![]() |
|
Log-Analyse und Auswertung: Windows 10: PUP.Adware.HeuristicWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
![]() | #1 |
| ![]() Windows 10: PUP.Adware.Heuristic Hallo zusammen, seit ein paar Monaten hat sich hin und wieder in meinem Browser (Microsoft Edge) ein Fenster ohne Inhalt kurz geöffnet und schnell wieder geschlossen. Gestern kam es öfter vor und in meinem Suchverlauf habe ich dann gesehen, dass das Fenster durch meine gesamte Historie immer wieder auftaucht, immer mit demselben Link mit einer Zahlenfolge (ging mit 127. los). Ich habe im Anschluss den AdwCleaner durchlaufen lassen und der hat sehr viele Bedrohungen erkannt. Ich habe sie alle in Quarantäne verschoben und gelöscht und den PC neu gestartet, aber die PUP.Adware.Heuristic Malware ist immer wieder erschienen. Ich gehe davon aus, dass der Trojaner über den LaTex-Editor auf meinen PC gelangt ist (ich glaube es waren Texmaker und MikTex Installer, die hatte ein Freund im August runtergeladen.) Ich habe die Programme gestern sofort gelöscht. Gleichzeitig hat sich gestern dann noch mein Dokumente Ordner kurz geöffnet und es erschien kurz "Dokumente kopieren." Ich habe dann den Browser bereinigt und auf seine Standardeinstellungen zurückgesetzt. Über Nacht habe ich meinen Computer zurückgesetzt und Windows wurde neu installiert, aber die Malware ist immer noch drauf. Heute habe ich wieder den AdwCleaner durchlaufen lassen (erschien wieder PUP.Adware.Heuristic) und zusätzlich Malwarebytes und es wurde wieder viel gefunden (pup.optional.amazon1button, PUP.Optional.ChipDe, pup.optional.bundleinstaller, PUP.Optional.Amazon1Button.AppFlsh). Die Logdateien sind leider zu groß für einen Beitrag, daher folgen mehrere Posts. (Anmerkung zu den Logs von AdwCleaner: die Preinstalled Software habe ich aus der Quarantäne wieder hergestellt.) FRST.txt Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-02-2025 Ran by Emilie (administrator) on LAPTOP-9AF8ONMC (Acer Aspire VN7-792G) (18-02-2025 09:54:09) Running from C:\Users\Emilie\Downloads\FRSTEnglish.exe Loaded Profiles: Emilie Platform: Microsoft Windows 10 Home Version 22H2 19045.5487 (X64) Language: Deutsch (Deutschland) Default browser: Edge Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAgent.exe (C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe ->) (Acer Incorporated -> Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe (C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe (C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (C:\Program Files\Acer\Acer Quick Access\QASvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAdminAgent.exe (C:\Program Files\Acer\Acer Quick Access\QASvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALockHandler.exe (C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcupdate.exe (C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe <2> (C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Windows\System32\mfevtps.exe <2> (C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe (C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (C:\Program Files\NVIDIA Corporation\Display\nvtray.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (explorer.exe ->) () [File not signed] C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe (explorer.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\SecureLine VPN\Vpn.exe <4> (explorer.exe ->) (BINARYLABS LIMITED -> Binarylabs LTD) C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner\BitCleaner Tasker.exe (explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <11> (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7ee21f0fcd504371\igfxEM.exe (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe (services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe (services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALSvc.exe (services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QASvc.exe (services.exe ->) (Acer Incorporated -> acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe (services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\SecureLine VPN\VpnSvc.exe (services.exe ->) (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe (services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (services.exe ->) (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (services.exe ->) (Intel(R) CN -> Intel Corporation) C:\Windows\System32\IntelSSTAPO\ParameterService\ParameterService.exe (services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7ee21f0fcd504371\igfxCUIService.exe (services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.5.471.0\McCSPServiceHost.exe (services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe (services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe (services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2> (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (services.exe ->) (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\AdminService.exe (services.exe ->) (WildTangent Inc -> WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe (svchost.exe ->) (Acer Incorporated -> ) C:\OEM\Preload\FubTracking\FubTracking.exe (svchost.exe ->) (Acer Incorporated -> ) C:\Program Files (x86)\Acer\Care Center\ACCStd.exe (svchost.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe (svchost.exe ->) (Acer Incorporated -> Acer) C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe (svchost.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7ee21f0fcd504371\igfxext.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe (svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18242040 2017-03-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1489400 2017-03-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor) HKLM\...\Run: [DAX2_APP] => C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe [628736 2015-06-16] () [File not signed] HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2631824 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart [1710056 2015-07-14] (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [File not signed] HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [66304 2015-05-06] (Acer Incorporated -> Acer Incorporated) HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [719272 2015-04-02] (McAfee, Inc. -> McAfee, Inc.) HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [619520 2025-02-17] (Microsoft Windows -> Microsoft Corporation) Startup: C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BitCleaner Tasker.lnk [2025-02-18] <==== ATTENTION ShortcutTarget: BitCleaner Tasker.lnk -> C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner\BitCleaner Tasker.exe (BINARYLABS LIMITED -> Binarylabs LTD) <==== ATTENTION Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast SecureLine VPN.lnk [2025-02-18] ShortcutTarget: Avast SecureLine VPN.lnk -> C:\Program Files\AVAST Software\SecureLine VPN\Vpn.exe (Avast Software s.r.o. -> Gen Digital Inc.) ==================== Scheduled Tasks (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {25746121-EB7E-4B7E-9BA4-27CAC8316AA5} - \Power Button -> No File <==== ATTENTION Task: {4F117C79-2706-4FBF-A748-C0259F51CEFA} - \Software Update Application -> No File <==== ATTENTION Task: {511D4F70-5C34-4428-AFAE-10D347114DCB} - \Microsoft\Windows\Windows Defender\Windows Defender Verification -> No File <==== ATTENTION Task: {611C823C-437B-46E7-9683-5312DFFCFD7B} - \Microsoft\Windows\UpdateOrchestrator\Policy Install -> No File <==== ATTENTION Task: {6A1AECEC-0766-473B-AE79-EAAA31DE758F} - \ACCAgent -> No File <==== ATTENTION Task: {6A250F7B-4F8A-4FEA-8CAE-31F28DA85202} - \ACCBackgroundApplication -> No File <==== ATTENTION Task: {6C488413-8509-4D62-94EB-159DC0C33122} - \Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan -> No File <==== ATTENTION Task: {7A003965-A297-4DC6-B15B-852D798391E0} - \Microsoft\Windows\UpdateOrchestrator\Reboot -> No File <==== ATTENTION Task: {7F4D5DE3-08C8-4008-AC82-C84BCA4B16DB} - \FUBTrackingByPLD -> No File <==== ATTENTION Task: {848DCC36-520C-4946-BF68-C7EFFEFA2F84} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot -> No File <==== ATTENTION Task: {8D20A4DC-B257-40AB-809F-565BEC5D3B5E} - \Quick Access -> No File <==== ATTENTION Task: {932EC946-767B-4FAA-9B54-A4A4A2DF1822} - \AcerCloud -> No File <==== ATTENTION Task: {93C99DC9-B400-40D5-A6DF-4310EAF3F1A6} - \Avast SecureLine -> No File <==== ATTENTION Task: {992AC68E-7168-40E1-B170-A736E71585A5} - \Microsoft\Office\Microsoft Office Touchless Attach Notification -> No File <==== ATTENTION Task: {A364E297-00AD-490D-900E-22AC34598C71} - \Microsoft\Windows\UpdateOrchestrator\Maintenance Install -> No File <==== ATTENTION Task: {BD02C08D-BA88-414E-A5E4-15FAFEB09DF3} - \Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance -> No File <==== ATTENTION Task: {C33F4607-C279-4257-9039-34FF9FE1F21A} - \Microsoft\Windows\AppID\SmartScreenSpecific -> No File <==== ATTENTION Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - \Microsoft\Windows\WindowsUpdate\sih -> No File <==== ATTENTION Task: {E135F27F-CC77-4798-8095-E4F7E716DE31} - \Microsoft\Windows\Windows Defender\Windows Defender Cleanup -> No File <==== ATTENTION Task: {E6010D43-6AE7-4B59-8E67-EC78FD8E8E96} - \Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler -> No File <==== ATTENTION Task: {E98AFDFB-4B5D-4DC1-9DCF-5DD16ED4B901} - \Microsoft\Windows\Plug and Play\Plug and Play Cleanup -> No File <==== ATTENTION Task: {EA3F661E-B31C-44A9-B40C-E3D5D56149D4} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display -> No File <==== ATTENTION Task: {F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6} - \UbtFrameworkService -> No File <==== ATTENTION Task: {FBE1992D-A1B2-44DD-9601-A1A2F799B096} - \ACC -> No File <==== ATTENTION Task: {FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59} - \Power Management -> No File <==== ATTENTION Task: {09512DFD-84D4-449F-9D11-9917471A5AA3} - System32\Tasks\Avast Software\Avast SecureLine VPN Bug Report => C:\Program Files\Avast Software\SecureLine VPN\AvBugReport.exe [6077736 2025-02-18] (Avast Software s.r.o. -> Gen Digital Inc.) -> --send "dumps|report" --silent --product 11 --programpath "C:\Program Files\Avast Software\SecureLine VPN" --configpath "C:\ProgramData\Avast Software\SecureLine VPN" --path "C:\ProgramData\Avast Software\SecureLine VPN\log" --path "C:\ProgramData\Avast Software\Icarus\Logs" --logpath "C:\ProgramDat (the data entry has 80 more characters). Task: {CC8E2FDE-48E1-4B14-B607-F03B518B236F} - System32\Tasks\Avast Software\Avast SecureLine VPN Emergency Update => C:\Program Files\Avast Software\SecureLine VPN\VpnUpdate.exe [3954984 2025-02-18] (Avast Software s.r.o. -> Gen Digital Inc.) Task: {9D08D3AC-8019-46E8-9835-EE375177789D} - System32\Tasks\Avast Software\Avast SecureLine VPN Update => C:\Program Files\Common Files\Avast Software\Icarus\avast-vpn\icarus.exe [8289064 2025-01-30] (Avast Software s.r.o. -> Gen Digital Inc.) Task: {EF900057-1F28-42A8-90CF-6AE22A491782} - System32\Tasks\Microsoft\Windows\SysResetDelayedCleanup => C:\WINDOWS\system32\ResetEngine.exe [21480 2025-02-17] (Microsoft Windows -> Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{3bea1b67-1567-4514-9a7e-1d29d203c030}: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{3bea1b67-1567-4514-9a7e-1d29d203c030}: [DhcpDomain] local Tcpip\..\Interfaces\{e74f9852-4b1d-4422-9e19-da6e72942a19}: [DhcpNameServer] 192.17.128.24 Edge: ======= Edge DefaultProfile: Default Edge Profile: C:\Users\Emilie\AppData\Local\Microsoft\Edge\User Data\Default [2025-02-18] Edge Extension: (Malwarebytes Browser Guard) - C:\Users\Emilie\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2025-02-18] Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn] Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn] FireFox: ======== FF DefaultProfile: now364od.default FF ProfilePath: C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default [2025-02-18] FF Extension: (Amazon 1Button App for Firefox) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\abb@amazon.com [2025-02-18] [Legacy] [not signed] FF Extension: (العربية Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-ar@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (български Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-bg@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Czech (CZ) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-cs@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Dansk (da) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-da@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Deutsch (DE) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-de@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Greek (GR) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-el@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (English (US) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-en-US@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Español (España) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-es-ES@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Estonian Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-et@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Finnish Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-fi@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Français Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-fr@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Hebrew (IL) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-he@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Magyar (HU) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-hu@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Italiano (IT) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-it@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Japanese Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-ja@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Korean (KR) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-ko@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Lietuvių Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-lt@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Norsk bokmċl (NO) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-nb-NO@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Nederlands (NL) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-nl@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Polski Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-pl@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Português Brasileiro Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-pt-BR@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Português (Portugal) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-pt-PT@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Russian (RU) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-ru@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Slovak (SK) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-sk@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Slovenski jezik Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-sl@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (српски (sr) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-sr@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Svenska (SE) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-sv-SE@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Thai Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-th@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Türkçe (TR) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-tr@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Ukrainian (UA) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-uk@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Chinese Simplified (zh-CN) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-zh-CN@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Traditional Chinese (zh-TW) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-zh-TW@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Mozilla Partner Defaults) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\partnerdefaults@mozilla.com [2025-02-18] [Legacy] FF Extension: (العربية Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-ar@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (български Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-bg@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Czech (CZ) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-cs@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Dansk (da) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-da@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Deutsch (DE) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-de@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Greek (GR) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-el@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (English (US) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-en-US@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Español (España) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-es-ES@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Estonian Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-et@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Finnish Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-fi@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Français Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-fr@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Hebrew (IL) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-he@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Magyar (HU) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-hu@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Italiano (IT) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-it@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Japanese Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-ja@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Korean (KR) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-ko@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Lietuvių Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-lt@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Norsk bokmċl (NO) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-nb-NO@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Nederlands (NL) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-nl@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Polski Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-pl@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Português Brasileiro Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-pt-BR@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Português (Portugal) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-pt-PT@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Russian (RU) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-ru@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Slovak (SK) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-sk@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Slovenski jezik Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-sl@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (српски (sr) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-sr@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Svenska (SE) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-sv-SE@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Thai Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-th@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Türkçe (TR) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-tr@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Ukrainian (UA) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-uk@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Chinese Simplified (zh-CN) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-zh-CN@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Traditional Chinese (zh-TW) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-zh-TW@firefox.mozilla.org [2025-02-18] [Legacy] FF Extension: (Mozilla Partner Defaults) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\partnerdefaults@mozilla.com [2025-02-18] [Legacy] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2025-02-18] [Legacy] [not signed] FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-07-16] (McAfee, Inc. -> ) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-07-16] (McAfee, Inc. -> ) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-14] (WildTangent Inc -> ) Chrome: ======= CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2839296 2015-05-06] (Acer Incorporated -> Acer Incorporated) R2 DAX2API; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [163336 2016-09-19] (Dolby Laboratories, Inc. -> ) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573568 2015-05-14] (Acer Incorporated -> Acer Incorporated) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [373312 2015-04-14] (WildTangent Inc -> WildTangent) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.) R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed] S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed] R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9483456 2025-02-18] (Malwarebytes Inc. -> Malwarebytes) S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-02-18] (Malwarebytes Inc. -> Malwarebytes) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [754792 2015-07-16] (McAfee, Inc. -> McAfee, Inc.) S3 McAWFwk; C:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [338208 2015-03-20] (McAfee, Inc. -> McAfee, Inc.) R2 mcbootdelaystartsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.) R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.471.0\McCSPServiceHost.exe [207344 2015-04-27] (McAfee, Inc. -> McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [612688 2015-04-09] (McAfee, Inc. -> McAfee, Inc.) S4 McOobeSv2; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.) R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [232656 2015-06-29] (McAfee, Inc. -> McAfee, Inc.) R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [373704 2015-07-30] (McAfee, Inc. -> McAfee, Inc.) R3 mfevtp; C:\Windows\system32\mfevtps.exe [254792 2015-06-29] (McAfee, Inc. -> McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.) R3 QALSvc; C:\Program Files\Acer\Acer Quick Access\QALSvc.exe [401248 2015-09-04] (Acer Incorporated -> Acer Incorporated) R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [453984 2015-09-04] (Acer Incorporated -> Acer Incorporated) R2 SecureLine; C:\Program Files\Avast Software\SecureLine VPN\VpnSvc.exe [13032232 2025-02-18] (Avast Software s.r.o. -> Gen Digital Inc.) R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [247040 2015-05-27] (Acer Incorporated -> acer) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation) S2 DCIService; C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe [X] <==== ATTENTION ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 aswVpnRdr; C:\WINDOWS\System32\drivers\aswVpnRdr.sys [85776 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Avast Software) R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [800672 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender) R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77536 2015-07-02] (McAfee, Inc. -> McAfee, Inc.) S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [207208 2015-05-19] (McAfee, Inc. -> McAfee, Inc.) R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [31000 2018-05-15] (Acer Incorporated -> Acer Incorporated) R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234072 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2025-02-18] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [202856 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [80448 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239568 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [189776 2025-02-18] (Malwarebytes Inc. -> Malwarebytes) R2 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [412440 2015-07-02] (McAfee, Inc. -> McAfee, Inc.) R2 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [347800 2015-07-02] (McAfee, Inc. -> McAfee, Inc.) S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [80920 2015-07-02] (Microsoft Windows Early Launch Anti-Malware Publisher -> McAfee, Inc.) R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [496888 2015-07-02] (McAfee, Inc. -> McAfee, Inc.) R2 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [875928 2015-07-02] (McAfee, Inc. -> McAfee, Inc.) R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [492000 2015-05-26] (McAfee, Inc. -> McAfee, Inc.) S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [109480 2015-05-26] (McAfee, Inc. -> McAfee, Inc.) R2 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [344704 2015-07-02] (McAfee, Inc. -> McAfee, Inc.) S3 NVSWCFilter; C:\WINDOWS\System32\drivers\nvswcfilter.sys [19616 2015-07-06] (Nvidia Corporation -> Windows (R) Win 7 DDK provider) R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [25368 2018-05-15] (Acer Incorporated -> Acer Incorporated) S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [76832 2022-09-30] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated) S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) (Whitelisted) ========= (If an entry is included in the fixlist, the file/folder will be moved.) 2025-02-18 09:48 - 2025-02-18 09:52 - 000036502 _____ C:\Users\Emilie\Downloads\Addition.txt 2025-02-18 09:39 - 2025-02-18 09:56 - 000037459 _____ C:\Users\Emilie\Downloads\FRST.txt 2025-02-18 09:38 - 2025-02-18 09:55 - 000000000 ____D C:\FRST 2025-02-18 09:33 - 2025-02-18 09:38 - 002403840 _____ (Farbar) C:\Users\Emilie\Downloads\FRSTEnglish.exe 2025-02-18 09:30 - 2025-02-18 09:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2025-02-18 09:26 - 2025-02-18 09:26 - 000000000 ____D C:\Users\Emilie\AppData\Local\CEF 2025-02-18 09:24 - 2025-02-18 09:24 - 000189776 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2025-02-18 09:24 - 2025-02-18 09:24 - 000000000 ____D C:\Users\Emilie\AppData\LocalLow\IGDump 2025-02-18 09:23 - 2025-02-18 09:23 - 000002153 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SecureLine VPN.lnk 2025-02-18 09:23 - 2025-02-18 09:23 - 000002141 _____ C:\Users\Public\Desktop\Avast SecureLine VPN.lnk 2025-02-18 09:23 - 2025-02-18 09:23 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software 2025-02-18 09:18 - 2025-02-18 09:18 - 000064789 _____ C:\Users\Emilie\Desktop\Malwarebytes Scan-Bericht 2025-02-18 090107.txt 2025-02-18 09:14 - 2025-02-18 09:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2025-02-18 09:00 - 2025-02-18 09:56 - 000000000 ____D C:\Users\Emilie\AppData\Local\Malwarebytes 2025-02-18 09:00 - 2025-02-18 09:00 - 000002097 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk 2025-02-18 09:00 - 2025-02-18 09:00 - 000002085 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2025-02-18 08:58 - 2025-02-18 08:58 - 002832624 _____ (Malwarebytes) C:\Users\Emilie\Downloads\MBSetup.exe 2025-02-18 08:58 - 2025-02-18 08:58 - 000000000 ____D C:\ProgramData\Malwarebytes 2025-02-18 08:58 - 2025-02-18 08:58 - 000000000 ____D C:\Program Files\Malwarebytes 2025-02-18 08:57 - 2025-02-18 08:57 - 000000000 ____D C:\Program Files\Common Files\Avast Software 2025-02-18 08:57 - 2025-01-30 09:28 - 000050976 _____ (Avast Software) C:\WINDOWS\system32\icarus_rvrt.exe 2025-02-18 08:55 - 2025-02-18 08:55 - 008790880 _____ (Malwarebytes) C:\Users\Emilie\Downloads\adwcleaner.exe 2025-02-18 08:53 - 2025-02-18 08:53 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\AVAST Software 2025-02-18 08:24 - 2025-02-18 08:24 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\Spelling 2025-02-18 08:20 - 2025-02-18 08:20 - 000000000 ____D C:\Users\Emilie\AppData\Local\CareCenter 2025-02-18 08:17 - 2025-02-18 08:17 - 000000000 ____D C:\Users\Emilie\AppData\Local\Comms 2025-02-18 08:11 - 2025-02-18 08:11 - 000000000 ____D C:\WINDOWS\oem 2025-02-18 08:04 - 2025-02-18 08:04 - 000000000 ____D C:\Users\Emilie\AppData\Local\NVIDIA 2025-02-18 08:03 - 2025-02-18 08:04 - 000000000 ____D C:\Users\Emilie\AppData\Local\Lavasoft 2025-02-18 08:02 - 2025-02-18 08:04 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Lavasoft 2025-02-18 08:02 - 2025-02-18 08:04 - 000000000 ____D C:\Program Files (x86)\Lavasoft 2025-02-18 08:01 - 2025-02-18 08:04 - 000000000 ____D C:\ProgramData\Lavasoft 2025-02-18 08:00 - 2025-02-18 08:00 - 000000000 ____D C:\Program Files\Common Files\AV 2025-02-18 07:55 - 2025-02-18 07:55 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2862171838-2850908273-2982186409-1001 2025-02-18 07:54 - 2025-02-18 08:02 - 000000000 ____D C:\Users\Emilie\AppData\Local\Mozilla 2025-02-18 07:54 - 2025-02-18 07:55 - 000003382 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2862171838-2850908273-2982186409-1001 2025-02-18 07:54 - 2025-02-18 07:54 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Mozilla 2025-02-18 07:53 - 2025-02-18 07:53 - 000000000 ____D C:\Users\Emilie\AppData\Local\clear.fi 2025-02-18 07:51 - 2025-02-18 07:51 - 000000000 ____D C:\Users\Emilie\AppData\Local\Publishers 2025-02-18 07:50 - 2025-02-18 08:35 - 000000000 ____D C:\ProgramData\Packages 2025-02-18 07:50 - 2025-02-18 08:11 - 000000000 ____D C:\Users\Emilie\AppData\Local\AOP SDK 2025-02-18 07:47 - 2025-02-18 09:33 - 000000000 ____D C:\Users\Emilie\AppData\Local\Packages 2025-02-18 07:47 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\Network 2025-02-18 07:47 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Adobe 2025-02-18 07:47 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie\AppData\Local\VirtualStore 2025-02-18 07:46 - 2025-02-18 08:08 - 000000000 ____D C:\Users\Emilie\AppData\Local\ConnectedDevicesPlatform 2025-02-18 07:46 - 2025-02-18 07:46 - 000000020 ___SH C:\Users\Emilie\ntuser.ini 2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\Users\Default\AppData\Local\Verlauf 2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten 2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\ProgramData\Vorlagen 2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\ProgramData\Startmenü 2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\ProgramData\Dokumente 2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\ProgramData\Anwendungsdaten 2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\Program Files\Gemeinsame Dateien 2025-02-18 02:27 - 2025-02-18 02:27 - 000009518 _____ C:\Users\Emilie\Desktop\Entfernte Apps.html 2025-02-18 02:24 - 2025-02-18 02:24 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\SystemCertificates 2025-02-18 02:24 - 2025-02-18 02:24 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\Crypto 2025-02-18 02:19 - 2025-02-18 02:19 - 000022960 _____ C:\WINDOWS\system32\emptyregdb.dat 2025-02-18 01:37 - 2025-02-18 07:55 - 000002390 _____ C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2025-02-18 01:37 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\Windows 2025-02-18 01:37 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Vorlagen 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Startmenü 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Netzwerkumgebung 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Lokale Einstellungen 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Eigene Dateien 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Druckumgebung 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Documents\Eigene Videos 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Documents\Eigene Musik 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Documents\Eigene Bilder 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\AppData\Local\Verlauf 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\AppData\Local\Anwendungsdaten 2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Anwendungsdaten 2025-02-18 01:21 - 2025-02-18 01:21 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate 2025-02-18 01:03 - 2025-02-18 09:22 - 000000000 ____D C:\ProgramData\NVIDIA 2025-02-18 01:03 - 2025-02-18 01:28 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2025-02-18 01:03 - 2017-05-01 21:52 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat 2025-02-18 01:03 - 2017-05-01 21:51 - 006437312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll 2025-02-18 01:03 - 2017-05-01 21:51 - 002479552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll 2025-02-18 01:03 - 2017-05-01 21:51 - 001762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll 2025-02-18 01:03 - 2017-05-01 21:51 - 000548800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll 2025-02-18 01:03 - 2017-05-01 21:51 - 000392312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll 2025-02-18 01:03 - 2017-05-01 21:51 - 000081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll 2025-02-18 01:03 - 2017-05-01 21:51 - 000069752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll 2025-02-18 01:03 - 2017-04-25 22:11 - 007944687 _____ C:\WINDOWS\system32\nvcoproc.bin 2025-02-18 01:02 - 2025-02-18 01:29 - 000000000 ____D C:\ProgramData\NVIDIA Corporation 2025-02-18 01:02 - 2025-02-18 01:26 - 000000000 ____D C:\Program Files (x86)\Intel 2025-02-18 01:02 - 2025-02-18 01:23 - 000000000 ____D C:\Program Files\NVIDIA Corporation 2025-02-18 01:02 - 2025-02-18 01:22 - 000000000 ____D C:\Program Files\Intel 2025-02-18 01:02 - 2025-02-18 01:02 - 000000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin 2025-02-18 01:01 - 2025-02-18 01:28 - 000000000 ____D C:\Program Files (x86)\Realtek 2025-02-18 01:01 - 2025-02-18 01:01 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk 2025-02-18 01:01 - 2025-02-18 01:01 - 000002278 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk 2025-02-18 01:01 - 2025-02-18 01:01 - 000000102 _____ C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc 2025-02-18 01:01 - 2025-02-18 01:01 - 000000000 ____D C:\WINDOWS\system32\IntelSSTAPO 2025-02-18 01:01 - 2025-02-18 01:01 - 000000000 ____D C:\ProgramData\rtkSSTSetting 2025-02-18 01:01 - 2025-02-18 01:01 - 000000000 ____D C:\ProgramData\Dolby 2025-02-18 01:01 - 2025-02-18 01:01 - 000000000 ____D C:\Program Files\Dolby 2025-02-18 01:00 - 2025-02-18 01:34 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2025-02-18 01:00 - 2025-02-18 01:01 - 000000000 ____D C:\WINDOWS\system32\DAX2 2025-02-18 01:00 - 2025-02-18 01:00 - 002173918 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip 2025-02-18 01:00 - 2025-02-18 01:00 - 000000000 ____D C:\WINDOWS\system32\DAX3 2025-02-18 01:00 - 2025-02-18 01:00 - 000000000 ____D C:\Program Files\Realtek 2025-02-18 01:00 - 2025-02-18 01:00 - 000000000 ____D C:\Program Files\Common Files\Atheros 2025-02-18 00:58 - 2025-02-18 07:57 - 000003756 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA 2025-02-18 00:58 - 2025-02-18 07:57 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore 2025-02-18 00:57 - 2025-02-18 00:57 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd 2025-02-18 00:56 - 2025-02-18 09:22 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2025-02-18 00:27 - 2025-02-18 07:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2025-02-18 00:27 - 2025-02-18 00:27 - 000268240 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2025-02-18 00:21 - 2025-02-18 03:00 - 000000000 ____D C:\WINDOWS\Panther 2025-02-17 23:43 - 2025-02-18 03:00 - 000000000 ____D C:\Windows.old 2025-02-17 23:41 - 2025-02-17 23:42 - 000000000 ____D C:\WINDOWS\ServiceProfiles 2025-02-17 23:29 - 2025-02-18 08:01 - 000000000 ____D C:\WINDOWS\SystemTemp 2025-02-17 23:29 - 2025-02-17 23:30 - 000000000 ____D C:\WINDOWS\system32\compatrel 2025-02-17 23:29 - 2025-02-17 23:29 - 000000000 ____D C:\WINDOWS\InboxApps 2025-02-17 23:29 - 2025-02-17 23:29 - 000000000 ____D C:\ProgramData\ssh 2025-02-17 23:11 - 2025-02-17 23:11 - 000022205 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json 2025-02-17 23:06 - 2025-02-17 23:06 - 000022205 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json 2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer 2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\Program Files\Reference Assemblies 2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\Program Files\MSBuild 2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies 2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\Program Files (x86)\MSBuild 2025-02-17 22:34 - 2025-02-17 22:34 - 000000000 ____D C:\WINDOWS\system32\Intel 2025-02-17 22:34 - 2025-02-17 22:34 - 000000000 ____D C:\WINDOWS\system32\cAVS 2025-02-17 22:33 - 2025-02-17 22:33 - 000000000 ____D C:\WINDOWS\SysWOW64\sda 2025-02-17 22:32 - 2025-02-17 22:32 - 000008192 _____ C:\WINDOWS\system32\config\userdiff 2025-02-17 21:28 - 2025-02-18 02:27 - 000000000 ___HD C:\$SysReset 2025-02-17 13:27 - 2025-02-18 08:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2025-02-17 13:23 - 2025-02-17 13:35 - 000000000 ____D C:\AdwCleaner 2025-02-14 12:10 - 2025-02-14 12:10 - 002371552 _____ C:\Users\Emilie\Downloads\screencapture-kbbjobs-softgarden-io-job-52655704-Volontar-in-Publikationspraktiken-Schwerpunkt-Redaktion-w-m-d-2025-02-14-12_09_51.pdf 2025-02-12 16:04 - 2025-02-12 16:04 - 000000000 ___HD C:\$WinREAgent 2025-02-12 12:21 - 2025-02-12 12:21 - 004420943 _____ C:\Users\Emilie\Downloads\screencapture-goodjobs-eu-jobs-junior-crm-managerin-momox-se-2025-02-12-12_21_30.pdf 2025-02-10 14:40 - 2025-02-10 14:40 - 002234243 _____ C:\Users\Emilie\Downloads\screencapture-flotte-lotte-berlin-de-jobs-2025-02-10-14_40_06.pdf 2025-02-06 16:05 - 2025-02-06 16:06 - 000000000 ____D C:\Users\Emilie\Documents\ADAC_Auslandskrankenversicherung 2025-02-06 12:26 - 2025-02-06 12:26 - 000100384 _____ C:\Users\Emilie\Downloads\20250113_225512_SCHREIBEN.pdf 2025-02-06 12:26 - 2025-02-06 12:26 - 000079950 _____ C:\Users\Emilie\Downloads\20241212_150914_SCHREIBEN.pdf 2025-02-06 11:29 - 2025-02-06 11:29 - 000000832 _____ C:\Users\Emilie\Downloads\ical.ics 2025-02-05 20:33 - 2025-02-18 00:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2025-02-05 11:47 - 2025-02-05 11:47 - 000190374 _____ C:\Users\Emilie\Downloads\Lebenslauf_*****, Emilie_2025.pdf 2025-02-05 11:44 - 2025-02-05 11:44 - 000185126 _____ C:\Users\Emilie\Downloads\Lebenslauf_*****,Emilie (1).pdf 2025-02-03 18:13 - 2025-02-03 18:13 - 002520612 _____ C:\Users\Emilie\Downloads\screencapture-join-companies-quintusstudios-13441555-junior-acquisitions-manager-m-f-d-2025-02-03-18_13_20.pdf 2025-02-03 18:02 - 2025-02-03 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24 2025-02-03 12:02 - 2025-02-03 12:02 - 001841686 _____ C:\Users\Emilie\Downloads\screencapture-duh-jobs-de-jobs-53047959-Trainee-w-m-d-im-Team-Presse-und-Kommunikation-2025-02-03-12_02_28.pdf 2025-02-01 10:34 - 2025-02-01 10:34 - 005049282 _____ C:\Users\Emilie\Downloads\screencapture-sonypicturesjobs-job-berlin-digital-marketing-manager-m-w-d-22978-76059651296-2025-02-01-10_34_12.pdf 2025-01-30 11:07 - 2025-01-30 11:07 - 004430477 _____ C:\Users\Emilie\Downloads\screencapture-sonypicturesjobs-job-berlin-booker-sales-analyst-im-bereich-film-disposition-m-w-d-22978-73662561280-2025-01-30-11_06_49.pdf 2025-01-26 12:08 - 2025-01-26 12:08 - 004486333 _____ C:\Users\Emilie\Downloads\screencapture-goodjobs-eu-jobs-mitarbeiterin-im-bereich-sexuelle-bildung-better-birth-control-ev-2025-01-26-12_07_47.pdf 2025-01-24 12:55 - 2025-01-24 12:55 - 000207360 _____ C:\Users\Emilie\Downloads\Anschreiben_***** Emilie.pdf 2025-01-24 12:54 - 2025-01-24 12:54 - 000188848 _____ C:\Users\Emilie\Downloads\Lebenslauf_***** Emilie_2025.pdf ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2025-02-18 09:58 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp 2025-02-18 09:30 - 2019-12-07 15:50 - 000744902 _____ C:\WINDOWS\system32\perfh007.dat 2025-02-18 09:30 - 2019-12-07 15:50 - 000150288 _____ C:\WINDOWS\system32\perfc007.dat 2025-02-18 09:30 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF 2025-02-18 09:30 - 2015-08-31 12:01 - 001722788 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2025-02-18 09:29 - 2015-08-31 11:51 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2025-02-18 09:26 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness 2025-02-18 09:24 - 2016-09-03 18:26 - 000000000 __SHD C:\Users\Emilie\IntelGraphicsProfiles 2025-02-18 09:23 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2025-02-18 09:23 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software 2025-02-18 09:23 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\AVAST Software 2025-02-18 09:22 - 2020-08-13 00:29 - 000008192 ___SH C:\DumpStack.log.tmp 2025-02-18 09:22 - 2015-08-31 11:50 - 000000000 ____D C:\Program Files\AVAST Software 2025-02-18 09:21 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2025-02-18 09:12 - 2016-02-26 04:13 - 000000000 ____D C:\Program Files (x86)\Amazon 2025-02-18 09:00 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2025-02-18 08:27 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState 2025-02-18 08:20 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\OEM 2025-02-18 08:13 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog 2025-02-18 08:12 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps 2025-02-18 08:10 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files (x86)\McAfee 2025-02-18 08:00 - 2015-08-31 11:52 - 000000000 ____D C:\ProgramData\McAfee 2025-02-18 07:54 - 2016-09-03 18:29 - 000000000 ___RD C:\Users\Emilie\OneDrive 2025-02-18 07:49 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2025-02-18 07:47 - 2017-11-24 10:10 - 000000000 ___RD C:\Users\Emilie\3D Objects 2025-02-18 07:47 - 2015-08-31 11:49 - 000000000 __RHD C:\Users\Public\AccountPictures 2025-02-18 03:01 - 2019-12-07 15:52 - 000000000 ____D C:\WINDOWS\system32\FxsTmp 2025-02-18 03:00 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe 2025-02-18 02:31 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows NT 2025-02-18 02:28 - 2019-12-07 10:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM 2025-02-18 02:27 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Registration 2025-02-18 02:26 - 2019-07-25 01:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby 2025-02-18 02:24 - 2019-12-07 10:14 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows 2025-02-18 02:18 - 2019-12-07 10:14 - 000000000 __RHD C:\Users\Public\Libraries 2025-02-18 02:18 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated 2025-02-18 01:34 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2025-02-18 01:34 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\spool 2025-02-18 01:34 - 2016-02-26 03:47 - 000000000 ____D C:\WINDOWS\system32\ihvmanager 2025-02-18 01:34 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed 2025-02-18 01:34 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\system32\Macromed 2025-02-18 01:33 - 2019-12-07 15:52 - 000000000 ____D C:\WINDOWS\OCR 2025-02-18 01:33 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Resources 2025-02-18 01:33 - 2016-02-26 11:59 - 000000000 ____D C:\WINDOWS\NAPP_Dism_Log 2025-02-18 01:33 - 2015-07-10 12:04 - 000000000 ___RD C:\WINDOWS\PurchaseDialog 2025-02-18 01:32 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Help 2025-02-18 01:32 - 2015-07-10 12:04 - 000000000 ___RD C:\WINDOWS\DesktopTileResources 2025-02-18 01:30 - 2016-02-26 04:15 - 000000000 ____D C:\Users\Public\Foxit Software 2025-02-18 01:30 - 2016-02-26 04:15 - 000000000 ____D C:\Users\Public\CyberLink 2025-02-18 01:30 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\WildTangent 2025-02-18 01:29 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\USOPrivate 2025-02-18 01:29 - 2016-02-26 04:15 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 12 2025-02-18 01:29 - 2016-02-26 04:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF 2025-02-18 01:29 - 2016-02-26 04:14 - 000000000 ____D C:\ProgramData\Temp 2025-02-18 01:29 - 2016-02-26 04:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2025-02-18 01:29 - 2016-02-26 03:44 - 000000000 ____D C:\ProgramData\Package Cache 2025-02-18 01:29 - 2015-08-31 11:51 - 000000000 ____D C:\ProgramData\Mozilla 2025-02-18 01:29 - 2015-08-31 11:50 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2025-02-18 01:29 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer 2025-02-18 01:29 - 2015-08-31 11:49 - 000000000 ____D C:\ProgramData\Microsoft OneDrive 2025-02-18 01:28 - 2016-02-26 04:15 - 000000000 ____D C:\ProgramData\CyberLink 2025-02-18 01:28 - 2016-02-26 04:15 - 000000000 ____D C:\ProgramData\CLSK 2025-02-18 01:28 - 2016-02-26 04:14 - 000000000 ____D C:\ProgramData\install_clap 2025-02-18 01:28 - 2016-02-26 03:47 - 000000000 ____D C:\Program Files (x86)\Qualcomm Atheros 2025-02-18 01:28 - 2016-02-26 03:45 - 000000000 ____D C:\ProgramData\Intel 2025-02-18 01:28 - 2016-02-26 03:44 - 000000000 ____D C:\ProgramData\DriverSetupUtility 2025-02-18 01:28 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\Acer 2025-02-18 01:28 - 2015-08-31 11:50 - 000000000 ____D C:\Program Files (x86)\WildTangent Games 2025-02-18 01:28 - 2015-08-31 11:50 - 000000000 ____D C:\Program Files (x86)\WildGames 2025-02-18 01:26 - 2016-02-26 04:15 - 000000000 ____D C:\Program Files (x86)\Foxit PhantomPDF 2025-02-18 01:26 - 2016-02-26 03:47 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2025-02-18 01:26 - 2016-02-26 03:39 - 000000000 ____D C:\Program Files (x86)\Microsoft Office 2025-02-18 01:26 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files (x86)\mcafee.com 2025-02-18 01:25 - 2016-02-26 04:15 - 000000000 ____D C:\Program Files (x86)\CyberLink 2025-02-18 01:24 - 2015-08-31 11:50 - 000000000 ____D C:\Program Files (x86)\Acer 2025-02-18 01:23 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files\mcafee.com 2025-02-18 01:23 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files\mcafee 2025-02-18 01:23 - 2015-07-10 14:14 - 000000000 ____D C:\Program Files\Windows Journal 2025-02-18 01:22 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2025-02-18 01:22 - 2016-02-26 03:48 - 000000000 ____D C:\Program Files\Common Files\QCA_Bluetooth 2025-02-18 01:22 - 2016-02-26 03:44 - 000000000 ____D C:\Program Files\DriverSetupUtility 2025-02-18 01:22 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files\Common Files\McAfee 2025-02-18 01:22 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files\Acer 2025-02-18 01:00 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\appcompat 2025-02-18 00:36 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2025-02-18 00:19 - 2019-12-07 10:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template 2025-02-18 00:19 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase 2025-02-18 00:19 - 2018-01-24 22:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip 2025-02-17 23:42 - 2021-12-06 14:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos 2025-02-17 23:42 - 2020-03-24 19:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO steuer Sparbuch 2020 2025-02-17 23:30 - 2019-12-07 15:51 - 000000000 ____D C:\WINDOWS\system32\OpenSSH 2025-02-17 23:30 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\SysWOW64\de 2025-02-17 23:30 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\system32\de 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemApps 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Keywords 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\DDFs 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Com 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\appraiser 2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers 2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Portable Devices 2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Multimedia Platform 2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices 2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\schemas 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\IME 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\DiagTrack 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System 2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender 2025-02-17 23:29 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing 2025-02-17 23:27 - 2019-12-07 15:54 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll 2025-02-17 23:27 - 2019-12-07 15:54 - 000020827 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml 2025-02-17 23:27 - 2019-12-07 10:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll 2025-02-17 23:27 - 2019-12-07 10:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll 2025-02-17 22:37 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI 2025-02-17 22:37 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\MUI 2025-02-04 19:18 - 2015-08-31 11:51 - 000001238 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2025-01-21 18:36 - 2019-12-20 19:02 - 000000000 ____D C:\Users\Emilie\Documents\Tickets 2025-01-19 16:17 - 2024-12-06 17:03 - 000000000 ____D C:\Users\Emilie\Documents\Kleinanzeigen und Vinted ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ======================== Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-02-2025 Ran by Emilie (18-02-2025 10:02:45) Running from C:\Users\Emilie\Downloads Microsoft Windows 10 Home Version 22H2 19045.5487 (X64) (2025-02-18 02:00:51) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= (If an entry is included in the fixlist, it will be removed.) Administrator (S-1-5-21-2862171838-2850908273-2982186409-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-2862171838-2850908273-2982186409-503 - Limited - Disabled) Emilie (S-1-5-21-2862171838-2850908273-2982186409-1001 - Administrator - Enabled) => C:\Users\Emilie Gast (S-1-5-21-2862171838-2850908273-2982186409-501 - Limited - Disabled) SophosSAULAPTOP-9aaa (S-1-5-21-2862171838-2850908273-2982186409-1002 - Limited - Enabled) WDAGUtilityAccount (S-1-5-21-2862171838-2850908273-2982186409-504 - Limited - Disabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Enabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543} AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: McAfee Anti-Virus und Anti-Spyware (Disabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 12 Labours of Hercules III: Girl Power (HKLM-x32\...\WTA-8d9b4f73-bb47-4fea-917d-c50dd2ffed5c) (Version: 3.0.2.118 - WildTangent) Hidden abFiles (HKLM-x32\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.03.2003 - Acer Incorporated) abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.03.2004.4 - Acer Incorporated) Acer Care Center (HKLM\...\{1AF41E84-3408-499A-8C93-8891F0612719}) (Version: 2.00.3005 - Acer Incorporated) Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3001 - Acer Incorporated) Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.06.2004 - Acer Incorporated) Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8109 - Acer Incorporated) Acer Quick Access (HKLM\...\{E3678E72-78E3-4F91-A9FB-913876FF6DA2}) (Version: 2.00.3008 - Acer Incorporated) Acer UEIP Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 2.01.3002 - Acer Incorporated) AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.07.2004.0 - Acer Incorporated) Avast SecureLine VPN (HKLM\...\Avast SecureLine) (Version: 25.1.11083.14496 - Avast Software) CyberLink PowerDVD 12 (HKLM-x32\...\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5427.02 - CyberLink Corp.) Hidden CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5427.02 - CyberLink Corp.) Dolby Audio X2 Windows API SDK (HKLM\...\{6A478BF2-F67F-4ABC-A7F1-B6B5BA862371}) (Version: 0.5.2.32 - Dolby Laboratories, Inc.) Dolby Audio X2 Windows API SDK (HKLM\...\{AA950AA4-CD9B-4D81-B6C0-BFABB7A24261}) (Version: 0.7.5.65 - Dolby Laboratories, Inc.) Dolby Audio X2 Windows APP (HKLM\...\{7DA57EF8-9D20-4126-AF15-D0CC97D0C017}) (Version: 0.4.0.22 - Dolby Laboratories, Inc.) DriverSetupUtility (HKLM\...\{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}) (Version: 1.00.3011 - Acer Incorporated) Foxit PhantomPDF (HKLM-x32\...\{A4023BDF-82D5-412D-9D58-8C2819EBFE2E}) (Version: 7.0.410.326 - Foxit Software Inc.) Game Explorer Categories - genres (HKLM-x32\...\WildTangentGameProvider-acer-genres) (Version: 13.0.0.6 - WildTangent, Inc.) Game Explorer Categories - main (HKLM-x32\...\WildTangentGameProvider-acer-main) (Version: 13.0.0.6 - WildTangent, Inc.) Home Makeover (HKLM-x32\...\WTA-ff512562-ab4b-4aae-9e8c-1d09bd47ac58) (Version: 3.0.2.59 - WildTangent) Hidden Intel(R) Chipset Device Software (HKLM\...\{55398EAC-F58E-4F19-B553-BDF8B9EFD839}) (Version: 10.1.1.9 - Intel Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation) Intel(R) Management Engine Components (HKLM\...\{5BD7E621-9791-4D9F-A620-1BA51153B749}) (Version: 1.0.0.0 - Intel Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{A53B7EAB-86BD-4F16-8C44-011B1376326A}) (Version: 11.0.0.1162 - Intel Corporation) Hidden Intel(R) ME UninstallLegacy (HKLM\...\{555B1C57-E71B-4775-BC1D-627EEF693F0D}) (Version: 1.0.1.0 - Intel Corporation) Hidden Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation) Intel(R) Serial IO (HKLM\...\{30E935B2-0DAC-455E-AC76-3C8504DC3D18}) (Version: 30.100.1519.07 - Intel Corporation) Hidden Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation) Intel Chipsatz-Gerätesoftware (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden Intel Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation) Intel Trusted Connect Service Client (HKLM\...\{7D84E343-A23D-451C-B123-0195B2D903A6}) (Version: 1.42.17.0 - Intel Corporation) Hidden Jewel Match 3 (HKLM-x32\...\WTA-679326c7-f13f-4d56-ae2e-6a7fee2304c7) (Version: 2.2.0.97 - WildTangent) Hidden Jewel Match Snowscapes (HKLM-x32\...\WTA-ad853ef4-00ea-4eae-8b6e-18dee9cd5722) (Version: 3.0.2.118 - WildTangent) Hidden Magic Academy (HKLM-x32\...\WTA-4c57b906-a5ca-4c03-9798-68e13f3261f1) (Version: 2.2.0.97 - WildTangent) Hidden Malwarebytes version 5.2.6.163 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.2.6.163 - Malwarebytes) McAfee LiveSafe Internet Security (HKLM-x32\...\MSC) (Version: 14.0.1122 - McAfee, Inc.) Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 92.0.902.67 - Microsoft Corporation) Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 133.0.3065.69 - Microsoft Corporation) Hidden Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4693.1005 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\...\OneDriveSetup.exe) (Version: 21.220.1024.0005 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden Mozilla Firefox 43.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla) NVIDIA GeForce Experience 2.5.11.45 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.11.45 - NVIDIA Corporation) NVIDIA Grafiktreiber 353.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.62 - NVIDIA Corporation) NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation) Polar Bowler 1st Frame (HKLM-x32\...\WTA-d421feba-0407-4288-b40c-de6252d31e83) (Version: 3.0.2.59 - WildTangent) Hidden Qualcomm Atheros 11ac Wireless LAN&Bluetooth Installer (HKLM-x32\...\{3241744A-BA36-41F0-B4AA-EF3946D00632}) (Version: 11.0.0.0099 - Qualcomm Atheros) Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.31213 - Realtek Semiconductor Corp.) Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8083 - Realtek Semiconductor Corp.) Rory's Restaurant (HKLM-x32\...\WTA-6e35cc10-c9f5-48e9-baf9-e03aec7ff14d) (Version: 3.0.2.126 - WildTangent) Hidden Runefall (HKLM-x32\...\WTA-4527bc60-c537-4ef8-8c87-cc9539bb1241) (Version: 3.0.2.126 - WildTangent) Hidden Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version: - WildTangent) Hidden Vegas World (HKLM-x32\...\WildTangentGDF-acer-vegasworld) (Version: 13.0.0.6 - WildTangent) Hidden Villagers and Heroes (HKLM-x32\...\WildTangentGDF-acer-villagersandheroes) (Version: 13.0.0.6 - WildTangent) Hidden WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent) WildTangent Games App (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer) (Version: 4.0.11.16 - WildTangent) Hidden Packages: ========= Acer Explorer -> C:\Program Files\WindowsApps\acerincorporated.acerexplorer_2.0.3007.0_x86__48frkmn4z8aw4 [2025-02-18] (Acer Incorporated) Kindle -> C:\Program Files\WindowsApps\amznmobilellc.kindleforwindows8_2.1.0.2_neutral__stfe6vwa9jnbp [2025-02-18] (AMZN Mobile LLC) Music Maker Jam -> C:\Program Files\WindowsApps\MAGIX.MusicMakerJam_3.1.1.0_x64__a2t3txkz9j1jw [2025-02-18] (MAGIX) ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated -> Acer Incorporated) ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated -> Acer Incorporated) ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated -> Acer Incorporated) ContextMenuHandlers1: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => C:\Program Files (x86)\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2015-01-27] (Foxit Software Incorporated -> Foxit Software Inc.) ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\mcafee\msc\McCtxMenuFrmWrk.dll [2015-07-16] (McAfee, Inc. -> McAfee, Inc.) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-02-18] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7ee21f0fcd504371\igfxDTCM.dll [2016-11-23] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation) ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-05-01] (NVIDIA Corporation -> NVIDIA Corporation) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-02-18] (Malwarebytes Inc. -> Malwarebytes) ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\mcafee\msc\McCtxMenuFrmWrk.dll [2015-07-16] (McAfee, Inc. -> McAfee, Inc.) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2015-05-06 18:06 - 2015-05-06 18:06 - 000086016 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Acer\AOP Framework\Interop.WUApiLib.2.0.dll 2016-02-26 04:05 - 2015-07-14 05:06 - 001942360 _____ (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [File not signed] C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll ==================== Alternate Data Streams (Whitelisted) ======== (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\Users\Emilie\Downloads:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Pictures:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\.dbxignore:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Die ästhetische Psychologie Hugo Münsterbergs.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Elements 10B8 - Verknüpfung.lnk:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Masterarbeit_Final_Mutti.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Office Home and Student 2016:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Spotify.lnk:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\.dbxignore:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\0307190535.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020 (1).pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2021.pdf:com.dropbox.attrs [52] AlternateDataStreams: C:\Users\Emilie\Downloads\2021-10141374.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\2022-12197991.pdf:com.dropbox.attrs [13] AlternateDataStreams: C:\Users\Emilie\Downloads\2307191224.pdf:com.dropbox.attrs [13] AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17(1).pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\4661823_t201402060_mit_Zusatzinfos.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\5072581_Wertermittlungsliste.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\9MYHZ8.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\Angebot-7099991-41393-00_2020-05-01_13-55.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\Anleitung_WISOSB20.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750(1).pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\FRSTEnglish.exe:MBAM.Zone.Identifier [225] AlternateDataStreams: C:\Users\Emilie\Documents\.dbxignore:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\AirDroid:com.dropbox.attrs [13] AlternateDataStreams: C:\Users\Emilie\Documents\amazon_bestellung_glühbirne_a.PNG:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\ausschreibung_projektbearbeiter_in_zip_2022_0.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Barmer_Unterlagen:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Benutzerdefinierte Office-Vorlagen:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Bewerbungen_Alt:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Bürgeramt:com.dropbox.attrs [13] AlternateDataStreams: C:\Users\Emilie\Documents\CyberLink:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Deutsche Bank:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\DKB:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Eigene Bilder:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Erasmus+2018:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Favorites:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Fax:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\FitX-2020-04-06_Kuendigung.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Flamenco:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\HandyHüllle_Bestellung.PNG:com.dropbox.attrs [52] AlternateDataStreams: C:\Users\Emilie\Documents\Hörbücher und Comedy:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Immatrikulationsbescheinigungen_BA:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Indien-Unterlagen:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Jobs2022.PNG:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\JobsNGO_Savethechildren.PNG:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Kottbusser Damm 8:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Kreuzworträtsel_Geburtstag_Kerstin.docx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:3or4kl4x13tuuug3Byamue2s4b [93] AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\*****, Emilie - Einkommensteuer 2019.steuer2019:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Lebenslauf_Emilie*****_Therapie.docx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\MADRID_2017_2018:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Master_Imma_Exma:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\NIE:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Outlook-Dateien:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Podcast.docx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Rückenkurs:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Sanitas:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Scanned Documents:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Smartmobil:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Steuer:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Synchronbuchautorin Kurs.docx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Tickets:com.dropbox.attrs [52] AlternateDataStreams: C:\Users\Emilie\Documents\VID_20210121_191050.mp4:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Wirbelsäulengymnastik:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\WS2016_2017 Masterarbeit:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Übergabeprotokoll_Feuerbachstraße.pdf:com.dropbox.attrs [54] ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer (Whitelisted) ============= HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer15.msn.com/?pc=ACTE HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer15.msn.com/?pc=ACTE Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2015-07-16] (McAfee, Inc. -> McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2015-07-16] (McAfee, Inc. -> McAfee, Inc.) (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\...\localhost -> localhost ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 12:04 - 2025-02-18 08:57 - 000000852 _____ C:\WINDOWS\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\ HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\Control Panel\Desktop\\Wallpaper -> c:\users\emilie\pictures\bilder\2019\img_20190531_123605.jpg DNS Servers: 192.168.2.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. Network Binding: ============= Ethernet: Realtek PCIe GBE Family Controller -> rt640x64.sys Bluetooth-Netzwerkverbindung: Bluetooth Device (Personal Area Network) -> bthpan.sys WLAN: Qualcomm Atheros QCA61x4A Wireless Network Adapter -> Qcamain10x64.sys ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{B72C14F9-5EBE-4CD4-B3FA-B14ACA07AAE7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.136.3203.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{F088D4B7-C4A1-4331-B8EC-B50800F00F46}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.136.3203.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{2288632D-FF55-46FD-8F44-3DBB2F04F5E9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.136.3203.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{ECDC2DA5-4098-47C8-A2EA-62D812819CC6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.136.3203.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.) FirewallRules: [{D2319136-30A8-41F3-8DE0-AAD1AB97DA1F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe (CyberLink Corp. -> CyberLink Corp.) FirewallRules: [{8FAA3C7C-DE8C-4120-AC01-423E055ABA2F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe (CyberLink Corp. -> CyberLink Corp.) FirewallRules: [{5F105548-94E8-4F32-9052-3694D8BBA11C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe => No File FirewallRules: [{781DDE61-C9B9-4AA0-8467-5502CB428725}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe => No File FirewallRules: [{BC00D19D-DCA3-4A98-8F4B-ECD74B3798B3}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe => No File FirewallRules: [{2D7EAABE-B4FC-46D1-866E-4F8D0D60829F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe (CyberLink Corp. -> CyberLink Corp.) FirewallRules: [{F79E32A1-C16E-4EC6-8E01-236B0BFE321A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{59B4438B-830C-4BED-A154-F63CC7EB45B3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{86279AAC-4579-4651-B213-E30CD5425C5F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{79231BD8-E4E4-4FC7-A65D-656F40D3856B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{21786C41-20CF-4E44-90CF-777CF758C0B4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{694D477D-DCED-460C-A481-F6A3BBD22AC4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{80825BCB-9BFE-4129-AD90-9424883C4DC9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation) FirewallRules: [{BA76611A-53EA-4E98-9240-01D77C34D7E0}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer) FirewallRules: [{9374E55F-F31F-454E-8D92-4D68414A5ACB}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer) FirewallRules: [{05EBF720-9C08-4032-9F83-DDB35AB3D67E}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer) FirewallRules: [{D1449E72-5288-4FF3-88B1-34F6AC527BFF}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer) FirewallRules: [{153D9351-68F9-4CE6-AE66-5419EB374260}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe (Acer Incorporated -> Acer Cloud Technology) FirewallRules: [{227DE642-B4A4-40DB-B65D-741AF59B20FE}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe (Acer Incorporated -> Acer Cloud Technology) FirewallRules: [{E0BBD98A-E2CA-44F7-97E6-4DC6B859B476}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc. -> McAfee, Inc.) FirewallRules: [{DA225F5C-C571-418A-9132-30223D45C585}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{91692DC0-BF42-45CE-82A5-6E667F038C2E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) FirewallRules: [{BD119173-2DBD-4D41-97F8-C693A535793E}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\133.0.3065.69\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation) FirewallRules: [{8AF13718-4B22-4CC1-A04A-A845CB1C8574}] => (Allow) C:\Program Files\Avast Software\SecureLine VPN\Vpn.exe (Avast Software s.r.o. -> Gen Digital Inc.) FirewallRules: [{7FB7A19C-3970-4B6E-A9C9-B555DC4BC07E}] => (Allow) C:\Program Files\Avast Software\SecureLine VPN\Vpn.exe (Avast Software s.r.o. -> Gen Digital Inc.) ==================== Restore Points ========================= 18-02-2025 08:20:22 Windows Modules Installer 18-02-2025 08:36:35 18.02.2024 ==================== Faulty Device Manager Devices ============ ==================== Event log errors: ======================== Application errors: ================== Error: (02/18/2025 09:51:57 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten. Error: (02/18/2025 09:29:29 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten. Error: (02/18/2025 09:23:03 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: nvvsvc.exe, Version: 8.17.13.5362, Zeitstempel: 0x55b03dc7 Name des fehlerhaften Moduls: NVCPL.DLL_unloaded, Version: 8.17.13.8205, Zeitstempel: 0x59079649 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000000000000141f ID des fehlerhaften Prozesses: 0x98c Startzeit der fehlerhaften Anwendung: 0x01db81de416cc07f Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\nvvsvc.exe Pfad des fehlerhaften Moduls: NVCPL.DLL Berichtskennung: 85611c6c-cb0d-49d9-b499-e45aa34d28c9 Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (02/18/2025 09:21:21 AM) (Source: VSS) (EventID: 13) (User: ) Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} und dem Namen "CEventSystem" kann nicht gestartet werden. [0x8007045b, Der Computer wird heruntergefahren.] Error: (02/18/2025 09:18:40 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten. Error: (02/18/2025 08:55:48 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten. Error: (02/18/2025 08:53:25 AM) (Source: SecurityCenter) (EventID: 17) (User: ) Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten. Error: (02/18/2025 08:50:27 AM) (Source: Service1) (EventID: 0) (User: ) Description: Fehler beim Verarbeiten von Sitzungsänderung. System.IO.IOException: Der Prozess kann nicht auf die Datei "C:\OEM\AcerLogs\Services.log" zugreifen, da sie von einem anderen Prozess verwendet wird. bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost) bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost) bei System.IO.StreamWriter.CreateFile(String path, Boolean append, Boolean checkHost) bei System.IO.StreamWriter..ctor(String path, Boolean append, Encoding encoding, Int32 bufferSize, Boolean checkHost) bei System.IO.StreamWriter..ctor(String path, Boolean append) bei WindowsService1.Se... System errors: ============= Error: (02/18/2025 09:28:51 AM) (Source: Service Control Manager) (EventID: 7023) (User: ) Description: Der Dienst "Broker für Laufzeitüberwachung der Systemüberwachung" wurde mit folgendem Fehler beendet: %%3489660935 Error: (02/18/2025 09:28:06 AM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT) Description: Der Server "{209500FC-6B45-4693-8871-6296C4843751}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error: (02/18/2025 09:27:08 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Übermittlungsoptimierung" wurde nicht richtig gestartet. Error: (02/18/2025 09:24:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (02/18/2025 09:24:00 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht. Error: (02/18/2025 09:23:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde aufgrund folgenden Fehlers nicht gestartet: Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung. Error: (02/18/2025 09:23:30 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht. Error: (02/18/2025 09:22:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "DCIService" wurde aufgrund folgenden Fehlers nicht gestartet: Das System kann die angegebene Datei nicht finden. CodeIntegrity: =============== Date: 2025-02-18 09:51:57 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements. Date: 2025-02-18 09:30:31 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Microsoft signing level requirements. ==================== Memory info =========================== BIOS: Insyde Corp. V1.09 05/17/2016 Motherboard: Acer Aspire VN7-792G Processor: Intel(R) Core(TM) i5-6300HQ CPU @ 2.30GHz Percentage of memory in use: 56% Total physical RAM: 8056.16 MB Available physical RAM: 3496.43 MB Total Virtual: 9976.16 MB Available Virtual: 5236.28 MB ==================== Drives ================================ Drive c: (Acer) (Fixed) (Total:930.86 GB) (Free:762.1 GB) (Model: TOSHIBA MQ02ABD100H) NTFS \\?\Volume{53aeb305-538e-4a4b-b132-682275219f17}\ () (Fixed) (Total:0.54 GB) (Free:0.08 GB) NTFS \\?\Volume{0a15119a-b7be-4531-a347-543a13aea1d2}\ (ESP) (Fixed) (Total:0.09 GB) (Free:0.04 GB) FAT32 ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (Size: 931.5 GB) (Disk ID: 969F2557) Partition: GPT. ==================== End of Addition.txt ======================= |
![]() | #2 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 10: PUP.Adware.Heuristic![]() Mein Name ist Matthias und ich werde dir bei der Analyse und Bereinigung deines Systems helfen. Poste bitte alle Logdateien von AdwCleaner (ADW) und Malwarebytes-AntiMalware (MBAM) mit den erwähnten Funden. |
![]() | #3 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 10: PUP.Adware.Heuristic Schon mal ein kleiner Hinweis vorab: Das Geld für McAfee hättest du dir sparen können:
__________________McAfee LiveSafe – Internet Security (HKLM-x32\...\MSC) (Version: 14.0.1122 - McAfee, Inc.) Sobald du alle Logs von ADW und MBAM gepostet hast, können wir anfangen. |
![]() | #4 |
| ![]() Logs Danke dir! Hier sind die Logs: MBAM Code:
ATTFilter Malwarebytes www.malwarebytes.com -Protokolldetails- Scan-Datum: 18.02.2025 Scan-Zeit: 09:01 Protokolldatei: 823c3fe0-edce-11ef-a662-3065ec9a1e2c.json -Softwaredaten- Version: 5.2.6.163 Komponentenversion: 1.0.5146 Version des Aktualisierungspakets: 1.0.96058 Lizenz: Kostenlos -Systemdaten- Betriebssystem: Windows 10 (Build 19045.5487) CPU: x64 Dateisystem: NTFS Benutzer: LAPTOP-9AF8ONMC\Emilie -Scan-Übersicht- Scan-Typ: Bedrohungs-Scan Scan gestartet von: Manuell Ergebnis: Abgeschlossen Gescannte Objekte: 193673 Erkannte Bedrohungen: 241 In die Quarantäne verschobene Bedrohungen: 241 Abgelaufene Zeit: 9 Min., 58 Sek. -Scan-Optionen- Speicher: Aktiviert Start: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Erkennung PUM: Erkennung -Scan-Details- Prozess: 0 (keine bösartigen Elemente erkannt) Modul: 0 (keine bösartigen Elemente erkannt) Registrierungsschlüssel: 6 PUP.Optional.Amazon1Button, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Amazon1ButtonBrowserHelper.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, HKLM\SOFTWARE\CLASSES\APPID\Amazon1ButtonBrowserHelper.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Amazon1ButtonRuntime.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, HKLM\SOFTWARE\CLASSES\APPID\Amazon1ButtonRuntime.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\Amazon1ButtonBrowserHelper.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\Amazon1ButtonRuntime.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , Registrierungswert: 2 PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, 5728, -1, 0.0.0, , action, , , PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, 5728, -1, 0.0.0, , action, , , Registrierungsdaten: 0 (keine bösartigen Elemente erkannt) Daten-Stream: 0 (keine bösartigen Elemente erkannt) Ordner: 60 PUP.Optional.Amazon1Button, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\DISTRIBUTION\EXTENSIONS\ABB@AMAZON.COM, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\campaign-attribution, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\attribution, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\network, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\storage, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\config, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\tabs, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\util, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\internals\storage, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\apps\titan, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\strategies, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\storage, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\internals, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\internals, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\apps, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\util, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients\network, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform\sandbox, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\extensions\mode, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\components, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\extensions, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\wrappers, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\storage, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\customstyles\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\customstyles, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\defaults\preferences, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\META-INF, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\defaults, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button.AppFlsh, C:\PROGRAM FILES (X86)\AMAZON\AMAZON1BUTTONAPP, In Quarantäne, 5728, 809559, 1.0.96058, , ame, , , Datei: 173 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\defaults\preferences\prefs.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\META-INF\manifest.mf, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D81B35D77F553B1714B274B57484F546, 211D9739B92E6110EBFCE4BFFB3F85B7562FD7B512A42532B7B64746C83BB40E PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\META-INF\zigbert.rsa, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , E38645A6E82531AD93CF1F27CBEFF4A4, AAADFA1D87543DA785C8C11240E76BC6C31985F477DBA577EA441AB8A662C7F2 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\META-INF\zigbert.sf, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 529E2F2E5F18A3DB3E6F473F336E315F, D3A9C40CF47DCDBFCD8F37EF50F3E6A55AF0944E4C30BAC99250C688F44BD0E5 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\internals\storage\async-in-memory-store.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B0AD0A364905B25E217768A549C9A292, E073C1580B9966CCEF028C2FECF7791D429BBC21AC4B814EFB88883DBBE5EEED PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\internals\session.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 9E7C86189F026F22E085E4B0CFEEFD20, D7CB00E7ED746B69A7906779773CBCE021B57522876EE70579851F9BF8F4431E PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\cherami-service.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1E78FBA55944AE658A88689637EA3626, DDA42218B3DFA56621EE8D290600BDA85345F4BF5E6BC4942D38EB1F6DB04796 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients\network\sdk-request-client.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 69B9BA89DE5038BAAB2BAA26E1FCCF26, 95FFB26C20CC06687305A68977EDAB5D451517D3B0F3AA82A4A322A2E017B500 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients\network\xhr-client.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D7B37DE2C69EB4FC6225BF43903F83F6, 6AF4E497BD4C60CBF89537019F2F2637F55AFEDE67B68AA5726B8CD2858FD87B PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients\s3-client.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , BC06173A64A72D784C2CEEEA006A2217, F6E1FBE582FB793D5A26348259771F689C5DF12F7EBD5DB95C9DC750A5A748DE PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\ajax.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3F240DAED44A6A35D8505DCD0F70E5CF, EF3800E3CB60AC60D68D92B5AE79E5178787324511CF2A160B3892ACFD2869CF PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\countdown-latch.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 072EADAC5ED0C9C17E9BE1284F32DE08, 59C30D59460DEFC76E927A6AFC7FB21A479D2839909A7464FBE964DBCD4B6F35 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\events.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 7675246E26F75237D4C9C7C0D6ACCE78, B0EFA2DBFAB3D542F065D9EA36C3C8D9822CA9A6206A6B85D9430DFC6140394C PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\flow.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3AABF2CF6D5D7A89AEC9499EAB451D26, 84D1B878B4806E3A108912415FC7A25605F62E5B2AFC74ADB434D3196E787EC9 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\lang.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F23A26CBB43F242F366BA64575761D43, 0789AA2D77854B1B0E5B9CBCE8D58916DBFE3B6A6789318EF2B4F8827444AF44 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\options.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 0D92B93731BDCBF6062FDEA0C1913501, AA9BFF5FA3ACAD1C6A4D3753A3FD1E6069C8C0BBBD95A03C5FF5ED906C2C8465 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\query-string-map.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F9F4BE7795ABF3905BCF3ED6AE9EA4D9, FCE174C7718C8F75558E06C092D282344DD92C7B513E0BA8117FEBDE3FA8D64F PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\ready-gate.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 83AF30538EE15FC625559681A5A82E06, 0EAA7E0F40072C8A0A9156ADEBCE13DB6156A0CEF14E94C66365EE2E2DC97706 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\serdes.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5BC6EFBDACCCA1B7B7FED122D259269C, 1F46FE2E62A66757C1EA7A9500209011F13CA442E892F62E9CBCBD1810B381D1 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\simple-future.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1B643C7D8622288997521BD63D6E5506, D3238797C53CBD5F3AF36C185C67B3DCC54C24B4C8533C4B00E930B091FD1883 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\state-guard.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 75003F461768BC3A2349AEC36CA090C7, EBBC2848E25B6C62A4FF011629951B8F6584A9AB6B534F11FB4E28E2B465BAD0 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\state-latch.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 18DBE0C4F4EB427703CCDF9EB2537DAD, 051939D04060C0F59F2F675D2ADD5A1B51893A990E03AFED7E89E5110075707D PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\state-machine.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 63AA36374A8A8FFEFFD80885FB74BC4A, 7E521081B7BFD363C1266E194DB866942424B059E55EA2023979750A916CA069 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\task-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 102C301977F44979A575A26D5CB6438E, D9500A5A1F0C4E668C6131FA7E1D84E606CD857AD2CB02AA91F5E44E450A90C7 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\timeout-hash.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 7A00500E0AAA8AE50129CBEE423CF5EB, 0BBBEE9CA4B4F08E0F941446A94AD0F8A5681F494C6B340A37E5BB01150F66F9 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\uri.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5EA97F1788BF5F5E6A2D8E2D963D1EC4, 7FFC220BE44A34BB7A91486D2885DA0FB01E833FE259E9B94DD49255E459ACD1 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\uuid.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3C431156D5A3DEDEF82CFF5114C9C611, 7DE3449E20C4FAC48900B7B867CF93A679722FA620ED47FFD0948BDBC07238A9 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\internals\message-subscriber.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , BD88F1B9FD615197992E7717458B569A, 84EA9856E78D23F717954A96D1C37998A0CCAA73A7FDB209B29EFFB4D716E363 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\strategies\port-transport-strategy.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 353C6E2275EBE9F0323B3027D992F1DB, DFD596A02E6A68A089F8845C29F1C1F017DDB644E07359CA5B8C755630BF0B5B PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\strategies\post-message-transport-strategy.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 6FACA6302837455BAF06F916257089DF, ACC7992FB61095130FBC1D9590E13046CF20A62091EA9A875FAB44B4D5873B83 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\composite-message-channel.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 474C41B3C2AA74D1E0316C561D1D5866, 84C7B03378BB9C0ABFD86649A438CEEFCB590863DA06E32A691C6EF161A1C881 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\invocation-router.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 95840F0D781AEEA5D608F0C41C250EB1, AB49B20853931359EC4AD6F3FEAC76DEB3D3CC53DDCDB2007E613F15EB39C51C PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-bus.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B4E2FC8A6192768109AF4DD409EFA97F, 0FAFAE1D84B6B3CF3076607FEE4844B9F6147F36EF001B02362BF8240AD860ED PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-channel.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 0CF2F120690958C0640183D14763D185, C3E449081BED3D108C36273B7BCE8714F1529A7F10AB9A3CD21256996B3B737D PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-dispatcher.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F97825E6B7FDFA9D0F0AD6232952E2B8, 278836E781B4EBA0055CBF88081F939E8C99D6D70327651C77C3FE1DBA88FA53 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-exchange.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , AA4A650F925DA347644988CB0BF3858B, 6F25FF5545C61D2B65D888FB436165526A92C9E1F1A989485581E1BE46B6189A PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-factory.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , E40EF3A5326F476E40B1169D51D5501E, F1C3DC5CE824203FD8B3C9644A0BAF1DAAB44BF97FA80EA496586CB527787A2D PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-framework.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 81053355C1A197DE0EAF4B969BD8F669, BF717A1D948DCBCBE0F0F0C4F43E1E64B7B1B3DC4EAEC29B1BD8D2F35EA0D273 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\transport-strategy-factory.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 35640945985D7B7C76F69C9605F026F3, C0B18AD3D2162F5D9ABA8A1374BB3B199DC385932D4578103C1579D4E45B9831 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\base-process.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5B7BCDB861F0D357C429A1142D18679C, 1267D74C80911A5A1F394CB28DF06FE44E4BF0BFB0895061F0F661FBF366390D PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\handshake.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1084D9B4DEFE7706E1993C576A681433, 72FC8932009839CF16DB592FDCB67D339AA291820AFAB8B8C19832995A34F89E PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\health-checker.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 0FF5420CD38B47259DA5CFC12C5FE242, B7C0B962739896845728C941ACBCBE4B1CD0E6B03EAFC48D7D61F0F9561B723F PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\pid.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , FF6A1F30E17F6A55EEEF25565E20052B, D1DFBE3EB445CB9E31A54F4E2DDA9CF66C70F16BBF0CFD239922F12877F00D5D PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\process-state.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1823FE0A8537A3B226363C5E45574259, 4640E1604F37EAE1BCAA1036E42CC54251DDC8AE0902308477B324DBC955E468 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\remote-process.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D5C83AB3D85B5179747F2995BC3BD534, 84E715FE3A6F4A139A80C8AF053C5DB2865017B28070BBA45BF28ED417041ED2 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\process-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EFD24F7BDEAC6494AA856159409DAABE, 9F23E0320162625D70A30966CCA1913CBE6E3CDEB5FC3533CFE75B9F731E5679 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\underscore.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , DD9663BE9A71F3570BC35F0EDBA28712, 163189EF69A3C210A04BB4CAC2C336119D78B576FB84B4231977514419EB0FAF PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\apps\titan\spawner.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 95CA4A1B95F2B71FF3896230C5442F23, 518D8698FC62E6C75DA8D7607BE8CCAFEE495E907C1BA7AF88E45C00AC4D145E PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\campaign-attribution\ubp-feature-campaign-attribution.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5A3D34EDDA166A08A5ECDDC9DAA765C1, 53EFF9AA5C467C61527584B38A24B1D7778737BDCA57558922AC5469ED0DB8F1 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\addon-uninstaller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , C277A15207CD91465FF3FAA779B0D138, 03ACF34B7C828DEB337D33976B57711A97C31ADA55174A97F9AF0CF5F0D73D75 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\alerts-badge-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3E8E42D6ED7F8A73C706D2CED8766312, E1C0260B626E913363566D6F0678D34FD9D0BDE11AE44062386D50C5EF18F229 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\attribution-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B48DFE2718B762AB0800C912DC0C5623, 524EEF5132301DF7B668AC9CB10CE414AB9CAE2D2C3345306114A4FD03B66A2F PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\configuration-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 459677CE3DC5D6902A8FA47294A316BE, F87D4AC8AB0397697BA825C2B83ECD8F1EA0E401A8444BAC44A79AC1E976969D PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\guid-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 2B8DFED4E963C71853CAF7F96DF5CA38, DB256D6FA6BE79704F82F04018D37444805BBC99B7765500292224D9B7FAD1B2 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\mode-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 627D14465FFF631FE0A144CC013A3DB1, 08C60EEA36D01A6032F2786D745D6CFEA657597C3C064F413E45A46066E3DA00 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\ping-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3F557B74C21F38D839A4A05739C5A21E, F0DE0CFED940D6586E681DBA4753F84146522201DD837515F7BE3F1869C26697 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\promotion-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 2DBFF92796821310FF19C323E1371B46, E1A2CB0E1EEA2C307B5DADC4748DE0A1E926054C99EB36A5C5C18E5F8F7BB172 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\token-vendor.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , DCF2D043548A3E4F2038D597BCC97D3A, 9C919E7B7E8028B73CE993B02AA126139257809C9B755B119C9BEBCB38105488 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\uninstall-wishlist.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EC7FE501DA17F8B85F93ACACCA4F74BD, 1179C34BDB7B2E0A9683167FDE5554B614F42269944FBB2D19FC6B326C5194CB PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\attribution\attribution.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D5713BCF847747CA023B72A81B93B4A3, 2B02831EC9DD667DFB1EA7B8DDDD4D7181F2AF5FAFAD4CFE48D33271ECD8FA7A PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\config\config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 79F1471FD1448B74BFF3C474A2A3BB65, D7001C13B04DE678F6515AF9368D5614CA08387B12784399F27D709794CF07BB PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\config\user-settings.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 6397C7CF703A9DE673B5CF334EA83EAA, 2001DDF990E927C8C9AA0A04D27631102D947FCB305644E4CF98560C9AD20861 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\content.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , A78F7EBAB8DE7F084CB3A42B5E834FD4, 8E56C58A29BC76E1CFD66AB7B393701869B010DC8BAF998F9FC475B885D9007C PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\interaction.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D7CC29767BC26B5D477C4517F7DDE3D9, B606B9DD19D3AE138B8AB8C529E1215171E35A0F4DF273CAE1443CA3046A9D16 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\meta.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 35A9285F4DB4976011A4846E69AC8AFD, B409695A6421591E93C148DB5056B552FCAB8CDB2BC8C29139089E1ECF32F861 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\page-nav.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 59C24BBF3DD4A83F827B6512BBE33654, 23FE1431CF61E68E81F726D3559398D9FF6DE8B2960218F3169E545965D0ABAE PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\sandbox.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 4545FF7337A9E1201AC8E9C804E4C014, 0397C889A3980AAACD456D42E41262B9B092723D0BF2718581444CD91DA1E2CD PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\style.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1CD9210F0922B5B3202B4B9FD8ACBE5C, B58DEEEA0FB4675BD649A2985B7E779C67531EB583AD2E9C19548DAEF9E60AD8 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\system.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 2D2CE27524A400975F9B231A7FD2AED6, B615E36540E24FC9D53172E37E66857A65AF04F217CCCE8CC1DD91803E626C42 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\network\amazon-xhr-request.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 91AAFDCE1FF19FB2A8DAD53A11C3245C, A553F6EF78F53B50BFBE99069124839B371CDC706C151509173C0E1A52ACC2F9 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\storage\simple-storage.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 29068224FE2BC8DFEEE3DF3E30D91A4A, F91B1F01CB5D60963420F1CCFFAB6A8272444A70C85E5F77A2F5490A21807F46 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\tabs\active-tab.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EE6B06BFA0D05BB8E751274E435A887A, D641D9F77BB1B2D77D281085AF968F1BBA0B08344902EE704F6179E78FEA32DA PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\util\filtering-dispatcher.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 9FCE48161183AC17A2C6BDE91F907DCA, DBF9E0006BE391374A7D76D42EFD2E63E737E7C8C56D05798999AC363DD407AA PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\alerts-badge-count.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , BEC460148CB688E79C0C415026064363, 59FF72C7466B83CCBBCB0BB1B7D915F9B0303C448FA723E939AC9D7FD1ADCDA2 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\contextual-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 589B6931870A7517FDADB4D4B33CBCC5, 53EE9C7EFE0D82F4789036ECC1E398FD66DA4EC2F0231073E905B740F077D76A PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\interaction-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5FD1FF74D815E7B0A9E0B0C4FBD6892E, 1D8BD79335AA2C0F91562FD30BF9FABBA65348C982B958E8F14586A7E9DB1D05 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\meta-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D834830EF2629F3E3428BDDA01CA3260, 18C3F8A073E865B6F49B0547B422F02AA3871F686EB083E04B84419713181845 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\platform-api-registry.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 96F6445548340231C4D5B55BD490E553, 3544C3943517959906797E1F20D10C16169D21A8CEF083586BBC47F6C887C00C PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\platform-service.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B3CC430A25F62B77E0140D738807169A, B901FD18EC2A1A58525ABF1521CB3714AF8095A8B88A6B83F58E6091E1F9FEE9 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\sandbox-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5CDE743111ABF7815C1562757A70E551, 675CFB0AA5FB4452537F8B658FFF945466A5AE5626A8B9EB4D87C1688D10862A PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\scraper-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 6A3208CCEC955ADA00953822B2491F42, 003EC655ADFD81683D753A283B9B05C476C12362D3C6FAE7BA89855E68AD86EF PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\style-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 99DE027AF2848B5BBA43AD174D351782, 7599129B888AC3D31D30426106C35A18F426F2496BC8D3E89C3E16DC7096E3C8 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\storage\simple-storage.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F1A69D71C22C0107815376C8D8EF5852, 67AB5C3E0D1F1823C795016FDC183809A6414FED45BD34DB8486A26E0C9041DF PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\util\mode.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5D2DCC82B1F262ABF893A86DBA1A488E, 9F5431915225BBBD99B1E14C4B9C54B33CCFCABC90D1C95FC190803B551791DB PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\util\smile-mode.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 473298BA8A3BDFA6AA462EBC28027BD9, 1819013DBDBC92E8DDA98C95BF413D720681A09EAFD2A769E014CE182E439262 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\one-button-app.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 9D835527971B40FDD8353AD176750EA3, 3E2BEE9BCE73ECDCAC908FCFCFD7568FF68A8C3CB8B0B2943550AC05A69852DD PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\any.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\async.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\bluebird.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1AE945B7BE46E6A2513EE553AA082A3C, FD818A2C6DA503CFF4F69DE0BB8AE75A2805B17C7D0E2E8EBA7C56EC9E3204E9 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\call_get.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\cancel.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\captured_trace.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\catch_filter.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\direct_resolve.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\errors.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\errors_api_rejection.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\es5.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\filter.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\finally.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\generators.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\global.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\map.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\nodeify.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\progress.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promise.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promise_array.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promise_resolver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promise_spawn.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promisify.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\properties_promise_array.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\props.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\queue.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\race.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\reduce.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\schedule.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\settle.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\settled_promise_array.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\some.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\some_promise_array.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\synchronous_inspection.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\thenables.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\timers.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\util.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\customstyles\lib\customstyles.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EE6C8CB0DD6DA7FE35EB1204964FF2BC, 86703B569899CFD7D3D6FE635CACBF4EE6248B048A9713402BB7BCAD53310EB2 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\host-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5C3E44348811ED03DC423F8D4E525197, 9FF43CCBCEAA25AB00883A3EBE8D13848B6D83535E6B60520EA11D75C0FB307E PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\HOWTO, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 113589070A26155A369BC73B7DD41A1A, B59C4B053061C341ECF9B0F525FF0668A20B6B0CF0CE67F242962F660C288ADD PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\interaction-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , E796BEB30736847CE954678C922A1DA5, 73D0DD5E72E4A67C47C90E42EFD04576AD6B5768CD72650829D3E2A5FDD01447 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\meta-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 7CC0CC86DC1CBA2FC4418D33B86003D6, 93D16836C6C6ADFF4520ACCF216AEF54DC97328E5A737EE9187E9A4F59B6F239 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\sandbox-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 58B6A99C9C3CA2E217E4A31B8A814E78, 043D04B6FEEB5F78A56E32DE1F3DE83BECAB6DF937263ED4A0CAF7029B1CDECB PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\scraper-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 4495369043B226449ED6AD6B491B3DD7, 74F9F88805AAE47A0C836542B3BF1521F62C7DAE1DD95CC792C80194440D5B68 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\style-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 4E121F0280145245B14DE520D67900D6, 2B841EC209B3466AA4480E742D4B9E097B9656D7DA64FA544F8679B9C3A9ADF4 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\hover-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B2EBF6E6FC61D1F3E3F61134A9DA2788, 343E72DDCE64C957FC3FEBBAE07701F586DBD16D12B013B54F5C986D44A5A837 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\interaction-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B572407E0C81C95BFEF763B7670D7DBE, 1D3B08270958AA70BE29973AE9B87F56EC6EC831F10F9A1E081CDCF44B4DC841 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\meta-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B3EC9E97CA55CD6E1AD7BBB8206B2FC5, EA39B76F95F77950F74DE6E82287BE6B393B99BCC902D66B7772C747BE6A18BF PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\sandbox-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 6D1F883A71165DEB5BB95BACF79A641A, 5FCDF159AE4F1C91C0BC0F4E4BB69830D6EA19FF688F86E84553F60293BB0E07 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\scraper-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , FEF90B8B18A295A8F3BB97ACB03DBF7C, F95B7EB1962C83374D374B8D76711E79E6D34865DCA590A741BB897F858B54FD PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\style-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F36F6000B96E3D9D511D2D72C81E7410, 01C19EE9123CFE306E128CFF12EC62A7214A824BE196F1585AA4D14DE34660C2 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\1button-asmile-16.ico, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , CAFF44101A0E9787F047CFBC4FBA2CF3, C3E8E6AD8D0AF2E2F1AEC62D47E3D7B980B558C561855B2C8399013B1E862623 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\1button-asmile-24.ico, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , DA4DC611243BCCBAF0CB9B8C78C653FA, B6792E577674E93A894027CFE936CC16DC8ED8FAAA49B767E4C5D8FC9DF4F072 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\buttonstyle.css, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1D509F5CDC36D4850F4760AFB47AC8A5, D2712AF7F84E00925D100BE3DDA396BEB141DF24723B90E34C5E2304BBFA2840 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\injectedmessagelistener.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 0849CDB956CE37E8815F179908401B85, 681DC1D44A1F19035E265871101DD1C95999A055C73E2BBFFF342C4332BB2715 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\logo.png, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 8F396843950111F1944A62FEF9CEA6EB, 287F8A17B0D2F17A5862D64963AF328637680E060B087A7DB310ECD102CF7346 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\oneButton.xml, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 7A1DAD30F5092F981D6BB92329FA609E, EEBF12C5F5EE0FF471359398F9199ECABD0E9DFB05E77E71E8F54109BEC467CB PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\ubpmessage.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 65022B1949FA8290F1103CF708E4BC11, 0433560DCDAF252DE71DA9D7FE514AF00C915A39ADCE84948D6558AC89DB44A0 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\ubpmessagelistener.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , DE10F32FCEB63BEAE64E28F5C5ED769C, B5CA5A00E5C823AA42ED0033312E083B6B76AF45FC0357D2B72E06B486493F19 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\main-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , A24A1272009F489F9B3AA2D34B8BBCC3, 51CD77D6879101D7C7B9C236B360B3040943CF8CA04F257A67ADB06576F4A5B8 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\mode-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , E9B52326B928DD39CCE657E79DD11CC1, CCAFF80C835D9396A237A268594ACBC179C1601BB0D41AD0436EFDA6B502C8FD PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\notification-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5F2DFA225435279ABF4132BC1212A5D6, 4C9CF3E29A8D03FE0EFED23DC1D38600D5E8EFAE6310C196FD0EC8A5F4C7E755 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\product-compass-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 81F49DA89DF8B60D3C859912FB6B76DD, 4A5558F6367836A37B94FEAC2754B8C32B53F05C2C42D6629D716CD0D99172C7 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\titan-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5B040F719CF378010C6E7FD512EFBFF2, BC5C54960B26553CA21AF487C9547118F1A4306D5C010BD37ACADD6607323E10 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\components\application-state.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 602D5F7E8BC379116C1434FF2A1A42AF, 60CFFF6B0BCC4610CDA795068DAA125FF0E68842F6E031DF6F4E32B97CD96CE3 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\components\campaign-attribution-agent.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 24B6B0FF2CC586DCC3169FFF8896E1AD, 578CE82FD9E41FED434E24F32B836464CA477F6B14D11A9085251D9CE3CD80D2 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\components\product-compass-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 94A75D1B61E2F15A4F2204F05D713C28, 2ED3E70D4E9E82BC58AC11ED4A4CA1A949E14477A02D5783F029A583DD4CF7DC PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\extensions\mode\smile-mode-extension.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , BE798B15614495D5EC70978286D7EC68, 1A4D0FDBE6AF780D1D3F3B7C58C118FC0C9170DDDC8F1A3D3D867F080B6C3C8E PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform\sandbox\page-worker-remote-process-sandbox-delegate.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , C09A2664439B92D88BEC42A62FC061D7, 236E04CB4FFBF580E2CCEB1801B332D65BB12E97CC461E01D086540EAC5C4383 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform\platform-service-bootstrapper.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 96EF5A0F29076646AF96EEA0597C0A6B, 47AD3BA274A925355C8FE6F56E4DBBC0EFD8FAA1CC5D2FDC7DFCD2D9525AEAE9 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform\product-compass-frame.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 931CBA9F398B5A07D327CA32D9E9CEF3, 6F99303A5505E3641E8F19F490860A52DC8D770E82627F1941793733B6D50B59 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\storage\native-storage.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 8BF3B4F9FBA62D73198B434C75F87EA0, 641D8D4A93B364BACE045EF062CEAEA88A6FF26A88CBB801088BF553A0CC0860 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\wrappers\tab-map.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , C70A446FC69D88FBA8937B8A02FA0573, 1059FA7471D9C2EBAC1151EB7E1D75CE4EC2E01C6F015357F14E9242B0B5B06B PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\attribution-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 97D1877DB141DC8080926428E9C9C021, 155AC61755E3FB9A51B4BAC983AC4CD773352DAB05496B254C76DA6CF91BA29C PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\extension-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3CA7DF0CAADA145BAFEC419B52C22F25, BCE95CB4877969D72144B01C18169EC4756007B8AA701A992D7BA159297EE3DB PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\main.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 281A480E76D5E867DA71197133A35305, 29DD44183411AF459B421B1596F22C943522DC2E2918CC10A717428A1E6DAF84 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\runtime.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , C9E6EE1B1026397DF744E14FD0C14C28, 93601312AFE28CD2C901A211C79C923C8ED587EB4C470F0DF89A90B943074E67 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\bootstrap.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EDEEB3F4B254CCF86A7E0C9F85133384, 747EB3BE7184769237CDECBD8D6C03DCC2876CD4BA2A3DF69650608BA3B0CC8E PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\harness-options.json, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 74EBDC8BFE3B8E02D3DF92773232CB9E, 497118CD23AD382B1C0DE723EE86A87B7DCFECD0199B1417F0779CD57C5F20CF PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\icon.png, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 8F396843950111F1944A62FEF9CEA6EB, 287F8A17B0D2F17A5862D64963AF328637680E060B087A7DB310ECD102CF7346 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\install.rdf, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 818498CAB8C952A945EEC2EE85516996, EC54551B9F32F61EE4D629EF89010E154E043BC51D37E8FB5FB36110C524AA68 PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\locales.json, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , A77421EB4FFAC031FF52E9D3B935998D, 8EBD8B8FF913E81C38A0C56E92417060D7CB578A662A601AA3EA98C5DA177682 PUP.Optional.ChipDe, C:\USERS\EMILIE\DOWNLOADS\ADWCLEANER - CHIP INSTALLER _AUZAV.EXE, In Quarantäne, 3874, 562568, 1.0.96058, , ame, , F5980F17F44DA870072C5CE396EB01BF, 2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B PUP.Optional.ChipDe, C:\USERS\EMILIE\DOWNLOADS\ADWCLEANER - CHIP INSTALLER _UEUAV.EXE, In Quarantäne, 3874, 562568, 1.0.96058, , ame, , F5980F17F44DA870072C5CE396EB01BF, 2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B PUP.Optional.BundleInstaller, C:\USERS\EMILIE\DOWNLOADS\SODAPDFDESKTOP14.EXE, In Quarantäne, 43, 1172329, 1.0.96058, , ame, , C88A0CEEFD336B577FA57E42D39D8886, F79AEDD0023456424EE3216A3EF9FA181546B0B0B6A21F191A4927527BBAED09 PUP.Optional.ChipDe, C:\USERS\EMILIE\DOWNLOADS\MICROSOFT EDGE - CHIP INSTALLER _MC6WP (1).EXE, In Quarantäne, 3874, 562568, 1.0.96058, , ame, , F5980F17F44DA870072C5CE396EB01BF, 2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B PUP.Optional.ChipDe, C:\USERS\EMILIE\DOWNLOADS\MICROSOFT EDGE - CHIP INSTALLER _MC6WP.EXE, In Quarantäne, 3874, 562568, 1.0.96058, , ame, , F5980F17F44DA870072C5CE396EB01BF, 2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B Physischer Sektor: 0 (keine bösartigen Elemente erkannt) WMI: 0 (keine bösartigen Elemente erkannt) (end) ADW (ist der letzte Log, solltest du die vorhergehenden auch benötigen, gib gerne Bescheid): Code:
ATTFilter # ------------------------------- # Malwarebytes AdwCleaner 8.4.2.0 # ------------------------------- # Build: 03-04-2024 # Database: 2024-03-04.1 (Local) # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Scan # ------------------------------- # Start: 02-18-2025 # Duration: 00:00:12 # OS: Windows 10 (Build 19045.5487) # Scanned: 32104 # Detected: 70 ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** PUP.Adware.Heuristic HKCU\SOFTWARE\438f84b93ab73e6e9ccd233d1abe724b ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries found. ***** [ Chromium URLs ] ***** No malicious Chromium URLs found. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries found. ***** [ Firefox URLs ] ***** No malicious Firefox URLs found. ***** [ Hosts File Entries ] ***** No malicious hosts file entries found. ***** [ Preinstalled Software ] ***** Preinstalled.ACERAOPFramework Folder C:\Program Files (x86)\ACER\AOP FRAMEWORK Preinstalled.ACERAOPFramework Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|BacKGround Agent Preinstalled.ACERAOPFramework Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4A37A114-702F-4055-A4B6-16571D4A5353} Preinstalled.ACERClear.fiShellExtension Registry HKLM\Software\Classes\CLSID\{ED32C084-BABB-11E1-B491-D4D66088709B} Preinstalled.ACERClear.fiShellExtension Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{ED32C084-BABB-11E1-B491-D4D66088709B} Preinstalled.AcerCareCenter File C:\Users\Public\Desktop\Acer Care Center.lnk Preinstalled.AcerCareCenter Folder C:\Program Files (x86)\ACER\CARE CENTER Preinstalled.AcerCareCenter Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A1AECEC-0766-473B-AE79-EAAA31DE758F} Preinstalled.AcerCareCenter Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A1AECEC-0766-473B-AE79-EAAA31DE758F} Preinstalled.AcerCareCenter Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A250F7B-4F8A-4FEA-8CAE-31F28DA85202} Preinstalled.AcerCareCenter Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACCAgent Preinstalled.AcerCareCenter Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACCBackgroundApplication Preinstalled.AcerCareCenter Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1AF41E84-3408-499A-8C93-8891F0612719} Preinstalled.AcerExplorerAgent Folder C:\Program Files\ACER\ACER EXPLORER AGENT Preinstalled.AcerExplorerAgent Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4D0F42CF-1693-43D9-BDC8-19141D023EE0} Preinstalled.AcerPortal Folder C:\Program Files (x86)\ACER\ACER PORTAL Preinstalled.AcerPortal Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{932EC946-767B-4FAA-9B54-A4A4A2DF1822} Preinstalled.AcerPortal Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AcerCloud Preinstalled.AcerPortal Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13} Preinstalled.AcerPowerManagement Folder C:\Program Files\ACER\ACER POWER MANAGEMENT Preinstalled.AcerQuickAccess File C:\Users\Emilie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Acer Quick Access.lnk Preinstalled.AcerQuickAccess Folder C:\Program Files\ACER\ACER QUICK ACCESS Preinstalled.AcerQuickAccess Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25746121-EB7E-4B7E-9BA4-27CAC8316AA5} Preinstalled.AcerQuickAccess Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D20A4DC-B257-40AB-809F-565BEC5D3B5E} Preinstalled.AcerQuickAccess Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Power Button Preinstalled.AcerQuickAccess Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Quick Access Preinstalled.AcerQuickAccess Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E3678E72-78E3-4F91-A9FB-913876FF6DA2} Preinstalled.AcerUEIPFramework Folder C:\Program Files\ACER\USER EXPERIENCE IMPROVEMENT PROGRAM\FRAMEWORK Preinstalled.AcerUEIPFramework Folder C:\Program Files\ACER\USER EXPERIENCE IMPROVEMENT PROGRAM\PLUGIN\APPMONITOR Preinstalled.AcerUEIPFramework Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6} Preinstalled.AcerUEIPFramework Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UbtFrameworkService Preinstalled.AcerUEIPFramework Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{12A718F2-2357-4D41-9E1F-18583A4745F7} Preinstalled.AcerabBox Registry HKLM\Software\Classes\CLSID\{5CCE71FA-9F61-4F24-9CD1-98D819B40D68} Preinstalled.GatewayPowerManagement Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59} Preinstalled.GatewayPowerManagement Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Power Management Preinstalled.HPCleanFLC File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk Preinstalled.LenovoPowerDVD Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A} Preinstalled.LenovoPowerDVD Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{B46BEA36-0B71-4A4E-AE41-87241643FA0A} Preinstalled.PackardBellPowerManagement Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{91F52DE4-B789-42B0-9311-A349F10E5479} Preinstalled.WildTangentGamesBundle File C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games App - acer.lnk Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDGAMES Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDGAMES\12 LABOURS OF HERCULES III GIRL POWER Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDGAMES\HOME MAKEOVER Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDGAMES\JEWEL MATCH 3 Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDGAMES\JEWEL MATCH SNOWSCAPES Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDGAMES\MAGIC ACADEMY Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDGAMES\POLAR BOWLER 1ST FRAME Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDGAMES\RUNEFALL Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDTANGENT GAMES Preinstalled.WildTangentGamesBundle Folder C:\Program Files (x86)\WILDTANGENT GAMES\APP Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6} Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6} Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-4527bc60-c537-4ef8-8c87-cc9539bb1241 Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-4c57b906-a5ca-4c03-9798-68e13f3261f1 Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-679326c7-f13f-4d56-ae2e-6a7fee2304c7 Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-6e35cc10-c9f5-48e9-baf9-e03aec7ff14d Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-8d9b4f73-bb47-4fea-917d-c50dd2ffed5c Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-ad853ef4-00ea-4eae-8b6e-18dee9cd5722 Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-d421feba-0407-4288-b40c-de6252d31e83 Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-ff512562-ab4b-4aae-9e8c-1d09bd47ac58 Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangent wildgames Master Uninstall Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-acer-vegasworld Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-acer-villagersandheroes Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-acer-genres Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-acer-main Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer Preinstalled.WildTangentGamesBundle Registry HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6} Preinstalled.WildTangentGamesBundle Registry HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6} AdwCleaner[S00].txt - [9475 octets] - [17/02/2025 13:29:23] AdwCleaner[C00].txt - [9839 octets] - [17/02/2025 13:36:51] AdwCleaner[S01].txt - [2005 octets] - [17/02/2025 19:40:32] AdwCleaner[C01].txt - [2081 octets] - [17/02/2025 19:42:15] AdwCleaner[S02].txt - [1706 octets] - [17/02/2025 19:58:02] AdwCleaner[C02].txt - [1876 octets] - [17/02/2025 19:58:18] AdwCleaner[S03].txt - [1786 octets] - [17/02/2025 20:00:33] AdwCleaner[C03].txt - [1976 octets] - [17/02/2025 20:01:03] AdwCleaner[S04].txt - [1950 octets] - [17/02/2025 21:21:16] AdwCleaner[C04].txt - [2236 octets] - [17/02/2025 21:21:32] AdwCleaner[S05].txt - [17036 octets] - [18/02/2025 08:03:33] AdwCleaner[C05].txt - [6839 octets] - [18/02/2025 08:04:54] AdwCleaner[S06].txt - [11462 octets] - [18/02/2025 08:45:38] AdwCleaner[C06].txt - [2504 octets] - [18/02/2025 08:46:03] AdwCleaner[S07].txt - [11585 octets] - [18/02/2025 08:57:08] AdwCleaner[C07].txt - [2627 octets] - [18/02/2025 08:57:22] ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S08].txt ########## |
![]() | #5 | |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 10: PUP.Adware.Heuristic Und noch ein 2. Hinweis vorab: Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #6 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 10: PUP.Adware.Heuristic Danke für die Logs, ich bereite eine Reparatur vor. Ursache für deine "Infektionen" sind deine Downloadquellen. Halte dich von Chip.de fern! Eine kurze Information vorab: ![]() Downloadquellen Die folgenden Seiten verteilen Software häufig mit einem sog. "Installer", mit dem Potentiell Unerwünschte Programme (PUP) oder Adware installiert werden können. Vereinzelt beinhalten diese "Installer" sogar Trojaner. Vermeide daher unbedingt die folgenden Seiten:
Für Windows gibt es seit einiger Zeit einen brauchbaren Paketmanager, der mit einfachen Befehlen es erlaubt, automatisiert Software herunterzuladen und zu installieren. Das erspart eine Menge Arbeit, denn ohne einen Paketmanager muss man jedes Programm selbst prüfen und separat manuell updaten, vorher manuell noch runterladen etc. pp. - siehe auch --> chocolatey Paketmanager für Windows Wir empfehlen dringend, alle Programme, sofern verfügbar, über chocolatey zu installieren. Falls du schon mit Linux zu tun hattest, wird dir die Syntax sehr vertraut sein. Die FAQs zu choco findest du da --> Chocolatey: Häufig gestellte Fragen (englisch) Selbstverständlich darfst du auch Fragen zu chocolatey im o.g. Thread zu chocolatey stellen. Für den seltenen Fall, dass du das benötigte Programm nicht im repository von chocolatey findest: Lade diese Software immer direkt beim jeweiligen Hersteller / Entwickler. |
![]() | #7 |
| ![]() Windows 10: PUP.Adware.Heuristic Danke dir für die schnelle Hilfe und die Hinweise! Das werde ich in Zukunft beachten! Den Paketmanager schaue ich mir an, sobald ich die Reparatur vollzogen habe. |
![]() | #8 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 10: PUP.Adware.Heuristic Wir führen eine Reparatur mit FRST durch. Diese wird bestimmt ein paar Minuten dauern, weil wir die Systemdateien auch gleich noch auf Fehler hin überprüfen. Du solltest nebenbei nichts anderes am System machen. Reparatur mit FRST HINWEIS AN ALLE MITLESER: Dieses FRST-Skript ist ausschließlich für diesen Nutzer gedacht und sollte niemals 1:1 für ein anderes System verwendet werden!
|
![]() | #9 |
| ![]() Windows 10: PUP.Adware.Heuristic Das hat etwas länger gedauert aber hier ist die Datei fixlog.txt: Code:
ATTFilter Fix result of Farbar Recovery Scan Tool (x64) Version: 18-02-2025 Ran by Emilie (18-02-2025 16:44:18) Run:1 Running from C:\Users\Emilie\Downloads Loaded Profiles: Emilie Boot Mode: Normal ============================================== fixlist content: ***************** Start:: CreateRestorePoint: CloseProcesses: AlternateDataStreams: C:\Users\Emilie\Downloads:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Pictures:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\.dbxignore:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Die ästhetische Psychologie Hugo Münsterbergs.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Elements 10B8 - Verknüpfung.lnk:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Masterarbeit_Final_Mutti.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Office Home and Student 2016:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Desktop\Spotify.lnk:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\.dbxignore:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\0307190535.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020 (1).pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2021.pdf:com.dropbox.attrs [52] AlternateDataStreams: C:\Users\Emilie\Downloads\2021-10141374.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\2022-12197991.pdf:com.dropbox.attrs [13] AlternateDataStreams: C:\Users\Emilie\Downloads\2307191224.pdf:com.dropbox.attrs [13] AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17(1).pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\4661823_t201402060_mit_Zusatzinfos.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\5072581_Wertermittlungsliste.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\9MYHZ8.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\Angebot-7099991-41393-00_2020-05-01_13-55.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\Anleitung_WISOSB20.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750(1).pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Downloads\FRSTEnglish.exe:MBAM.Zone.Identifier [225] AlternateDataStreams: C:\Users\Emilie\Documents\.dbxignore:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\AirDroid:com.dropbox.attrs [13] AlternateDataStreams: C:\Users\Emilie\Documents\amazon_bestellung_glühbirne_a.PNG:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\ausschreibung_projektbearbeiter_in_zip_2022_0.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Barmer_Unterlagen:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Benutzerdefinierte Office-Vorlagen:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Bewerbungen_Alt:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Bürgeramt:com.dropbox.attrs [13] AlternateDataStreams: C:\Users\Emilie\Documents\CyberLink:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Deutsche Bank:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\DKB:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Eigene Bilder:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Erasmus+2018:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Favorites:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Fax:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\FitX-2020-04-06_Kuendigung.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Flamenco:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\HandyHüllle_Bestellung.PNG:com.dropbox.attrs [52] AlternateDataStreams: C:\Users\Emilie\Documents\Hörbücher und Comedy:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Immatrikulationsbescheinigungen_BA:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Indien-Unterlagen:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Jobs2022.PNG:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\JobsNGO_Savethechildren.PNG:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Kottbusser Damm 8:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Kreuzworträtsel_Geburtstag_Kerstin.docx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:3or4kl4x13tuuug3Byamue2s4b [93] AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0] AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.pdf:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\*****, Emilie - Einkommensteuer 2019.steuer2019:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Lebenslauf_Emilie*****_Therapie.docx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\MADRID_2017_2018:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Master_Imma_Exma:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\NIE:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Outlook-Dateien:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Podcast.docx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Rückenkurs:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Sanitas:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Scanned Documents:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Smartmobil:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Steuer:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Synchronbuchautorin Kurs.docx:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Tickets:com.dropbox.attrs [52] AlternateDataStreams: C:\Users\Emilie\Documents\VID_20210121_191050.mp4:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Wirbelsäulengymnastik:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\WS2016_2017 Masterarbeit:com.dropbox.attrs [54] AlternateDataStreams: C:\Users\Emilie\Documents\Übergabeprotokoll_Feuerbachstraße.pdf:com.dropbox.attrs [54] HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION Startup: C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BitCleaner Tasker.lnk [2025-02-18] <==== ATTENTION ShortcutTarget: BitCleaner Tasker.lnk -> C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner\BitCleaner Tasker.exe (BINARYLABS LIMITED -> Binarylabs LTD) <==== ATTENTION C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner Task: {25746121-EB7E-4B7E-9BA4-27CAC8316AA5} - \Power Button -> No File <==== ATTENTION Task: {4F117C79-2706-4FBF-A748-C0259F51CEFA} - \Software Update Application -> No File <==== ATTENTION Task: {511D4F70-5C34-4428-AFAE-10D347114DCB} - \Microsoft\Windows\Windows Defender\Windows Defender Verification -> No File <==== ATTENTION Task: {611C823C-437B-46E7-9683-5312DFFCFD7B} - \Microsoft\Windows\UpdateOrchestrator\Policy Install -> No File <==== ATTENTION Task: {6A1AECEC-0766-473B-AE79-EAAA31DE758F} - \ACCAgent -> No File <==== ATTENTION Task: {6A250F7B-4F8A-4FEA-8CAE-31F28DA85202} - \ACCBackgroundApplication -> No File <==== ATTENTION Task: {6C488413-8509-4D62-94EB-159DC0C33122} - \Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan -> No File <==== ATTENTION Task: {7A003965-A297-4DC6-B15B-852D798391E0} - \Microsoft\Windows\UpdateOrchestrator\Reboot -> No File <==== ATTENTION Task: {7F4D5DE3-08C8-4008-AC82-C84BCA4B16DB} - \FUBTrackingByPLD -> No File <==== ATTENTION Task: {848DCC36-520C-4946-BF68-C7EFFEFA2F84} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot -> No File <==== ATTENTION Task: {8D20A4DC-B257-40AB-809F-565BEC5D3B5E} - \Quick Access -> No File <==== ATTENTION Task: {932EC946-767B-4FAA-9B54-A4A4A2DF1822} - \AcerCloud -> No File <==== ATTENTION Task: {93C99DC9-B400-40D5-A6DF-4310EAF3F1A6} - \Avast SecureLine -> No File <==== ATTENTION Task: {992AC68E-7168-40E1-B170-A736E71585A5} - \Microsoft\Office\Microsoft Office Touchless Attach Notification -> No File <==== ATTENTION Task: {A364E297-00AD-490D-900E-22AC34598C71} - \Microsoft\Windows\UpdateOrchestrator\Maintenance Install -> No File <==== ATTENTION Task: {BD02C08D-BA88-414E-A5E4-15FAFEB09DF3} - \Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance -> No File <==== ATTENTION Task: {C33F4607-C279-4257-9039-34FF9FE1F21A} - \Microsoft\Windows\AppID\SmartScreenSpecific -> No File <==== ATTENTION Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - \Microsoft\Windows\WindowsUpdate\sih -> No File <==== ATTENTION Task: {E135F27F-CC77-4798-8095-E4F7E716DE31} - \Microsoft\Windows\Windows Defender\Windows Defender Cleanup -> No File <==== ATTENTION Task: {E6010D43-6AE7-4B59-8E67-EC78FD8E8E96} - \Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler -> No File <==== ATTENTION Task: {E98AFDFB-4B5D-4DC1-9DCF-5DD16ED4B901} - \Microsoft\Windows\Plug and Play\Plug and Play Cleanup -> No File <==== ATTENTION Task: {EA3F661E-B31C-44A9-B40C-E3D5D56149D4} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display -> No File <==== ATTENTION Task: {F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6} - \UbtFrameworkService -> No File <==== ATTENTION Task: {FBE1992D-A1B2-44DD-9601-A1A2F799B096} - \ACC -> No File <==== ATTENTION Task: {FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59} - \Power Management -> No File <==== ATTENTION C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\abb@amazon.com S2 DCIService; C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe [X] <==== ATTENTION C:\Users\AllUserName\AppData\Roaming\BitCleaner C:\Program Files (x86)\Lavasoft C:\ProgramData\Application Data\Lavasoft C:\ProgramData\Lavasoft C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft C:\Users\AllUserName\AppData\Local\Lavasoft C:\Users\AllUserName\AppData\Roaming\Lavasoft DeleteKey: HKCU\Software\Lavasoft DeleteKey: HKLM\Software\Wow6432Node\Lavasoft DeleteKey: HKCU\SOFTWARE\438f84b93ab73e6e9ccd233d1abe724b CMD: cscript /nologo %systemroot%\System32\slmgr.vbs /dlv CMD: netsh winsock reset CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: netsh winhttp reset proxy CMD: Bitsadmin /Reset /Allusers CMD: Winmgmt /salvagerepository CMD: Winmgmt /verifyrepository CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R CMD: sfc /scannow Hosts: RemoveProxy: EmptyTemp: End:: ***************** Restore point was successfully created. Processes closed successfully. C:\Users\Emilie\Downloads => ":com.dropbox.attrs" ADS could not remove. C:\Users\Emilie\Pictures => ":com.dropbox.attrs" ADS could not remove. C:\Users\Emilie\Desktop\.dbxignore => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Desktop\Die ästhetische Psychologie Hugo Münsterbergs.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Desktop\Elements 10B8 - Verknüpfung.lnk => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Desktop\Masterarbeit_Final_Mutti.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Desktop\Office Home and Student 2016 => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Desktop\Spotify.lnk => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\.dbxignore => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\0307190535.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020 (1).pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2021.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\2021-10141374.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\2022-12197991.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\2307191224.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17(1).pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\4661823_t201402060_mit_Zusatzinfos.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\5072581_Wertermittlungsliste.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\9MYHZ8.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\Angebot-7099991-41393-00_2020-05-01_13-55.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\Anleitung_WISOSB20.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\ARC6903138750(1).pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Downloads\ARC6903138750.pdf => ":com.dropbox.attrs" ADS removed successfully "C:\Users\Emilie\Downloads\FRSTEnglish.exe" => ":MBAM.Zone.Identifier" ADS not found. C:\Users\Emilie\Documents\.dbxignore => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\AirDroid => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\amazon_bestellung_glühbirne_a.PNG => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\ausschreibung_projektbearbeiter_in_zip_2022_0.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Barmer_Unterlagen => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Benutzerdefinierte Office-Vorlagen => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Bewerbungen_Alt => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Bürgeramt => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\CyberLink => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Deutsche Bank => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\DKB => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Eigene Bilder => ":com.dropbox.attrs" ADS could not remove. C:\Users\Emilie\Documents\Erasmus+2018 => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Favorites => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Fax => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\FitX-2020-04-06_Kuendigung.pdf => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Flamenco => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\HandyHüllle_Bestellung.PNG => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Hörbücher und Comedy => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Immatrikulationsbescheinigungen_BA => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Indien-Unterlagen => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Jobs2022.PNG => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\JobsNGO_Savethechildren.PNG => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Kottbusser Damm 8 => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Kreuzworträtsel_Geburtstag_Kerstin.docx => ":com.dropbox.attrs" ADS removed successfully "C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg" => ":3or4kl4x13tuuug3Byamue2s4b" ADS not found. "C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg" => ":com.dropbox.attrs" ADS not found. "C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg" => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS not found. "C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.pdf" => ":com.dropbox.attrs" ADS not found. "C:\Users\Emilie\Documents\*****, Emilie - Einkommensteuer 2019.steuer2019" => ":com.dropbox.attrs" ADS not found. "C:\Users\Emilie\Documents\Lebenslauf_Emilie*****_Therapie.docx" => ":com.dropbox.attrs" ADS not found. C:\Users\Emilie\Documents\MADRID_2017_2018 => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Master_Imma_Exma => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\NIE => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Outlook-Dateien => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Podcast.docx => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Rückenkurs => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Sanitas => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Scanned Documents => ":com.dropbox.attrs" ADS could not remove. C:\Users\Emilie\Documents\Smartmobil => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Steuer => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Synchronbuchautorin Kurs.docx => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Tickets => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\VID_20210121_191050.mp4 => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Wirbelsäulengymnastik => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\WS2016_2017 Masterarbeit => ":com.dropbox.attrs" ADS removed successfully C:\Users\Emilie\Documents\Übergabeprotokoll_Feuerbachstraße.pdf => ":com.dropbox.attrs" ADS removed successfully HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => removed successfully C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BitCleaner Tasker.lnk => moved successfully C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner\BitCleaner Tasker.exe => moved successfully "C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner" Folder move: C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner => moved successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{25746121-EB7E-4B7E-9BA4-27CAC8316AA5}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25746121-EB7E-4B7E-9BA4-27CAC8316AA5}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Power Button" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4F117C79-2706-4FBF-A748-C0259F51CEFA}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F117C79-2706-4FBF-A748-C0259F51CEFA}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Software Update Application" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{511D4F70-5C34-4428-AFAE-10D347114DCB}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{511D4F70-5C34-4428-AFAE-10D347114DCB}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Verification" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{611C823C-437B-46E7-9683-5312DFFCFD7B}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{611C823C-437B-46E7-9683-5312DFFCFD7B}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Policy Install" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A1AECEC-0766-473B-AE79-EAAA31DE758F}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A1AECEC-0766-473B-AE79-EAAA31DE758F}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACCAgent" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6A250F7B-4F8A-4FEA-8CAE-31F28DA85202}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A250F7B-4F8A-4FEA-8CAE-31F28DA85202}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACCBackgroundApplication" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C488413-8509-4D62-94EB-159DC0C33122}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C488413-8509-4D62-94EB-159DC0C33122}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7A003965-A297-4DC6-B15B-852D798391E0}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A003965-A297-4DC6-B15B-852D798391E0}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7F4D5DE3-08C8-4008-AC82-C84BCA4B16DB}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7F4D5DE3-08C8-4008-AC82-C84BCA4B16DB}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FUBTrackingByPLD" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{848DCC36-520C-4946-BF68-C7EFFEFA2F84}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{848DCC36-520C-4946-BF68-C7EFFEFA2F84}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8D20A4DC-B257-40AB-809F-565BEC5D3B5E}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D20A4DC-B257-40AB-809F-565BEC5D3B5E}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Quick Access" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{932EC946-767B-4FAA-9B54-A4A4A2DF1822}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{932EC946-767B-4FAA-9B54-A4A4A2DF1822}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AcerCloud" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{93C99DC9-B400-40D5-A6DF-4310EAF3F1A6}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{93C99DC9-B400-40D5-A6DF-4310EAF3F1A6}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast SecureLine" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{992AC68E-7168-40E1-B170-A736E71585A5}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{992AC68E-7168-40E1-B170-A736E71585A5}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Office\Microsoft Office Touchless Attach Notification" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A364E297-00AD-490D-900E-22AC34598C71}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A364E297-00AD-490D-900E-22AC34598C71}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Maintenance Install" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD02C08D-BA88-414E-A5E4-15FAFEB09DF3}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD02C08D-BA88-414E-A5E4-15FAFEB09DF3}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C33F4607-C279-4257-9039-34FF9FE1F21A}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C33F4607-C279-4257-9039-34FF9FE1F21A}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\AppID\SmartScreenSpecific" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsUpdate\sih" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E135F27F-CC77-4798-8095-E4F7E716DE31}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E135F27F-CC77-4798-8095-E4F7E716DE31}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Cleanup" => not found "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E6010D43-6AE7-4B59-8E67-EC78FD8E8E96}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6010D43-6AE7-4B59-8E67-EC78FD8E8E96}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E98AFDFB-4B5D-4DC1-9DCF-5DD16ED4B901}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E98AFDFB-4B5D-4DC1-9DCF-5DD16ED4B901}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Plug and Play\Plug and Play Cleanup" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA3F661E-B31C-44A9-B40C-E3D5D56149D4}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA3F661E-B31C-44A9-B40C-E3D5D56149D4}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UbtFrameworkService" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FBE1992D-A1B2-44DD-9601-A1A2F799B096}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FBE1992D-A1B2-44DD-9601-A1A2F799B096}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACC" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59}" => removed successfully "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Power Management" => removed successfully "C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\abb@amazon.com" Folder move: C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\abb@amazon.com => moved successfully HKLM\System\CurrentControlSet\Services\DCIService => removed successfully DCIService => service removed successfully "C:\Users\ProgramData\AppData\Roaming\BitCleaner" => not found "C:\Users\Default\AppData\Roaming\BitCleaner" => not found "C:\Users\Emilie\AppData\Roaming\BitCleaner" => not found "C:\Users\Public\AppData\Roaming\BitCleaner" => not found "C:\Program Files (x86)\Lavasoft" Folder move: C:\Program Files (x86)\Lavasoft => moved successfully "C:\ProgramData\Application Data\Lavasoft" Folder move: C:\ProgramData\Application Data\Lavasoft => moved successfully "C:\ProgramData\Lavasoft" Folder move: C:\ProgramData\Lavasoft => moved successfully "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft" Folder move: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft => moved successfully "C:\Users\ProgramData\AppData\Local\Lavasoft" => not found "C:\Users\Default\AppData\Local\Lavasoft" => not found "C:\Users\Emilie\AppData\Local\Lavasoft" Folder move: C:\Users\Emilie\AppData\Local\Lavasoft => moved successfully "C:\Users\Public\AppData\Local\Lavasoft" => not found "C:\Users\ProgramData\AppData\Roaming\Lavasoft" => not found "C:\Users\Default\AppData\Roaming\Lavasoft" => not found "C:\Users\Emilie\AppData\Roaming\Lavasoft" Folder move: C:\Users\Emilie\AppData\Roaming\Lavasoft => moved successfully "C:\Users\Public\AppData\Roaming\Lavasoft" => not found HKCU\Software\Lavasoft => removed successfully HKLM\Software\Wow6432Node\Lavasoft => removed successfully HKCU\SOFTWARE\438f84b93ab73e6e9ccd233d1abe724b => not found ========= cscript /nologo %systemroot%\System32\slmgr.vbs /dlv ========= Softwarelizenzierungsdienst-Version: 10.0.19041.5486 Name: Windows(R), Core edition Beschreibung: Windows(R) Operating System, OEM_DM channel Aktivierungs-ID: 8db63db6-4f8f-46d6-a448-66444faaaa72 Anwendungs-ID: 55c92734-d682-4d71-983e-d6ec3f16059f Erweiterte PID: 03612-03259-590-980202-02-1031-19045.0000-0492025 Product Key-Kanal: OEM:DM Installations-ID: 712397573211500936751740479633014131501740885649006386437620724 Lizenz-URL verwenden: https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=DM URL fr die šberprfung: https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx Teil-Product Key: QJ3DR Lizenzstatus: Lizenziert Verbleibende Windows Rearm-Anzahl: 1001 Verbleibende SKU Rearm-Anzahl: 1001 Vertrauenswrdige Zeit: 18.02.2025 16:46:14 ========= End of CMD: ========= ========= netsh winsock reset ========= Der Winsock-Katalog wurde zurckgesetzt. Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen. ========= End of CMD: ========= ========= netsh advfirewall reset ========= OK. ========= End of CMD: ========= ========= netsh advfirewall set allprofiles state ON ========= OK. ========= End of CMD: ========= ========= netsh winhttp reset proxy ========= Aktuelle WinHTTP-Proxyeinstellungen: DirectAccess (kein Proxyserver). ========= End of CMD: ========= ========= Bitsadmin /Reset /Allusers ========= BITSADMIN version 3.0 BITS administration utility. (C) Copyright Microsoft Corp. {144701F6-5688-4268-8BA6-14DF94124BA1} canceled. 1 out of 1 jobs canceled. ========= End of CMD: ========= ========= Winmgmt /salvagerepository ========= Das WMI-Repository ist konsistent. ========= End of CMD: ========= ========= Winmgmt /verifyrepository ========= Das WMI-Repository ist konsistent. ========= End of CMD: ========= ========= "%WINDIR%\SYSTEM32\lodctr.exe" /R ========= Fehler: Die Leistungsindikatoreinstellung konnte nicht aus dem Systemsicherungsspeicher neu erstellt werden. Fehlercode: 2. ========= End of CMD: ========= ========= "%WINDIR%\SysWOW64\lodctr.exe" /R ========= Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden. ========= End of CMD: ========= ========= "%WINDIR%\SYSTEM32\lodctr.exe" /R ========= Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden. ========= End of CMD: ========= ========= "%WINDIR%\SysWOW64\lodctr.exe" /R ========= Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden. ========= End of CMD: ========= ========= sfc /scannow ========= Systemsuche wird gestartet. Dieser Vorgang kann einige Zeit dauern. Überprüfungsphase der Systemsuche wird gestartet. Überprüfung 0 % abgeschlossen. Überprüfung 1 % abgeschlossen. Überprüfung 1 % abgeschlossen. Überprüfung 2 % abgeschlossen. Überprüfung 3 % abgeschlossen. Überprüfung 3 % abgeschlossen. Überprüfung 4 % abgeschlossen. Überprüfung 5 % abgeschlossen. Überprüfung 5 % abgeschlossen. Überprüfung 6 % abgeschlossen. Überprüfung 7 % abgeschlossen. Überprüfung 7 % abgeschlossen. Überprüfung 8 % abgeschlossen. Überprüfung 9 % abgeschlossen. Überprüfung 9 % abgeschlossen. Überprüfung 10 % abgeschlossen. Überprüfung 11 % abgeschlossen. Überprüfung 11 % abgeschlossen. Überprüfung 12 % abgeschlossen. Überprüfung 12 % abgeschlossen. Überprüfung 13 % abgeschlossen. Überprüfung 14 % abgeschlossen. Überprüfung 14 % abgeschlossen. Überprüfung 15 % abgeschlossen. Überprüfung 16 % abgeschlossen. Überprüfung 16 % abgeschlossen. Überprüfung 17 % abgeschlossen. Überprüfung 18 % abgeschlossen. Überprüfung 18 % abgeschlossen. Überprüfung 19 % abgeschlossen. Überprüfung 20 % abgeschlossen. Überprüfung 20 % abgeschlossen. Überprüfung 21 % abgeschlossen. Überprüfung 22 % abgeschlossen. Überprüfung 22 % abgeschlossen. Überprüfung 23 % abgeschlossen. Überprüfung 23 % abgeschlossen. Überprüfung 24 % abgeschlossen. Überprüfung 25 % abgeschlossen. Überprüfung 25 % abgeschlossen. Überprüfung 26 % abgeschlossen. Überprüfung 27 % abgeschlossen. Überprüfung 27 % abgeschlossen. Überprüfung 28 % abgeschlossen. Überprüfung 29 % abgeschlossen. Überprüfung 29 % abgeschlossen. Überprüfung 30 % abgeschlossen. Überprüfung 31 % abgeschlossen. Überprüfung 31 % abgeschlossen. Überprüfung 32 % abgeschlossen. Überprüfung 33 % abgeschlossen. Überprüfung 33 % abgeschlossen. Überprüfung 34 % abgeschlossen. Überprüfung 34 % abgeschlossen. Überprüfung 35 % abgeschlossen. Überprüfung 36 % abgeschlossen. Überprüfung 36 % abgeschlossen. Überprüfung 37 % abgeschlossen. Überprüfung 38 % abgeschlossen. Überprüfung 38 % abgeschlossen. Überprüfung 39 % abgeschlossen. Überprüfung 40 % abgeschlossen. Überprüfung 40 % abgeschlossen. Überprüfung 41 % abgeschlossen. Überprüfung 42 % abgeschlossen. Überprüfung 42 % abgeschlossen. Überprüfung 43 % abgeschlossen. Überprüfung 44 % abgeschlossen. Überprüfung 44 % abgeschlossen. Überprüfung 45 % abgeschlossen. Überprüfung 45 % abgeschlossen. Überprüfung 46 % abgeschlossen. Überprüfung 47 % abgeschlossen. Überprüfung 47 % abgeschlossen. Überprüfung 48 % abgeschlossen. Überprüfung 49 % abgeschlossen. Überprüfung 49 % abgeschlossen. Überprüfung 50 % abgeschlossen. Überprüfung 51 % abgeschlossen. Überprüfung 51 % abgeschlossen. Überprüfung 52 % abgeschlossen. Überprüfung 53 % abgeschlossen. Überprüfung 53 % abgeschlossen. Überprüfung 54 % abgeschlossen. Überprüfung 55 % abgeschlossen. Überprüfung 55 % abgeschlossen. Überprüfung 56 % abgeschlossen. Überprüfung 56 % abgeschlossen. Überprüfung 57 % abgeschlossen. Überprüfung 58 % abgeschlossen. Überprüfung 58 % abgeschlossen. Überprüfung 59 % abgeschlossen. Überprüfung 60 % abgeschlossen. Überprüfung 60 % abgeschlossen. Überprüfung 61 % abgeschlossen. Überprüfung 62 % abgeschlossen. Überprüfung 62 % abgeschlossen. Überprüfung 63 % abgeschlossen. Überprüfung 64 % abgeschlossen. Überprüfung 64 % abgeschlossen. Überprüfung 65 % abgeschlossen. Überprüfung 66 % abgeschlossen. Überprüfung 66 % abgeschlossen. Überprüfung 67 % abgeschlossen. Überprüfung 68 % abgeschlossen. Überprüfung 68 % abgeschlossen. Überprüfung 69 % abgeschlossen. Überprüfung 69 % abgeschlossen. Überprüfung 70 % abgeschlossen. Überprüfung 71 % abgeschlossen. Überprüfung 71 % abgeschlossen. Überprüfung 72 % abgeschlossen. Überprüfung 73 % abgeschlossen. Überprüfung 73 % abgeschlossen. Überprüfung 74 % abgeschlossen. Überprüfung 75 % abgeschlossen. Überprüfung 75 % abgeschlossen. Überprüfung 76 % abgeschlossen. Überprüfung 77 % abgeschlossen. Überprüfung 77 % abgeschlossen. Überprüfung 78 % abgeschlossen. Überprüfung 79 % abgeschlossen. Überprüfung 79 % abgeschlossen. Überprüfung 80 % abgeschlossen. Überprüfung 80 % abgeschlossen. Überprüfung 81 % abgeschlossen. Überprüfung 82 % abgeschlossen. Überprüfung 82 % abgeschlossen. Überprüfung 83 % abgeschlossen. Überprüfung 84 % abgeschlossen. Überprüfung 84 % abgeschlossen. Überprüfung 85 % abgeschlossen. Überprüfung 86 % abgeschlossen. Überprüfung 86 % abgeschlossen. Überprüfung 87 % abgeschlossen. Überprüfung 88 % abgeschlossen. Überprüfung 88 % abgeschlossen. Überprüfung 89 % abgeschlossen. Überprüfung 90 % abgeschlossen. Überprüfung 90 % abgeschlossen. Überprüfung 91 % abgeschlossen. Überprüfung 91 % abgeschlossen. Überprüfung 92 % abgeschlossen. Überprüfung 93 % abgeschlossen. Überprüfung 93 % abgeschlossen. Überprüfung 94 % abgeschlossen. Überprüfung 95 % abgeschlossen. Überprüfung 95 % abgeschlossen. Überprüfung 96 % abgeschlossen. Überprüfung 97 % abgeschlossen. Überprüfung 97 % abgeschlossen. Überprüfung 98 % abgeschlossen. Überprüfung 99 % abgeschlossen. Überprüfung 99 % abgeschlossen. Überprüfung 100 % abgeschlossen. Der Windows-Ressourcenschutz hat keine Integritätsverletzungen gefunden. ========= End of CMD: ========= C:\Windows\System32\Drivers\etc\hosts => moved successfully Hosts restored successfully. ========= RemoveProxy: ========= HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully "HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully "HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully ========= End of RemoveProxy: ========= =========== EmptyTemp: ========== FlushDNS => completed BITS transfer queue => 1310720 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 25345394 B Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B Windows/system/drivers => 956385 B Edge => 0 B Firefox => 2815187 B Opera => 0 B Temp, IE cache, history, cookies, recent: Default => 7680 B ProgramData => 7680 B Public => 7680 B systemprofile => 7680 B systemprofile32 => 7680 B LocalService => 27036 B NetworkService => 30762 B Emilie => 106848282 B RecycleBin => 2274352204 B EmptyTemp: => 2.2 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 17:11:46 ==== |
![]() | #10 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windows 10: PUP.Adware.Heuristic Gut gemacht. ![]() Der in Windows integrierte Windows Defender genügt. Dieser aktiviert sich automatisch, sobald McAfee deinstalliert ist. Aber kein Tool erkennt 100%, das musst du dir immer bewusst machen. Findet AdwCleaner jetzt noch was? Mach mal einen neuen Suchlauf und berichte. Führe bitte SecurityCheck (SC) gemäß der bebilderten Anleitung aus und poste abschließend die Logdatei. Tipps gibts dann am Ende. Geändert von M-K-D-B (Heute um 19:46 Uhr) |
![]() | #11 |
| ![]() Windows 10: PUP.Adware.Heuristic Danke dir für die ganze Hilfe! ![]() Der AdwCleaner hat folgendes gemeldet: Sie sind frei von PUPs und Adware. Wir haben jedoch festgestellt, dass eine oder mehrere vorinstallierte Software auf ihrem Computer vorhanden ist. Im nächsten Bildschirm haben Sie die Möglichkeit, diese zu behalten oder zu entfernen. Ich habe die vorinstallierte Software jetzt nicht entfernt. Ist es ratsam das zu tun? Hier die SC Logdatei: Code:
ATTFilter SecurityCheck by glax24 & Severnyj v.1.4.0.58 [15.08.24] WebSite: www.safezone.cc DateLog: 18.02.2025 20:24:22 Path starting: C:\Users\Emilie\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe Log directory: C:\SecurityCheck\ IsAdmin: True User: Emilie VersionXML: 13.36is-18.02.2025 ___________________________________________________________________________ Windows 10 Core (x64) Release: 22H2 (10.0.19045.5487) Lang: German(0407) Installation date OS: 18.02.2025 02:00:51 LicenseStatus: Office 16, Office16O365ProPlusR_Subscription1 edition Windows is in Notification mode LicenseStatus: Office 16, Office16O365ProPlusR_Grace edition Windows is in Notification mode LicenseStatus: Windows(R), Core edition The machine is permanently activated. LicenseStatus: Office 16, Office16HomeStudentR_Retail edition The machine is permanently activated. Boot Mode: Normal Default Browser: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe SystemDrive: C: FS: [NTFS] Capacity: [930.9 Gb] Used: [167.7 Gb] Free: [763.2 Gb] ------------------------------- [ Windows ] ------------------------------- User Account Control enabled (Level 3) Sicherheitscenter (wscsvc) - The service is running Remoteregistrierung (RemoteRegistry) - The service has stopped SSDP-Suche (SSDPSRV) - The service is running Remotedesktopdienste (TermService) - The service has stopped Windows-Remoteverwaltung (WS-Verwaltung) (WinRM) - The service has stopped Background Intelligent Transfer Service (BITS) - The service has stopped Übermittlungsoptimierung (DoSvc) - The service is running Windows-Sicherheitsdienst (SecurityHealthService) - The service is running Update Orchestrator Service (UsoSvc) - The service is running Windows Update Medic Service (WaaSMedicSvc) - The service has stopped Windows Update (wuauserv) - The service is running ------------------------------ [ MS Office ] ------------------------------ Microsoft Office 2013 x86 v.15.0.4693.1005 ---------------------------- [ Antivirus_WMI ] ---------------------------- Malwarebytes (enabled and up to date) Windows Defender (disabled and up to date) McAfee Anti-Virus und Anti-Spyware (disabled) ---------------------------- [ Firewall_WMI ] ----------------------------- McAfee Firewall --------------------------- [ AntiSpyware_WMI ] --------------------------- Windows Defender (enabled and up to date) ---------------------- [ AntiVirusFirewallInstall ] ----------------------- Malwarebytes version 5.2.6.163 v.5.2.6.163 McAfee LiveSafe – Internet Security v.14.0.1122 Warning! Download Update --------------------------- [ OtherUtilities ] ---------------------------- NVIDIA GeForce Experience 2.5.11.45 v.2.5.11.45 Warning! Download Update Microsoft Edge WebView2-Laufzeit v.133.0.3065.69 Microsoft Office v.15.0.4693.1005 ------------------------------- [ Backup ] -------------------------------- Microsoft OneDrive v.21.220.1024.0005 Warning! Download Update ---------------------------- [ ProxyAndVPNs ] ----------------------------- Avast SecureLine VPN v.25.1.11083.14496 ------------------------------- [ Browser ] ------------------------------- Microsoft Edge v.133.0.3065.69 Mozilla Firefox 43.0.1 (x86 en-US) v.43.0.1 Warning! Download Update ------------------ [ AntivirusFirewallProcessServices ] ------------------- Avast SecureLine VPN (SecureLine) - The service is running C:\Program Files\AVAST Software\SecureLine VPN\VpnSvc.exe v.25.1.11083.0 C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe v.4.1.0.179 Malwarebytes Service (MBAMService) - The service is running C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe v.3.2.0.1372 C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe v.15.4.0.674 McAfee Validation Trust Protection Service (mfevtp) - The service is running C:\Windows\System32\mfevtps.exe McAfee Firewall Core Service (mfefire) - The service is running C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe v.15.4.0.674 McAfee AP Service (McAPExe) - The service is running C:\Program Files\mcafee\msc\McAPExe.exe v.14.0.1122.0 McAfee Personal Firewall Service (McMPFSvc) - The service is running C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe v.5.0.281.0 C:\Program Files\Common Files\McAfee\platform\McUICnt.exe v.7.0.285.0 McAfee CSP Service (mccspsvc) - The service is running C:\Program Files\Common Files\McAfee\CSP\1.5.471.0\McCSPServiceHost.exe v.1.5.471.0 McAfee Scanner (McODS) - The service has stopped McAfee Service Controller (mfemms) - The service is running C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe v.15.4.0.674 McAfee Home Network (HomeNetSvc) - The service is running McAfee VirusScan Announcer (McNaiAnn) - The service is running McAfee OOBE Service2 (McOobeSv2) - The service has stopped McAfee Platform Services (mcpltsvc) - The service is running McAfee Proxy Service (McProxy) - The service is running McAfee Boot Delay Start Service (mcbootdelaystartsvc) - The service is running McAfee Platform Services (mcpltsvc) - The service is running C:\Program Files\AVAST Software\SecureLine VPN\VpnSvc.exe v.25.1.11083.0 Microsoft Defender Antivirus-Dienst (WinDefend) - The service has stopped Microsoft Defender Antivirus-Netzwerkinspektionsdienst (WdNisSvc) - The service has stopped ----------------------------- [ End of Log ] ------------------------------ Eine kurze Frage noch: Auf meinem Desktop ist eine DBXIGNORE-Datei (.dbxignore) erschienen. Sollte ich die löschen? Geändert von Emma88 (Heute um 20:57 Uhr) |
![]() |
Themen zu Windows 10: PUP.Adware.Heuristic |
avast, browser, computer, cpu, defender, desktop, fehler, home, installation, internet, internet explorer, malware, mozilla, pup.optional.amazon1button, pup.optional.amazon1button.appflsh, pup.optional.bundleinstaller, pup.optional.chipde, realtek, registry, rundll, security, services.exe, software, sparbuch, svchost.exe, trojaner, usb, windows, wiso |