-8B8FEA6CEF14} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C0756D99-64A1-4332-B783-A5A1B571D431} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CF0A778A-DDA0-4492-9804-EF38C9A9F1A5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D1C6444C-CC06-4060-A486-736DEAFD9C16} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D8746A3A-A372-4C8B-96E5-B58F6474EB19} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{30D1E30D-B7F5-4C7A-8EDA-9F02966538A8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472F-A0FF-E1416B8B2E3A} Schlüssel Gelöscht : HKCU\Software\PriceMeterLiveUpdate Schlüssel Gelöscht : HKCU\Software\PriceMeterUpdater Schlüssel Gelöscht : HKLM\SOFTWARE\PriceMeterLiveUpdate Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467 ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17416 -\\ Mozilla Firefox v34.0.5 (x86 de) [hbfpzoq7.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search"); [hbfpzoq7.default\prefs.js] - Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZLLx3LpAeVW-lRGGSHpxmTbfKJHlnyK_aDwNHQTYmf-siGbws3NtgpS5YShEidOdf5wfEuV69m_x89ZB2VUYLS7jp2qz-gqs8I3AGxqhCZIw[...] -\\ Google Chrome v [C:\Users\Barbara Kleere\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://de.ask.com/web?q={searchTerms} ************************* AdwCleaner[R0].txt - [4434 octets] - [20/12/2014 21:00:24] AdwCleaner[S0].txt - [4234 octets] - [20/12/2014 21:01:53] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4294 octets] ########## JRT Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.0 (11.29.2014:1) OS: Windows 8.1 x64 Ran by Barbara Kleere on 20.12.2014 at 21:04:52,80 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20.12.2014 at 21:06:15,12 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ sc-cleaner Code:
ATTFilter Shortcut Cleaner 1.3.4 by Lawrence Abrams (Grinler) hxxp://www.bleepingcomputer.com/ Copyright 2008-2014 BleepingComputer.com More Information about Shortcut Cleaner can be found at this link: hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/ Windows Version: Windows 8.1 Program started at: 12/20/2014 09:07:31 PM. Scanning for registry hijacks: * No issues found in the Registry. Searching for Hijacked Shortcuts: Searching C:\Users\Barbara Kleere\AppData\Roaming\Microsoft\Windows\Start Menu\ Searching C:\ProgramData\Microsoft\Windows\Start Menu\ Searching C:\Users\Barbara Kleere\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\ Searching C:\Users\Public\Desktop\ Searching C:\Users\Barbara Kleere\Desktop 0 bad shortcuts found. Program finished at: 12/20/2014 09:07:31 PM Execution time: 0 hours(s), 0 minute(s), and 0 seconds(s) Eset Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=be7d947cbd17d343bc4bfc72cf963211 # engine=21650 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-12-20 08:42:01 # local_time=2014-12-20 09:42:01 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='Kaspersky PURE 3.0' # compatibility_mode=1289 16777214 100 99 2312 111357789 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 2717432 43989414 0 0 # scanned=204189 # found=12 # cleaned=0 # scan_time=1756 sh=48F867C4395BB577CB7983D37C10B02FD9399179 ft=1 fh=9b812e24d02fa239 vn="Variante von Win32/VOPackage.BD evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Microsoft\Windows\INetCache\IE\BJ5B0DLM\dl[1].htm" sh=63B02B87A6ED801D990F31A00751C2B854409DAF ft=1 fh=a9839698103bfe44 vn="Variante von Win32/TrojanDropper.MsiDrop.B Trojaner" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Microsoft\Windows\INetCache\IE\BJ5B0DLM\Installer[1].exe" sh=1B04BEAB8809408148333E3B4D40F719A73BBAC5 ft=1 fh=993133e3e4342124 vn="Win32/Verti.K evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Microsoft\Windows\INetCache\IE\BJ5B0DLM\StormWatchSetup[1].exe" sh=E5057D9A7C1A00EEA9FB785664D524322941808B ft=1 fh=c71c0011335af664 vn="Variante von MSIL/Adware.iBryte.N Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Microsoft\Windows\INetCache\IE\DKF72J1Y\rt-installer[1].exe" sh=C68C1E6B04552799D818FFEFA4AE388FF1E452F7 ft=1 fh=d5ad8c706392f543 vn="Variante von Win32/InstallCore.QR evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Microsoft\Windows\INetCache\IE\PH58O2NS\Setup[1].exe" sh=187C2FCA13A753292A1103766DB9610913330E87 ft=1 fh=67533e3a6392f543 vn="Variante von Win32/InstallCore.QR evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Microsoft\Windows\INetCache\IE\PH58O2NS\Setup[2].exe" sh=CC9E67A9F2E1C96CA6BD55C70A721E516ABAFE4A ft=1 fh=5c9d4d294dba47e9 vn="Variante von Win32/Speedchecker.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Microsoft\Windows\INetCache\IE\Y7JSDTEO\pcspeedup[1].exe" sh=F2251A7A386675FE43902ADC0525D33672C8BB84 ft=1 fh=e069b17bc5bd2e6a vn="Win32/VOPackage.AZ evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Microsoft\Windows\INetCache\IE\Y7JSDTEO\VOPackage_1712[1].exe" sh=187C2FCA13A753292A1103766DB9610913330E87 ft=1 fh=67533e3a6392f543 vn="Variante von Win32/InstallCore.QR evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Temp\ICReinstall_nsb8F69.tmp" sh=C68C1E6B04552799D818FFEFA4AE388FF1E452F7 ft=1 fh=d5ad8c706392f543 vn="Variante von Win32/InstallCore.QR evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Temp\ICReinstall_nsh4002.tmp" sh=187C2FCA13A753292A1103766DB9610913330E87 ft=1 fh=67533e3a6392f543 vn="Variante von Win32/InstallCore.QR evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Temp\nsb8F69.tmp" sh=C68C1E6B04552799D818FFEFA4AE388FF1E452F7 ft=1 fh=d5ad8c706392f543 vn="Variante von Win32/InstallCore.QR evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Barbara Kleere\AppData\Local\Temp\nsh4002.tmp" |