Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 10: PUP.Adware.Heuristic

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt Heute, 16:09   #1
Emma88
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic



Hallo zusammen,
seit ein paar Monaten hat sich hin und wieder in meinem Browser (Microsoft Edge) ein Fenster ohne Inhalt kurz geöffnet und schnell wieder geschlossen. Gestern kam es öfter vor und in meinem Suchverlauf habe ich dann gesehen, dass das Fenster durch meine gesamte Historie immer wieder auftaucht, immer mit demselben Link mit einer Zahlenfolge (ging mit 127. los). Ich habe im Anschluss den AdwCleaner durchlaufen lassen und der hat sehr viele Bedrohungen erkannt. Ich habe sie alle in Quarantäne verschoben und gelöscht und den PC neu gestartet, aber die PUP.Adware.Heuristic Malware ist immer wieder erschienen. Ich gehe davon aus, dass der Trojaner über den LaTex-Editor auf meinen PC gelangt ist (ich glaube es waren Texmaker und MikTex Installer, die hatte ein Freund im August runtergeladen.) Ich habe die Programme gestern sofort gelöscht. Gleichzeitig hat sich gestern dann noch mein Dokumente Ordner kurz geöffnet und es erschien kurz "Dokumente kopieren." Ich habe dann den Browser bereinigt und auf seine Standardeinstellungen zurückgesetzt. Über Nacht habe ich meinen Computer zurückgesetzt und Windows wurde neu installiert, aber die Malware ist immer noch drauf. Heute habe ich wieder den AdwCleaner durchlaufen lassen (erschien wieder PUP.Adware.Heuristic) und zusätzlich Malwarebytes und es wurde wieder viel gefunden (pup.optional.amazon1button, PUP.Optional.ChipDe, pup.optional.bundleinstaller, PUP.Optional.Amazon1Button.AppFlsh). Die Logdateien sind leider zu groß für einen Beitrag, daher folgen mehrere Posts. (Anmerkung zu den Logs von AdwCleaner: die Preinstalled Software habe ich aus der Quarantäne wieder hergestellt.)

FRST.txt

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-02-2025
Ran by Emilie (administrator) on LAPTOP-9AF8ONMC (Acer Aspire VN7-792G) (18-02-2025 09:54:09)
Running from C:\Users\Emilie\Downloads\FRSTEnglish.exe
Loaded Profiles: Emilie
Platform: Microsoft Windows 10 Home Version 22H2 19045.5487 (X64) Language: Deutsch (Deutschland)
Default browser: Edge
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAgent.exe
(C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe ->) (Acer Incorporated -> Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(C:\Program Files\Acer\Acer Quick Access\QASvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QAAdminAgent.exe
(C:\Program Files\Acer\Acer Quick Access\QASvc.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALockHandler.exe
(C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\mcafee.com\agent\mcupdate.exe
(C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe <2>
(C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Windows\System32\mfevtps.exe <2>
(C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\Malwarebytes.exe
(C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(C:\Program Files\NVIDIA Corporation\Display\nvtray.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(explorer.exe ->) () [File not signed] C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe
(explorer.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\SecureLine VPN\Vpn.exe <4>
(explorer.exe ->) (BINARYLABS LIMITED -> Binarylabs LTD) C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner\BitCleaner Tasker.exe
(explorer.exe ->) (Microsoft Corporation -> Microsoft Corporation) C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe <11>
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(explorer.exe ->) (Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7ee21f0fcd504371\igfxEM.exe
(McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
(services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QALSvc.exe
(services.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(services.exe ->) (Acer Incorporated -> acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(services.exe ->) (Avast Software s.r.o. -> Gen Digital Inc.) C:\Program Files\AVAST Software\SecureLine VPN\VpnSvc.exe
(services.exe ->) (Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(services.exe ->) (Intel Corporation - Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(services.exe ->) (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
(services.exe ->) (Intel(R) CN -> Intel Corporation) C:\Windows\System32\IntelSSTAPO\ParameterService\ParameterService.exe
(services.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7ee21f0fcd504371\igfxCUIService.exe
(services.exe ->) (Malwarebytes Inc. -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.5.471.0\McCSPServiceHost.exe
(services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe
(services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(services.exe ->) (McAfee, Inc. -> McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(services.exe ->) (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(services.exe ->) (Qualcomm Atheros -> Windows (R) Win 7 DDK provider) C:\Windows\System32\AdminService.exe
(services.exe ->) (WildTangent Inc -> WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(svchost.exe ->) (Acer Incorporated -> ) C:\OEM\Preload\FubTracking\FubTracking.exe
(svchost.exe ->) (Acer Incorporated -> ) C:\Program Files (x86)\Acer\Care Center\ACCStd.exe
(svchost.exe ->) (Acer Incorporated -> Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerButton_NB.exe
(svchost.exe ->) (Acer Incorporated -> Acer) C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe
(svchost.exe ->) (Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7ee21f0fcd504371\igfxext.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MoUsoCoreWorker.exe
(svchost.exe ->) (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18242040 2017-03-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1489400 2017-03-09] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [DAX2_APP] => C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe [628736 2015-06-16] () [File not signed]
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2631824 2015-07-14] (NVIDIA Corporation -> NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart [1710056 2015-07-14] (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [File not signed]
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [66304 2015-05-06] (Acer Incorporated -> Acer Incorporated)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe [719272 2015-04-02] (McAfee, Inc. -> McAfee, Inc.)
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION
HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\PhotoScreensaver.scr [619520 2025-02-17] (Microsoft Windows -> Microsoft Corporation)
Startup: C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BitCleaner Tasker.lnk [2025-02-18] <==== ATTENTION
ShortcutTarget: BitCleaner Tasker.lnk -> C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner\BitCleaner Tasker.exe (BINARYLABS LIMITED -> Binarylabs LTD) <==== ATTENTION
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast SecureLine VPN.lnk [2025-02-18]
ShortcutTarget: Avast SecureLine VPN.lnk -> C:\Program Files\AVAST Software\SecureLine VPN\Vpn.exe (Avast Software s.r.o. -> Gen Digital Inc.)

==================== Scheduled Tasks (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {25746121-EB7E-4B7E-9BA4-27CAC8316AA5} - \Power Button -> No File <==== ATTENTION
Task: {4F117C79-2706-4FBF-A748-C0259F51CEFA} - \Software Update Application -> No File <==== ATTENTION
Task: {511D4F70-5C34-4428-AFAE-10D347114DCB} - \Microsoft\Windows\Windows Defender\Windows Defender Verification -> No File <==== ATTENTION
Task: {611C823C-437B-46E7-9683-5312DFFCFD7B} - \Microsoft\Windows\UpdateOrchestrator\Policy Install -> No File <==== ATTENTION
Task: {6A1AECEC-0766-473B-AE79-EAAA31DE758F} - \ACCAgent -> No File <==== ATTENTION
Task: {6A250F7B-4F8A-4FEA-8CAE-31F28DA85202} - \ACCBackgroundApplication -> No File <==== ATTENTION
Task: {6C488413-8509-4D62-94EB-159DC0C33122} - \Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan -> No File <==== ATTENTION
Task: {7A003965-A297-4DC6-B15B-852D798391E0} - \Microsoft\Windows\UpdateOrchestrator\Reboot -> No File <==== ATTENTION
Task: {7F4D5DE3-08C8-4008-AC82-C84BCA4B16DB} - \FUBTrackingByPLD -> No File <==== ATTENTION
Task: {848DCC36-520C-4946-BF68-C7EFFEFA2F84} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot -> No File <==== ATTENTION
Task: {8D20A4DC-B257-40AB-809F-565BEC5D3B5E} - \Quick Access -> No File <==== ATTENTION
Task: {932EC946-767B-4FAA-9B54-A4A4A2DF1822} - \AcerCloud -> No File <==== ATTENTION
Task: {93C99DC9-B400-40D5-A6DF-4310EAF3F1A6} - \Avast SecureLine -> No File <==== ATTENTION
Task: {992AC68E-7168-40E1-B170-A736E71585A5} - \Microsoft\Office\Microsoft Office Touchless Attach Notification -> No File <==== ATTENTION
Task: {A364E297-00AD-490D-900E-22AC34598C71} - \Microsoft\Windows\UpdateOrchestrator\Maintenance Install -> No File <==== ATTENTION
Task: {BD02C08D-BA88-414E-A5E4-15FAFEB09DF3} - \Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance -> No File <==== ATTENTION
Task: {C33F4607-C279-4257-9039-34FF9FE1F21A} - \Microsoft\Windows\AppID\SmartScreenSpecific -> No File <==== ATTENTION
Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - \Microsoft\Windows\WindowsUpdate\sih -> No File <==== ATTENTION
Task: {E135F27F-CC77-4798-8095-E4F7E716DE31} - \Microsoft\Windows\Windows Defender\Windows Defender Cleanup -> No File <==== ATTENTION
Task: {E6010D43-6AE7-4B59-8E67-EC78FD8E8E96} - \Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler -> No File <==== ATTENTION
Task: {E98AFDFB-4B5D-4DC1-9DCF-5DD16ED4B901} - \Microsoft\Windows\Plug and Play\Plug and Play Cleanup -> No File <==== ATTENTION
Task: {EA3F661E-B31C-44A9-B40C-E3D5D56149D4} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display -> No File <==== ATTENTION
Task: {F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6} - \UbtFrameworkService -> No File <==== ATTENTION
Task: {FBE1992D-A1B2-44DD-9601-A1A2F799B096} - \ACC -> No File <==== ATTENTION
Task: {FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59} - \Power Management -> No File <==== ATTENTION
Task: {09512DFD-84D4-449F-9D11-9917471A5AA3} - System32\Tasks\Avast Software\Avast SecureLine VPN Bug Report => C:\Program Files\Avast Software\SecureLine VPN\AvBugReport.exe [6077736 2025-02-18] (Avast Software s.r.o. -> Gen Digital Inc.) -> --send "dumps|report" --silent --product 11 --programpath "C:\Program Files\Avast Software\SecureLine VPN" --configpath "C:\ProgramData\Avast Software\SecureLine VPN" --path "C:\ProgramData\Avast Software\SecureLine VPN\log" --path "C:\ProgramData\Avast Software\Icarus\Logs" --logpath "C:\ProgramDat (the data entry has 80 more characters).
Task: {CC8E2FDE-48E1-4B14-B607-F03B518B236F} - System32\Tasks\Avast Software\Avast SecureLine VPN Emergency Update => C:\Program Files\Avast Software\SecureLine VPN\VpnUpdate.exe [3954984 2025-02-18] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {9D08D3AC-8019-46E8-9835-EE375177789D} - System32\Tasks\Avast Software\Avast SecureLine VPN Update => C:\Program Files\Common Files\Avast Software\Icarus\avast-vpn\icarus.exe [8289064 2025-01-30] (Avast Software s.r.o. -> Gen Digital Inc.)
Task: {EF900057-1F28-42A8-90CF-6AE22A491782} - System32\Tasks\Microsoft\Windows\SysResetDelayedCleanup => C:\WINDOWS\system32\ResetEngine.exe [21480 2025-02-17] (Microsoft Windows -> Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{3bea1b67-1567-4514-9a7e-1d29d203c030}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{3bea1b67-1567-4514-9a7e-1d29d203c030}: [DhcpDomain] local
Tcpip\..\Interfaces\{e74f9852-4b1d-4422-9e19-da6e72942a19}: [DhcpNameServer] 192.17.128.24

Edge: 
=======
Edge DefaultProfile: Default
Edge Profile: C:\Users\Emilie\AppData\Local\Microsoft\Edge\User Data\Default [2025-02-18]
Edge Extension: (Malwarebytes Browser Guard) - C:\Users\Emilie\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\bojobppfploabceghnmlahpoonbcbacn [2025-02-18]
Edge HKLM\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]
Edge HKLM-x32\...\Edge\Extension: [bojobppfploabceghnmlahpoonbcbacn]

FireFox:
========
FF DefaultProfile: now364od.default
FF ProfilePath: C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default [2025-02-18]
FF Extension: (Amazon 1Button App for Firefox) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\abb@amazon.com [2025-02-18] [Legacy] [not signed]
FF Extension: (العربية Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-ar@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (български Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-bg@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Czech (CZ) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-cs@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Dansk (da) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-da@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Deutsch (DE) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-de@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Greek (GR) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-el@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (English (US) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-en-US@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Español (España) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-es-ES@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Estonian Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-et@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Finnish Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-fi@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Français Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-fr@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Hebrew (IL) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-he@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Magyar (HU) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-hu@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Italiano (IT) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-it@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Japanese Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-ja@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Korean (KR) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-ko@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Lietuvių Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-lt@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Norsk bokmċl (NO) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-nb-NO@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Nederlands (NL) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-nl@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Polski Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-pl@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Português Brasileiro Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-pt-BR@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Português (Portugal) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-pt-PT@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Russian (RU) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-ru@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Slovak (SK) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-sk@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Slovenski jezik Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-sl@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (српски (sr) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-sr@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Svenska (SE) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-sv-SE@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Thai Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-th@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Türkçe (TR) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-tr@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Ukrainian (UA) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-uk@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Chinese Simplified (zh-CN) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-zh-CN@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Traditional Chinese (zh-TW) Language Pack) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\langpack-zh-TW@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Mozilla Partner Defaults) - C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\partnerdefaults@mozilla.com [2025-02-18] [Legacy]
FF Extension: (العربية Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-ar@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (български Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-bg@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Czech (CZ) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-cs@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Dansk (da) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-da@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Deutsch (DE) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-de@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Greek (GR) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-el@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (English (US) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-en-US@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Español (España) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-es-ES@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Estonian Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-et@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Finnish Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-fi@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Français Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-fr@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Hebrew (IL) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-he@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Magyar (HU) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-hu@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Italiano (IT) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-it@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Japanese Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-ja@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Korean (KR) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-ko@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Lietuvių Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-lt@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Norsk bokmċl (NO) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-nb-NO@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Nederlands (NL) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-nl@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Polski Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-pl@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Português Brasileiro Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-pt-BR@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Português (Portugal) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-pt-PT@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Russian (RU) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-ru@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Slovak (SK) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-sk@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Slovenski jezik Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-sl@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (српски (sr) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-sr@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Svenska (SE) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-sv-SE@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Thai Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-th@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Türkçe (TR) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-tr@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Ukrainian (UA) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-uk@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Chinese Simplified (zh-CN) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-zh-CN@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Traditional Chinese (zh-TW) Language Pack) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\langpack-zh-TW@firefox.mozilla.org [2025-02-18] [Legacy]
FF Extension: (Mozilla Partner Defaults) - C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\partnerdefaults@mozilla.com [2025-02-18] [Legacy]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2025-02-18] [Legacy] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-07-16] (McAfee, Inc. -> )
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2014-10-20] (Foxit Software Incorporated -> Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel(R) Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-07-16] (McAfee, Inc. -> )
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-14] (WildTangent Inc -> )

Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]
CHR HKLM-x32\...\Chrome\Extension: [ihcjicgdanjaechkgeegckofjjedodee]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2839296 2015-05-06] (Acer Incorporated -> Acer Incorporated)
R2 DAX2API; C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe [163336 2016-09-19] (Dolby Laboratories, Inc. -> )
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573568 2015-05-14] (Acer Incorporated -> Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [373312 2015-04-14] (WildTangent Inc -> WildTangent)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.)
R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [9483456 2025-02-18] (Malwarebytes Inc. -> Malwarebytes)
S3 MBVpnTunnelService; C:\Program Files\Malwarebytes\Anti-Malware\MBVpnTunnelService.exe [2788304 2025-02-18] (Malwarebytes Inc. -> Malwarebytes)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [754792 2015-07-16] (McAfee, Inc. -> McAfee, Inc.)
S3 McAWFwk; C:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [338208 2015-03-20] (McAfee, Inc. -> McAfee, Inc.)
R2 mcbootdelaystartsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.471.0\McCSPServiceHost.exe [207344 2015-04-27] (McAfee, Inc. -> McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [612688 2015-04-09] (McAfee, Inc. -> McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [232656 2015-06-29] (McAfee, Inc. -> McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [373704 2015-07-30] (McAfee, Inc. -> McAfee, Inc.)
R3 mfevtp; C:\Windows\system32\mfevtps.exe [254792 2015-06-29] (McAfee, Inc. -> McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-04-02] (McAfee, Inc. -> McAfee, Inc.)
R3 QALSvc; C:\Program Files\Acer\Acer Quick Access\QALSvc.exe [401248 2015-09-04] (Acer Incorporated -> Acer Incorporated)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [453984 2015-09-04] (Acer Incorporated -> Acer Incorporated)
R2 SecureLine; C:\Program Files\Avast Software\SecureLine VPN\VpnSvc.exe [13032232 2025-02-18] (Avast Software s.r.o. -> Gen Digital Inc.)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [247040 2015-05-27] (Acer Incorporated -> acer)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [3004048 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103384 2019-12-07] (Microsoft Windows Publisher -> Microsoft Corporation)
S2 DCIService; C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe [X] <==== ATTENTION

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswVpnRdr; C:\WINDOWS\System32\drivers\aswVpnRdr.sys [85776 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Avast Software)
R2 BdDci; C:\WINDOWS\system32\DRIVERS\bddci.sys [800672 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Bitdefender)
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77536 2015-07-02] (McAfee, Inc. -> McAfee, Inc.)
S3 dg_ssudbus; C:\WINDOWS\System32\drivers\ssudbus2.sys [167440 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [158640 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [207208 2015-05-19] (McAfee, Inc. -> McAfee, Inc.)
R3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [31000 2018-05-15] (Acer Incorporated -> Acer Incorporated)
R2 mbamchameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [234072 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [21480 2025-02-18] (Microsoft Windows Early Launch Anti-Malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [202856 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\System32\Drivers\mbam.sys [80448 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [239568 2025-02-18] (Microsoft Windows Hardware Compatibility Publisher -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [189776 2025-02-18] (Malwarebytes Inc. -> Malwarebytes)
R2 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [412440 2015-07-02] (McAfee, Inc. -> McAfee, Inc.)
R2 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [347800 2015-07-02] (McAfee, Inc. -> McAfee, Inc.)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [80920 2015-07-02] (Microsoft Windows Early Launch Anti-Malware Publisher -> McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [496888 2015-07-02] (McAfee, Inc. -> McAfee, Inc.)
R2 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [875928 2015-07-02] (McAfee, Inc. -> McAfee, Inc.)
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [492000 2015-05-26] (McAfee, Inc. -> McAfee, Inc.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [109480 2015-05-26] (McAfee, Inc. -> McAfee, Inc.)
R2 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [344704 2015-07-02] (McAfee, Inc. -> McAfee, Inc.)
S3 NVSWCFilter; C:\WINDOWS\System32\drivers\nvswcfilter.sys [19616 2015-07-06] (Nvidia Corporation -> Windows (R) Win 7 DDK provider)
R3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [25368 2018-05-15] (Acer Incorporated -> Acer Incorporated)
S3 ssudqcfilter; C:\WINDOWS\System32\drivers\ssudqcfilter.sys [76832 2022-09-30] (Samsung Electronics CO., LTD. -> QUALCOMM Incorporated)
S3 ss_conn_usb_driver2; C:\WINDOWS\System32\Drivers\ss_conn_usb_driver2.sys [50720 2022-09-30] (Samsung Electronics CO., LTD. -> Samsung Electronics Co., Ltd.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46688 2019-12-07] (Microsoft Windows Early Launch Anti-Malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [350136 2019-12-07] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [54200 2019-12-07] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) (Whitelisted) =========

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-02-18 09:48 - 2025-02-18 09:52 - 000036502 _____ C:\Users\Emilie\Downloads\Addition.txt
2025-02-18 09:39 - 2025-02-18 09:56 - 000037459 _____ C:\Users\Emilie\Downloads\FRST.txt
2025-02-18 09:38 - 2025-02-18 09:55 - 000000000 ____D C:\FRST
2025-02-18 09:33 - 2025-02-18 09:38 - 002403840 _____ (Farbar) C:\Users\Emilie\Downloads\FRSTEnglish.exe
2025-02-18 09:30 - 2025-02-18 09:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2025-02-18 09:26 - 2025-02-18 09:26 - 000000000 ____D C:\Users\Emilie\AppData\Local\CEF
2025-02-18 09:24 - 2025-02-18 09:24 - 000189776 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2025-02-18 09:24 - 2025-02-18 09:24 - 000000000 ____D C:\Users\Emilie\AppData\LocalLow\IGDump
2025-02-18 09:23 - 2025-02-18 09:23 - 000002153 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SecureLine VPN.lnk
2025-02-18 09:23 - 2025-02-18 09:23 - 000002141 _____ C:\Users\Public\Desktop\Avast SecureLine VPN.lnk
2025-02-18 09:23 - 2025-02-18 09:23 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2025-02-18 09:18 - 2025-02-18 09:18 - 000064789 _____ C:\Users\Emilie\Desktop\Malwarebytes Scan-Bericht 2025-02-18 090107.txt
2025-02-18 09:14 - 2025-02-18 09:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2025-02-18 09:00 - 2025-02-18 09:56 - 000000000 ____D C:\Users\Emilie\AppData\Local\Malwarebytes
2025-02-18 09:00 - 2025-02-18 09:00 - 000002097 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2025-02-18 09:00 - 2025-02-18 09:00 - 000002085 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2025-02-18 08:58 - 2025-02-18 08:58 - 002832624 _____ (Malwarebytes) C:\Users\Emilie\Downloads\MBSetup.exe
2025-02-18 08:58 - 2025-02-18 08:58 - 000000000 ____D C:\ProgramData\Malwarebytes
2025-02-18 08:58 - 2025-02-18 08:58 - 000000000 ____D C:\Program Files\Malwarebytes
2025-02-18 08:57 - 2025-02-18 08:57 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2025-02-18 08:57 - 2025-01-30 09:28 - 000050976 _____ (Avast Software) C:\WINDOWS\system32\icarus_rvrt.exe
2025-02-18 08:55 - 2025-02-18 08:55 - 008790880 _____ (Malwarebytes) C:\Users\Emilie\Downloads\adwcleaner.exe
2025-02-18 08:53 - 2025-02-18 08:53 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\AVAST Software
2025-02-18 08:24 - 2025-02-18 08:24 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\Spelling
2025-02-18 08:20 - 2025-02-18 08:20 - 000000000 ____D C:\Users\Emilie\AppData\Local\CareCenter
2025-02-18 08:17 - 2025-02-18 08:17 - 000000000 ____D C:\Users\Emilie\AppData\Local\Comms
2025-02-18 08:11 - 2025-02-18 08:11 - 000000000 ____D C:\WINDOWS\oem
2025-02-18 08:04 - 2025-02-18 08:04 - 000000000 ____D C:\Users\Emilie\AppData\Local\NVIDIA
2025-02-18 08:03 - 2025-02-18 08:04 - 000000000 ____D C:\Users\Emilie\AppData\Local\Lavasoft
2025-02-18 08:02 - 2025-02-18 08:04 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Lavasoft
2025-02-18 08:02 - 2025-02-18 08:04 - 000000000 ____D C:\Program Files (x86)\Lavasoft
2025-02-18 08:01 - 2025-02-18 08:04 - 000000000 ____D C:\ProgramData\Lavasoft
2025-02-18 08:00 - 2025-02-18 08:00 - 000000000 ____D C:\Program Files\Common Files\AV
2025-02-18 07:55 - 2025-02-18 07:55 - 000003592 _____ C:\WINDOWS\system32\Tasks\OneDrive Reporting Task-S-1-5-21-2862171838-2850908273-2982186409-1001
2025-02-18 07:54 - 2025-02-18 08:02 - 000000000 ____D C:\Users\Emilie\AppData\Local\Mozilla
2025-02-18 07:54 - 2025-02-18 07:55 - 000003382 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2862171838-2850908273-2982186409-1001
2025-02-18 07:54 - 2025-02-18 07:54 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Mozilla
2025-02-18 07:53 - 2025-02-18 07:53 - 000000000 ____D C:\Users\Emilie\AppData\Local\clear.fi
2025-02-18 07:51 - 2025-02-18 07:51 - 000000000 ____D C:\Users\Emilie\AppData\Local\Publishers
2025-02-18 07:50 - 2025-02-18 08:35 - 000000000 ____D C:\ProgramData\Packages
2025-02-18 07:50 - 2025-02-18 08:11 - 000000000 ____D C:\Users\Emilie\AppData\Local\AOP SDK
2025-02-18 07:47 - 2025-02-18 09:33 - 000000000 ____D C:\Users\Emilie\AppData\Local\Packages
2025-02-18 07:47 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\Network
2025-02-18 07:47 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Adobe
2025-02-18 07:47 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie\AppData\Local\VirtualStore
2025-02-18 07:46 - 2025-02-18 08:08 - 000000000 ____D C:\Users\Emilie\AppData\Local\ConnectedDevicesPlatform
2025-02-18 07:46 - 2025-02-18 07:46 - 000000020 ___SH C:\Users\Emilie\ntuser.ini
2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\ProgramData\Vorlagen
2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\ProgramData\Startmenü
2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\ProgramData\Dokumente
2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\ProgramData\Anwendungsdaten
2025-02-18 02:31 - 2025-02-18 02:31 - 000000000 _SHDL C:\Program Files\Gemeinsame Dateien
2025-02-18 02:27 - 2025-02-18 02:27 - 000009518 _____ C:\Users\Emilie\Desktop\Entfernte Apps.html
2025-02-18 02:24 - 2025-02-18 02:24 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\SystemCertificates
2025-02-18 02:24 - 2025-02-18 02:24 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\Crypto
2025-02-18 02:19 - 2025-02-18 02:19 - 000022960 _____ C:\WINDOWS\system32\emptyregdb.dat
2025-02-18 01:37 - 2025-02-18 07:55 - 000002390 _____ C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2025-02-18 01:37 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie\AppData\Roaming\Microsoft\Windows
2025-02-18 01:37 - 2025-02-18 07:47 - 000000000 ____D C:\Users\Emilie
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Vorlagen
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Startmenü
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Netzwerkumgebung
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Lokale Einstellungen
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Eigene Dateien
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Druckumgebung
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Documents\Eigene Videos
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Documents\Eigene Musik
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Documents\Eigene Bilder
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\AppData\Local\Verlauf
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\AppData\Local\Anwendungsdaten
2025-02-18 01:37 - 2025-02-18 01:37 - 000000000 _SHDL C:\Users\Emilie\Anwendungsdaten
2025-02-18 01:21 - 2025-02-18 01:21 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2025-02-18 01:03 - 2025-02-18 09:22 - 000000000 ____D C:\ProgramData\NVIDIA
2025-02-18 01:03 - 2025-02-18 01:28 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2025-02-18 01:03 - 2017-05-01 21:52 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2025-02-18 01:03 - 2017-05-01 21:51 - 006437312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2025-02-18 01:03 - 2017-05-01 21:51 - 002479552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2025-02-18 01:03 - 2017-05-01 21:51 - 001762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2025-02-18 01:03 - 2017-05-01 21:51 - 000548800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2025-02-18 01:03 - 2017-05-01 21:51 - 000392312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2025-02-18 01:03 - 2017-05-01 21:51 - 000081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2025-02-18 01:03 - 2017-05-01 21:51 - 000069752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2025-02-18 01:03 - 2017-04-25 22:11 - 007944687 _____ C:\WINDOWS\system32\nvcoproc.bin
2025-02-18 01:02 - 2025-02-18 01:29 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2025-02-18 01:02 - 2025-02-18 01:26 - 000000000 ____D C:\Program Files (x86)\Intel
2025-02-18 01:02 - 2025-02-18 01:23 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2025-02-18 01:02 - 2025-02-18 01:22 - 000000000 ____D C:\Program Files\Intel
2025-02-18 01:02 - 2025-02-18 01:02 - 000000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2025-02-18 01:01 - 2025-02-18 01:28 - 000000000 ____D C:\Program Files (x86)\Realtek
2025-02-18 01:01 - 2025-02-18 01:01 - 000002440 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2025-02-18 01:01 - 2025-02-18 01:01 - 000002278 _____ C:\Users\Public\Desktop\Microsoft Edge.lnk
2025-02-18 01:01 - 2025-02-18 01:01 - 000000102 _____ C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc
2025-02-18 01:01 - 2025-02-18 01:01 - 000000000 ____D C:\WINDOWS\system32\IntelSSTAPO
2025-02-18 01:01 - 2025-02-18 01:01 - 000000000 ____D C:\ProgramData\rtkSSTSetting
2025-02-18 01:01 - 2025-02-18 01:01 - 000000000 ____D C:\ProgramData\Dolby
2025-02-18 01:01 - 2025-02-18 01:01 - 000000000 ____D C:\Program Files\Dolby
2025-02-18 01:00 - 2025-02-18 01:34 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2025-02-18 01:00 - 2025-02-18 01:01 - 000000000 ____D C:\WINDOWS\system32\DAX2
2025-02-18 01:00 - 2025-02-18 01:00 - 002173918 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
2025-02-18 01:00 - 2025-02-18 01:00 - 000000000 ____D C:\WINDOWS\system32\DAX3
2025-02-18 01:00 - 2025-02-18 01:00 - 000000000 ____D C:\Program Files\Realtek
2025-02-18 01:00 - 2025-02-18 01:00 - 000000000 ____D C:\Program Files\Common Files\Atheros
2025-02-18 00:58 - 2025-02-18 07:57 - 000003756 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2025-02-18 00:58 - 2025-02-18 07:57 - 000003632 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2025-02-18 00:57 - 2025-02-18 00:57 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2025-02-18 00:56 - 2025-02-18 09:22 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2025-02-18 00:27 - 2025-02-18 07:46 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2025-02-18 00:27 - 2025-02-18 00:27 - 000268240 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2025-02-18 00:21 - 2025-02-18 03:00 - 000000000 ____D C:\WINDOWS\Panther
2025-02-17 23:43 - 2025-02-18 03:00 - 000000000 ____D C:\Windows.old
2025-02-17 23:41 - 2025-02-17 23:42 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2025-02-17 23:29 - 2025-02-18 08:01 - 000000000 ____D C:\WINDOWS\SystemTemp
2025-02-17 23:29 - 2025-02-17 23:30 - 000000000 ____D C:\WINDOWS\system32\compatrel
2025-02-17 23:29 - 2025-02-17 23:29 - 000000000 ____D C:\WINDOWS\InboxApps
2025-02-17 23:29 - 2025-02-17 23:29 - 000000000 ____D C:\ProgramData\ssh
2025-02-17 23:11 - 2025-02-17 23:11 - 000022205 _____ C:\WINDOWS\SysWOW64\IntegratedServicesRegionPolicySet.json
2025-02-17 23:06 - 2025-02-17 23:06 - 000022205 _____ C:\WINDOWS\system32\IntegratedServicesRegionPolicySet.json
2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\Program Files\Reference Assemblies
2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\Program Files\MSBuild
2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2025-02-17 22:37 - 2025-02-17 22:37 - 000000000 ____D C:\Program Files (x86)\MSBuild
2025-02-17 22:34 - 2025-02-17 22:34 - 000000000 ____D C:\WINDOWS\system32\Intel
2025-02-17 22:34 - 2025-02-17 22:34 - 000000000 ____D C:\WINDOWS\system32\cAVS
2025-02-17 22:33 - 2025-02-17 22:33 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2025-02-17 22:32 - 2025-02-17 22:32 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2025-02-17 21:28 - 2025-02-18 02:27 - 000000000 ___HD C:\$SysReset
2025-02-17 13:27 - 2025-02-18 08:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2025-02-17 13:23 - 2025-02-17 13:35 - 000000000 ____D C:\AdwCleaner
2025-02-14 12:10 - 2025-02-14 12:10 - 002371552 _____ C:\Users\Emilie\Downloads\screencapture-kbbjobs-softgarden-io-job-52655704-Volontar-in-Publikationspraktiken-Schwerpunkt-Redaktion-w-m-d-2025-02-14-12_09_51.pdf
2025-02-12 16:04 - 2025-02-12 16:04 - 000000000 ___HD C:\$WinREAgent
2025-02-12 12:21 - 2025-02-12 12:21 - 004420943 _____ C:\Users\Emilie\Downloads\screencapture-goodjobs-eu-jobs-junior-crm-managerin-momox-se-2025-02-12-12_21_30.pdf
2025-02-10 14:40 - 2025-02-10 14:40 - 002234243 _____ C:\Users\Emilie\Downloads\screencapture-flotte-lotte-berlin-de-jobs-2025-02-10-14_40_06.pdf
2025-02-06 16:05 - 2025-02-06 16:06 - 000000000 ____D C:\Users\Emilie\Documents\ADAC_Auslandskrankenversicherung
2025-02-06 12:26 - 2025-02-06 12:26 - 000100384 _____ C:\Users\Emilie\Downloads\20250113_225512_SCHREIBEN.pdf
2025-02-06 12:26 - 2025-02-06 12:26 - 000079950 _____ C:\Users\Emilie\Downloads\20241212_150914_SCHREIBEN.pdf
2025-02-06 11:29 - 2025-02-06 11:29 - 000000832 _____ C:\Users\Emilie\Downloads\ical.ics
2025-02-05 20:33 - 2025-02-18 00:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2025-02-05 11:47 - 2025-02-05 11:47 - 000190374 _____ C:\Users\Emilie\Downloads\Lebenslauf_*****, Emilie_2025.pdf
2025-02-05 11:44 - 2025-02-05 11:44 - 000185126 _____ C:\Users\Emilie\Downloads\Lebenslauf_*****,Emilie (1).pdf
2025-02-03 18:13 - 2025-02-03 18:13 - 002520612 _____ C:\Users\Emilie\Downloads\screencapture-join-companies-quintusstudios-13441555-junior-acquisitions-manager-m-f-d-2025-02-03-18_13_20.pdf
2025-02-03 18:02 - 2025-02-03 18:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24
2025-02-03 12:02 - 2025-02-03 12:02 - 001841686 _____ C:\Users\Emilie\Downloads\screencapture-duh-jobs-de-jobs-53047959-Trainee-w-m-d-im-Team-Presse-und-Kommunikation-2025-02-03-12_02_28.pdf
2025-02-01 10:34 - 2025-02-01 10:34 - 005049282 _____ C:\Users\Emilie\Downloads\screencapture-sonypicturesjobs-job-berlin-digital-marketing-manager-m-w-d-22978-76059651296-2025-02-01-10_34_12.pdf
2025-01-30 11:07 - 2025-01-30 11:07 - 004430477 _____ C:\Users\Emilie\Downloads\screencapture-sonypicturesjobs-job-berlin-booker-sales-analyst-im-bereich-film-disposition-m-w-d-22978-73662561280-2025-01-30-11_06_49.pdf
2025-01-26 12:08 - 2025-01-26 12:08 - 004486333 _____ C:\Users\Emilie\Downloads\screencapture-goodjobs-eu-jobs-mitarbeiterin-im-bereich-sexuelle-bildung-better-birth-control-ev-2025-01-26-12_07_47.pdf
2025-01-24 12:55 - 2025-01-24 12:55 - 000207360 _____ C:\Users\Emilie\Downloads\Anschreiben_*****  Emilie.pdf
2025-01-24 12:54 - 2025-01-24 12:54 - 000188848 _____ C:\Users\Emilie\Downloads\Lebenslauf_*****  Emilie_2025.pdf

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2025-02-18 09:58 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\CbsTemp
2025-02-18 09:30 - 2019-12-07 15:50 - 000744902 _____ C:\WINDOWS\system32\perfh007.dat
2025-02-18 09:30 - 2019-12-07 15:50 - 000150288 _____ C:\WINDOWS\system32\perfc007.dat
2025-02-18 09:30 - 2019-12-07 10:13 - 000000000 ____D C:\WINDOWS\INF
2025-02-18 09:30 - 2015-08-31 12:01 - 001722788 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2025-02-18 09:29 - 2015-08-31 11:51 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2025-02-18 09:26 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\AppReadiness
2025-02-18 09:24 - 2016-09-03 18:26 - 000000000 __SHD C:\Users\Emilie\IntelGraphicsProfiles
2025-02-18 09:23 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2025-02-18 09:23 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2025-02-18 09:23 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\AVAST Software
2025-02-18 09:22 - 2020-08-13 00:29 - 000008192 ___SH C:\DumpStack.log.tmp
2025-02-18 09:22 - 2015-08-31 11:50 - 000000000 ____D C:\Program Files\AVAST Software
2025-02-18 09:21 - 2019-12-07 10:03 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2025-02-18 09:12 - 2016-02-26 04:13 - 000000000 ____D C:\Program Files (x86)\Amazon
2025-02-18 09:00 - 2019-12-07 10:14 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2025-02-18 08:27 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ServiceState
2025-02-18 08:20 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\OEM
2025-02-18 08:13 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\PrintDialog
2025-02-18 08:12 - 2019-12-07 10:14 - 000000000 ___HD C:\Program Files\WindowsApps
2025-02-18 08:10 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files (x86)\McAfee
2025-02-18 08:00 - 2015-08-31 11:52 - 000000000 ____D C:\ProgramData\McAfee
2025-02-18 07:54 - 2016-09-03 18:29 - 000000000 ___RD C:\Users\Emilie\OneDrive
2025-02-18 07:49 - 2019-12-07 10:14 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2025-02-18 07:47 - 2017-11-24 10:10 - 000000000 ___RD C:\Users\Emilie\3D Objects
2025-02-18 07:47 - 2015-08-31 11:49 - 000000000 __RHD C:\Users\Public\AccountPictures
2025-02-18 03:01 - 2019-12-07 15:52 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2025-02-18 03:00 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\oobe
2025-02-18 02:31 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows NT
2025-02-18 02:28 - 2019-12-07 10:03 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2025-02-18 02:27 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Registration
2025-02-18 02:26 - 2019-07-25 01:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2025-02-18 02:24 - 2019-12-07 10:14 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows
2025-02-18 02:18 - 2019-12-07 10:14 - 000000000 __RHD C:\Users\Public\Libraries
2025-02-18 02:18 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2025-02-18 01:34 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2025-02-18 01:34 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\spool
2025-02-18 01:34 - 2016-02-26 03:47 - 000000000 ____D C:\WINDOWS\system32\ihvmanager
2025-02-18 01:34 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2025-02-18 01:34 - 2015-07-10 12:04 - 000000000 ____D C:\WINDOWS\system32\Macromed
2025-02-18 01:33 - 2019-12-07 15:52 - 000000000 ____D C:\WINDOWS\OCR
2025-02-18 01:33 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Resources
2025-02-18 01:33 - 2016-02-26 11:59 - 000000000 ____D C:\WINDOWS\NAPP_Dism_Log
2025-02-18 01:33 - 2015-07-10 12:04 - 000000000 ___RD C:\WINDOWS\PurchaseDialog
2025-02-18 01:32 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Help
2025-02-18 01:32 - 2015-07-10 12:04 - 000000000 ___RD C:\WINDOWS\DesktopTileResources
2025-02-18 01:30 - 2016-02-26 04:15 - 000000000 ____D C:\Users\Public\Foxit Software
2025-02-18 01:30 - 2016-02-26 04:15 - 000000000 ____D C:\Users\Public\CyberLink
2025-02-18 01:30 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\WildTangent
2025-02-18 01:29 - 2019-12-07 10:14 - 000000000 ____D C:\ProgramData\USOPrivate
2025-02-18 01:29 - 2016-02-26 04:15 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 12
2025-02-18 01:29 - 2016-02-26 04:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF
2025-02-18 01:29 - 2016-02-26 04:14 - 000000000 ____D C:\ProgramData\Temp
2025-02-18 01:29 - 2016-02-26 04:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2025-02-18 01:29 - 2016-02-26 03:44 - 000000000 ____D C:\ProgramData\Package Cache
2025-02-18 01:29 - 2015-08-31 11:51 - 000000000 ____D C:\ProgramData\Mozilla
2025-02-18 01:29 - 2015-08-31 11:50 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2025-02-18 01:29 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2025-02-18 01:29 - 2015-08-31 11:49 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2025-02-18 01:28 - 2016-02-26 04:15 - 000000000 ____D C:\ProgramData\CyberLink
2025-02-18 01:28 - 2016-02-26 04:15 - 000000000 ____D C:\ProgramData\CLSK
2025-02-18 01:28 - 2016-02-26 04:14 - 000000000 ____D C:\ProgramData\install_clap
2025-02-18 01:28 - 2016-02-26 03:47 - 000000000 ____D C:\Program Files (x86)\Qualcomm Atheros
2025-02-18 01:28 - 2016-02-26 03:45 - 000000000 ____D C:\ProgramData\Intel
2025-02-18 01:28 - 2016-02-26 03:44 - 000000000 ____D C:\ProgramData\DriverSetupUtility
2025-02-18 01:28 - 2015-08-31 11:50 - 000000000 ____D C:\ProgramData\Acer
2025-02-18 01:28 - 2015-08-31 11:50 - 000000000 ____D C:\Program Files (x86)\WildTangent Games
2025-02-18 01:28 - 2015-08-31 11:50 - 000000000 ____D C:\Program Files (x86)\WildGames
2025-02-18 01:26 - 2016-02-26 04:15 - 000000000 ____D C:\Program Files (x86)\Foxit PhantomPDF
2025-02-18 01:26 - 2016-02-26 03:47 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2025-02-18 01:26 - 2016-02-26 03:39 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2025-02-18 01:26 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files (x86)\mcafee.com
2025-02-18 01:25 - 2016-02-26 04:15 - 000000000 ____D C:\Program Files (x86)\CyberLink
2025-02-18 01:24 - 2015-08-31 11:50 - 000000000 ____D C:\Program Files (x86)\Acer
2025-02-18 01:23 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files\mcafee.com
2025-02-18 01:23 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files\mcafee
2025-02-18 01:23 - 2015-07-10 14:14 - 000000000 ____D C:\Program Files\Windows Journal
2025-02-18 01:22 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2025-02-18 01:22 - 2016-02-26 03:48 - 000000000 ____D C:\Program Files\Common Files\QCA_Bluetooth
2025-02-18 01:22 - 2016-02-26 03:44 - 000000000 ____D C:\Program Files\DriverSetupUtility
2025-02-18 01:22 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files\Common Files\McAfee
2025-02-18 01:22 - 2015-08-31 11:52 - 000000000 ____D C:\Program Files\Acer
2025-02-18 01:00 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\appcompat
2025-02-18 00:36 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2025-02-18 00:19 - 2019-12-07 10:14 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2025-02-18 00:19 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2025-02-18 00:19 - 2018-01-24 22:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2025-02-17 23:42 - 2021-12-06 14:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2025-02-17 23:42 - 2020-03-24 19:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WISO steuer Sparbuch 2020
2025-02-17 23:30 - 2019-12-07 15:51 - 000000000 ____D C:\WINDOWS\system32\OpenSSH
2025-02-17 23:30 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\SysWOW64\de
2025-02-17 23:30 - 2019-12-07 15:50 - 000000000 ____D C:\WINDOWS\system32\de
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\UNP
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\F12
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\PerceptionSimulation
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Keywords
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\Com
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemResources
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SystemApps
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\ShellExperiences
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\setup
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\PerceptionSimulation
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\migwiz
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Keywords
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\et-EE
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\es-MX
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Dism
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\DDFs
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\Com
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\appraiser
2025-02-17 23:30 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Portable Devices
2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2025-02-17 23:29 - 2019-12-07 15:54 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellExperiences
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\ShellComponents
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\schemas
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\Provisioning
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\IME
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\DiagTrack
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\bcastdvr
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Windows Defender
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files\Common Files\System
2025-02-17 23:29 - 2019-12-07 10:14 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2025-02-17 23:29 - 2019-12-07 10:03 - 000000000 ____D C:\WINDOWS\servicing
2025-02-17 23:27 - 2019-12-07 15:54 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\OEMDefaultAssociations.dll
2025-02-17 23:27 - 2019-12-07 15:54 - 000020827 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2025-02-17 23:27 - 2019-12-07 10:15 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2025-02-17 23:27 - 2019-12-07 10:14 - 000232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2025-02-17 22:37 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2025-02-17 22:37 - 2019-12-07 10:14 - 000000000 ____D C:\WINDOWS\system32\MUI
2025-02-04 19:18 - 2015-08-31 11:51 - 000001238 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2025-01-21 18:36 - 2019-12-20 19:02 - 000000000 ____D C:\Users\Emilie\Documents\Tickets
2025-01-19 16:17 - 2024-12-06 17:03 - 000000000 ____D C:\Users\Emilie\Documents\Kleinanzeigen und Vinted

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
         

Addition.txt

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-02-2025
Ran by Emilie (18-02-2025 10:02:45)
Running from C:\Users\Emilie\Downloads
Microsoft Windows 10 Home Version 22H2 19045.5487 (X64) (2025-02-18 02:00:51)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

(If an entry is included in the fixlist, it will be removed.)

Administrator (S-1-5-21-2862171838-2850908273-2982186409-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2862171838-2850908273-2982186409-503 - Limited - Disabled)
Emilie (S-1-5-21-2862171838-2850908273-2982186409-1001 - Administrator - Enabled) => C:\Users\Emilie
Gast (S-1-5-21-2862171838-2850908273-2982186409-501 - Limited - Disabled)
SophosSAULAPTOP-9aaa (S-1-5-21-2862171838-2850908273-2982186409-1002 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-2862171838-2850908273-2982186409-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Malwarebytes (Enabled - Up to date) {0D452135-A081-B000-D6B6-132E52638543}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee Anti-Virus und Anti-Spyware (Disabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

12 Labours of Hercules III: Girl Power (HKLM-x32\...\WTA-8d9b4f73-bb47-4fea-917d-c50dd2ffed5c) (Version: 3.0.2.118 - WildTangent) Hidden
abFiles (HKLM-x32\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.03.2003 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.03.2004.4 - Acer Incorporated)
Acer Care Center (HKLM\...\{1AF41E84-3408-499A-8C93-8891F0612719}) (Version: 2.00.3005 - Acer Incorporated)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3001 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.06.2004 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8109 - Acer Incorporated)
Acer Quick Access (HKLM\...\{E3678E72-78E3-4F91-A9FB-913876FF6DA2}) (Version: 2.00.3008 - Acer Incorporated)
Acer UEIP Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 2.01.3002 - Acer Incorporated)
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.07.2004.0 - Acer Incorporated)
Avast SecureLine VPN (HKLM\...\Avast SecureLine) (Version: 25.1.11083.14496 - Avast Software)
CyberLink PowerDVD 12 (HKLM-x32\...\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5427.02 - CyberLink Corp.) Hidden
CyberLink PowerDVD 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.5427.02 - CyberLink Corp.)
Dolby Audio X2 Windows API SDK (HKLM\...\{6A478BF2-F67F-4ABC-A7F1-B6B5BA862371}) (Version: 0.5.2.32 - Dolby Laboratories, Inc.)
Dolby Audio X2 Windows API SDK (HKLM\...\{AA950AA4-CD9B-4D81-B6C0-BFABB7A24261}) (Version: 0.7.5.65 - Dolby Laboratories, Inc.)
Dolby Audio X2 Windows APP (HKLM\...\{7DA57EF8-9D20-4126-AF15-D0CC97D0C017}) (Version: 0.4.0.22 - Dolby Laboratories, Inc.)
DriverSetupUtility (HKLM\...\{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}) (Version: 1.00.3011 - Acer Incorporated)
Foxit PhantomPDF (HKLM-x32\...\{A4023BDF-82D5-412D-9D58-8C2819EBFE2E}) (Version: 7.0.410.326 - Foxit Software Inc.)
Game Explorer Categories - genres (HKLM-x32\...\WildTangentGameProvider-acer-genres) (Version: 13.0.0.6 - WildTangent, Inc.)
Game Explorer Categories - main (HKLM-x32\...\WildTangentGameProvider-acer-main) (Version: 13.0.0.6 - WildTangent, Inc.)
Home Makeover (HKLM-x32\...\WTA-ff512562-ab4b-4aae-9e8c-1d09bd47ac58) (Version: 3.0.2.59 - WildTangent) Hidden
Intel(R) Chipset Device Software (HKLM\...\{55398EAC-F58E-4F19-B553-BDF8B9EFD839}) (Version: 10.1.1.9 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\...\{5BD7E621-9791-4D9F-A620-1BA51153B749}) (Version: 1.0.0.0 - Intel Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{A53B7EAB-86BD-4F16-8C44-011B1376326A}) (Version: 11.0.0.1162 - Intel Corporation) Hidden
Intel(R) ME UninstallLegacy (HKLM\...\{555B1C57-E71B-4775-BC1D-627EEF693F0D}) (Version: 1.0.1.0 - Intel Corporation) Hidden
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4279 - Intel Corporation)
Intel(R) Serial IO (HKLM\...\{30E935B2-0DAC-455E-AC76-3C8504DC3D18}) (Version: 30.100.1519.07 - Intel Corporation) Hidden
Intel(R) Serial IO (HKLM\...\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.100.1519.7 - Intel Corporation)
Intel Chipsatz-Gerätesoftware (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden
Intel Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation)
Intel Trusted Connect Service Client (HKLM\...\{7D84E343-A23D-451C-B123-0195B2D903A6}) (Version: 1.42.17.0 - Intel Corporation) Hidden
Jewel Match 3 (HKLM-x32\...\WTA-679326c7-f13f-4d56-ae2e-6a7fee2304c7) (Version: 2.2.0.97 - WildTangent) Hidden
Jewel Match Snowscapes (HKLM-x32\...\WTA-ad853ef4-00ea-4eae-8b6e-18dee9cd5722) (Version: 3.0.2.118 - WildTangent) Hidden
Magic Academy (HKLM-x32\...\WTA-4c57b906-a5ca-4c03-9798-68e13f3261f1) (Version: 2.2.0.97 - WildTangent) Hidden
Malwarebytes version 5.2.6.163 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 5.2.6.163 - Malwarebytes)
McAfee LiveSafe – Internet Security (HKLM-x32\...\MSC) (Version: 14.0.1122 - McAfee, Inc.)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 92.0.902.67 - Microsoft Corporation)
Microsoft Edge WebView2-Laufzeit (HKLM-x32\...\Microsoft EdgeWebView) (Version: 133.0.3065.69 - Microsoft Corporation) Hidden
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4693.1005 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\...\OneDriveSetup.exe) (Version: 21.220.1024.0005 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 (HKLM-x32\...\{B175520C-86A2-35A7-8619-86DC379688B9}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 (HKLM-x32\...\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}) (Version: 11.0.61030 - Microsoft Corporation) Hidden
Mozilla Firefox 43.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 43.0.1.5828 - Mozilla)
NVIDIA GeForce Experience 2.5.11.45 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.11.45 - NVIDIA Corporation)
NVIDIA Grafiktreiber 353.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.62 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Polar Bowler 1st Frame (HKLM-x32\...\WTA-d421feba-0407-4288-b40c-de6252d31e83) (Version: 3.0.2.59 - WildTangent) Hidden
Qualcomm Atheros 11ac Wireless LAN&Bluetooth Installer (HKLM-x32\...\{3241744A-BA36-41F0-B4AA-EF3946D00632}) (Version: 11.0.0.0099 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.31213 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.1.505.2015 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8083 - Realtek Semiconductor Corp.)
Rory's Restaurant (HKLM-x32\...\WTA-6e35cc10-c9f5-48e9-baf9-e03aec7ff14d) (Version: 3.0.2.126 - WildTangent) Hidden
Runefall (HKLM-x32\...\WTA-4527bc60-c537-4ef8-8c87-cc9539bb1241) (Version: 3.0.2.126 - WildTangent) Hidden
Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - WildTangent) Hidden
Vegas World (HKLM-x32\...\WildTangentGDF-acer-vegasworld) (Version: 13.0.0.6 - WildTangent) Hidden
Villagers and Heroes (HKLM-x32\...\WildTangentGDF-acer-villagersandheroes) (Version: 13.0.0.6 - WildTangent) Hidden
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer) (Version: 4.0.11.16 - WildTangent) Hidden

Packages:
=========
Acer Explorer -> C:\Program Files\WindowsApps\acerincorporated.acerexplorer_2.0.3007.0_x86__48frkmn4z8aw4 [2025-02-18] (Acer Incorporated)
Kindle -> C:\Program Files\WindowsApps\amznmobilellc.kindleforwindows8_2.1.0.2_neutral__stfe6vwa9jnbp [2025-02-18] (AMZN Mobile LLC)
Music Maker Jam -> C:\Program Files\WindowsApps\MAGIX.MusicMakerJam_3.1.1.0_x64__a2t3txkz9j1jw [2025-02-18] (MAGIX)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [ ACloudSynced] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated -> Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated -> Acer Incorporated)
ShellIconOverlayIdentifiers: [ ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\shellext\x64\shellext_win.dll [2015-05-06] (Acer Incorporated -> Acer Incorporated)
ContextMenuHandlers1: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => C:\Program Files (x86)\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2015-01-27] (Foxit Software Incorporated -> Foxit Software Inc.)
ContextMenuHandlers1: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\mcafee\msc\McCtxMenuFrmWrk.dll [2015-07-16] (McAfee, Inc. -> McAfee, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-02-18] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_7ee21f0fcd504371\igfxDTCM.dll [2016-11-23] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-05-01] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2025-02-18] (Malwarebytes Inc. -> Malwarebytes)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\mcafee\msc\McCtxMenuFrmWrk.dll [2015-07-16] (McAfee, Inc. -> McAfee, Inc.)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2015-05-06 18:06 - 2015-05-06 18:06 - 000086016 _____ () [File not signed] [File is in use] C:\Program Files (x86)\Acer\AOP Framework\Interop.WUApiLib.2.0.dll
2016-02-26 04:05 - 2015-07-14 05:06 - 001942360 _____ (NVIDIA Corporation PE Sign v2014 -> NVIDIA Corporation) [File not signed] C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Emilie\Downloads:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Pictures:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\.dbxignore:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Die ästhetische Psychologie Hugo Münsterbergs.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Elements 10B8 - Verknüpfung.lnk:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Masterarbeit_Final_Mutti.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Office Home and Student 2016:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Spotify.lnk:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\.dbxignore:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\0307190535.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020 (1).pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2021.pdf:com.dropbox.attrs [52]
AlternateDataStreams: C:\Users\Emilie\Downloads\2021-10141374.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\2022-12197991.pdf:com.dropbox.attrs [13]
AlternateDataStreams: C:\Users\Emilie\Downloads\2307191224.pdf:com.dropbox.attrs [13]
AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17(1).pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\4661823_t201402060_mit_Zusatzinfos.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\5072581_Wertermittlungsliste.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\9MYHZ8.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\Angebot-7099991-41393-00_2020-05-01_13-55.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\Anleitung_WISOSB20.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750(1).pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\FRSTEnglish.exe:MBAM.Zone.Identifier [225]
AlternateDataStreams: C:\Users\Emilie\Documents\.dbxignore:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\AirDroid:com.dropbox.attrs [13]
AlternateDataStreams: C:\Users\Emilie\Documents\amazon_bestellung_glühbirne_a.PNG:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\ausschreibung_projektbearbeiter_in_zip_2022_0.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Barmer_Unterlagen:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Benutzerdefinierte Office-Vorlagen:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Bewerbungen_Alt:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Bürgeramt:com.dropbox.attrs [13]
AlternateDataStreams: C:\Users\Emilie\Documents\CyberLink:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Deutsche Bank:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\DKB:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Eigene Bilder:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Erasmus+2018:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Favorites:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Fax:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\FitX-2020-04-06_Kuendigung.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Flamenco:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\HandyHüllle_Bestellung.PNG:com.dropbox.attrs [52]
AlternateDataStreams: C:\Users\Emilie\Documents\Hörbücher und Comedy:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Immatrikulationsbescheinigungen_BA:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Indien-Unterlagen:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Jobs2022.PNG:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\JobsNGO_Savethechildren.PNG:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Kottbusser Damm 8:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Kreuzworträtsel_Geburtstag_Kerstin.docx:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:3or4kl4x13tuuug3Byamue2s4b [93]
AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\*****, Emilie - Einkommensteuer 2019.steuer2019:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Lebenslauf_Emilie*****_Therapie.docx:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\MADRID_2017_2018:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Master_Imma_Exma:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\NIE:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Outlook-Dateien:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Podcast.docx:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Rückenkurs:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Sanitas:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Scanned Documents:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Smartmobil:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Steuer:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Synchronbuchautorin Kurs.docx:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Tickets:com.dropbox.attrs [52]
AlternateDataStreams: C:\Users\Emilie\Documents\VID_20210121_191050.mp4:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Wirbelsäulengymnastik:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\WS2016_2017 Masterarbeit:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Übergabeprotokoll_Feuerbachstraße.pdf:com.dropbox.attrs [54]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) =============

HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer15.msn.com/?pc=ACTE
HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer15.msn.com/?pc=ACTE
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2015-07-16] (McAfee, Inc. -> McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2015-07-16] (McAfee, Inc. -> McAfee, Inc.)

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\...\localhost -> localhost

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-10 12:04 - 2025-02-18 08:57 - 000000852 _____ C:\WINDOWS\system32\drivers\etc\hosts

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\Control Panel\Desktop\\Wallpaper -> c:\users\emilie\pictures\bilder\2019\img_20190531_123605.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

Network Binding:
=============
Ethernet: Realtek PCIe GBE Family Controller -> rt640x64.sys
Bluetooth-Netzwerkverbindung: Bluetooth Device (Personal Area Network) -> bthpan.sys
WLAN: Qualcomm Atheros QCA61x4A Wireless Network Adapter -> Qcamain10x64.sys

==================== MSCONFIG/TASK MANAGER disabled items ==

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{B72C14F9-5EBE-4CD4-B3FA-B14ACA07AAE7}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.136.3203.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F088D4B7-C4A1-4331-B8EC-B50800F00F46}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.136.3203.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2288632D-FF55-46FD-8F44-3DBB2F04F5E9}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.136.3203.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{ECDC2DA5-4098-47C8-A2EA-62D812819CC6}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.136.3203.0_x64__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{D2319136-30A8-41F3-8DE0-AAD1AB97DA1F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{8FAA3C7C-DE8C-4120-AC01-423E055ABA2F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{5F105548-94E8-4F32-9052-3694D8BBA11C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe => No File
FirewallRules: [{781DDE61-C9B9-4AA0-8467-5502CB428725}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe => No File
FirewallRules: [{BC00D19D-DCA3-4A98-8F4B-ECD74B3798B3}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe => No File
FirewallRules: [{2D7EAABE-B4FC-46D1-866E-4F8D0D60829F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe (CyberLink Corp. -> CyberLink Corp.)
FirewallRules: [{F79E32A1-C16E-4EC6-8E01-236B0BFE321A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{59B4438B-830C-4BED-A154-F63CC7EB45B3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{86279AAC-4579-4651-B213-E30CD5425C5F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{79231BD8-E4E4-4FC7-A65D-656F40D3856B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{21786C41-20CF-4E44-90CF-777CF758C0B4}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{694D477D-DCED-460C-A481-F6A3BBD22AC4}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{80825BCB-9BFE-4129-AD90-9424883C4DC9}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{BA76611A-53EA-4E98-9240-01D77C34D7E0}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer)
FirewallRules: [{9374E55F-F31F-454E-8D92-4D68414A5ACB}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe (Acer Incorporated -> acer)
FirewallRules: [{05EBF720-9C08-4032-9F83-DDB35AB3D67E}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{D1449E72-5288-4FF3-88B1-34F6AC527BFF}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe (Acer Incorporated -> acer)
FirewallRules: [{153D9351-68F9-4CE6-AE66-5419EB374260}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe (Acer Incorporated -> Acer Cloud Technology)
FirewallRules: [{227DE642-B4A4-40DB-B65D-741AF59B20FE}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe (Acer Incorporated -> Acer Cloud Technology)
FirewallRules: [{E0BBD98A-E2CA-44F7-97E6-4DC6B859B476}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc. -> McAfee, Inc.)
FirewallRules: [{DA225F5C-C571-418A-9132-30223D45C585}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{91692DC0-BF42-45CE-82A5-6E667F038C2E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{BD119173-2DBD-4D41-97F8-C693A535793E}] => (Allow) C:\Program Files (x86)\Microsoft\EdgeWebView\Application\133.0.3065.69\msedgewebview2.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{8AF13718-4B22-4CC1-A04A-A845CB1C8574}] => (Allow) C:\Program Files\Avast Software\SecureLine VPN\Vpn.exe (Avast Software s.r.o. -> Gen Digital Inc.)
FirewallRules: [{7FB7A19C-3970-4B6E-A9C9-B555DC4BC07E}] => (Allow) C:\Program Files\Avast Software\SecureLine VPN\Vpn.exe (Avast Software s.r.o. -> Gen Digital Inc.)

==================== Restore Points =========================

18-02-2025 08:20:22 Windows Modules Installer
18-02-2025 08:36:35 18.02.2024

==================== Faulty Device Manager Devices ============

==================== Event log errors: ========================

Application errors:
==================
Error: (02/18/2025 09:51:57 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten.

Error: (02/18/2025 09:29:29 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten.

Error: (02/18/2025 09:23:03 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: nvvsvc.exe, Version: 8.17.13.5362, Zeitstempel: 0x55b03dc7
Name des fehlerhaften Moduls: NVCPL.DLL_unloaded, Version: 8.17.13.8205, Zeitstempel: 0x59079649
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000000141f
ID des fehlerhaften Prozesses: 0x98c
Startzeit der fehlerhaften Anwendung: 0x01db81de416cc07f
Pfad der fehlerhaften Anwendung: C:\WINDOWS\system32\nvvsvc.exe
Pfad des fehlerhaften Moduls: NVCPL.DLL
Berichtskennung: 85611c6c-cb0d-49d9-b499-e45aa34d28c9
Vollständiger Name des fehlerhaften Pakets: 
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:

Error: (02/18/2025 09:21:21 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volumenschattenkopie-Dienst-Informationen: Der COM-Server mit CLSID {4e14fba2-2e22-11d1-9964-00c04fbbb345} und dem Namen "CEventSystem" kann nicht gestartet werden. [0x8007045b, Der Computer wird heruntergefahren.]

Error: (02/18/2025 09:18:40 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten.

Error: (02/18/2025 08:55:48 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten.

Error: (02/18/2025 08:53:25 AM) (Source: SecurityCenter) (EventID: 17) (User: )
Description: Das Sicherheitscenter konnte den Aufrufer nicht überprüfen. Der Fehler %1 ist aufgetreten.

Error: (02/18/2025 08:50:27 AM) (Source: Service1) (EventID: 0) (User: )
Description: Fehler beim Verarbeiten von Sitzungsänderung. System.IO.IOException: Der Prozess kann nicht auf die Datei "C:\OEM\AcerLogs\Services.log" zugreifen, da sie von einem anderen Prozess verwendet wird.
   bei System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath)
   bei System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)
   bei System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)
   bei System.IO.StreamWriter.CreateFile(String path, Boolean append, Boolean checkHost)
   bei System.IO.StreamWriter..ctor(String path, Boolean append, Encoding encoding, Int32 bufferSize, Boolean checkHost)
   bei System.IO.StreamWriter..ctor(String path, Boolean append)
   bei WindowsService1.Se...


System errors:
=============
Error: (02/18/2025 09:28:51 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Broker für Laufzeitüberwachung der Systemüberwachung" wurde mit folgendem Fehler beendet: 
%%3489660935

Error: (02/18/2025 09:28:06 AM) (Source: DCOM) (EventID: 10010) (User: NT-AUTORITÄT)
Description: Der Server "{209500FC-6B45-4693-8871-6296C4843751}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden.

Error: (02/18/2025 09:27:08 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Übermittlungsoptimierung" wurde nicht richtig gestartet.

Error: (02/18/2025 09:24:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Error: (02/18/2025 09:24:00 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht.

Error: (02/18/2025 09:23:30 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde aufgrund folgenden Fehlers nicht gestartet: 
Der Dienst antwortete nicht rechtzeitig auf die Start- oder Steuerungsanforderung.

Error: (02/18/2025 09:23:30 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Presentation Foundation-Schriftartcache 3.0.0.0 erreicht.

Error: (02/18/2025 09:22:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "DCIService" wurde aufgrund folgenden Fehlers nicht gestartet: 
Das System kann die angegebene Datei nicht finden.


CodeIntegrity:
===============
Date: 2025-02-18 09:51:57
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Windows signing level requirements.

Date: 2025-02-18 09:30:31
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume3\Program Files\Malwarebytes\Anti-Malware\mbamsi64.dll that did not meet the Microsoft signing level requirements.


==================== Memory info =========================== 

BIOS: Insyde Corp. V1.09 05/17/2016
Motherboard: Acer Aspire VN7-792G
Processor: Intel(R) Core(TM) i5-6300HQ CPU @ 2.30GHz
Percentage of memory in use: 56%
Total physical RAM: 8056.16 MB
Available physical RAM: 3496.43 MB
Total Virtual: 9976.16 MB
Available Virtual: 5236.28 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:930.86 GB) (Free:762.1 GB) (Model: TOSHIBA MQ02ABD100H) NTFS

\\?\Volume{53aeb305-538e-4a4b-b132-682275219f17}\ () (Fixed) (Total:0.54 GB) (Free:0.08 GB) NTFS
\\?\Volume{0a15119a-b7be-4531-a347-543a13aea1d2}\ (ESP) (Fixed) (Total:0.09 GB) (Free:0.04 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 969F2557)

Partition: GPT.

==================== End of Addition.txt =======================
         

Alt Heute, 16:13   #2
M-K-D-B
/// TB-Ausbilder
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic







Mein Name ist Matthias und ich werde dir bei der Analyse und Bereinigung deines Systems helfen.



Poste bitte alle Logdateien von AdwCleaner (ADW) und Malwarebytes-AntiMalware (MBAM) mit den erwähnten Funden.
__________________


Alt Heute, 16:14   #3
M-K-D-B
/// TB-Ausbilder
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic



Schon mal ein kleiner Hinweis vorab: Das Geld für McAfee hättest du dir sparen können:
McAfee LiveSafe – Internet Security (HKLM-x32\...\MSC) (Version: 14.0.1122 - McAfee, Inc.)



Sobald du alle Logs von ADW und MBAM gepostet hast, können wir anfangen.
__________________

Alt Heute, 16:20   #4
Emma88
 
Windows 10: PUP.Adware.Heuristic - Standard

Logs



Danke dir! Hier sind die Logs:

MBAM

Code:
ATTFilter
Malwarebytes
www.malwarebytes.com

-Protokolldetails-
Scan-Datum: 18.02.2025
Scan-Zeit: 09:01
Protokolldatei: 823c3fe0-edce-11ef-a662-3065ec9a1e2c.json

-Softwaredaten-
Version: 5.2.6.163
Komponentenversion: 1.0.5146
Version des Aktualisierungspakets: 1.0.96058
Lizenz: Kostenlos

-Systemdaten-
Betriebssystem: Windows 10 (Build 19045.5487)
CPU: x64
Dateisystem: NTFS
Benutzer: LAPTOP-9AF8ONMC\Emilie

-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 193673
Erkannte Bedrohungen: 241
In die Quarantäne verschobene Bedrohungen: 241
Abgelaufene Zeit: 9 Min., 58 Sek.

-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung

-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)

Modul: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 6
PUP.Optional.Amazon1Button, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Amazon1ButtonBrowserHelper.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, HKLM\SOFTWARE\CLASSES\APPID\Amazon1ButtonBrowserHelper.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Amazon1ButtonRuntime.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, HKLM\SOFTWARE\CLASSES\APPID\Amazon1ButtonRuntime.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\Amazon1ButtonBrowserHelper.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\Amazon1ButtonRuntime.dll, In Quarantäne, 3043, 468987, 1.0.96058, , ame, , , 

Registrierungswert: 2
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, 5728, -1, 0.0.0, , action, , , 
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, In Quarantäne, 5728, -1, 0.0.0, , action, , , 

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Daten-Stream: 0
(keine bösartigen Elemente erkannt)

Ordner: 60
PUP.Optional.Amazon1Button, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\DISTRIBUTION\EXTENSIONS\ABB@AMAZON.COM, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\campaign-attribution, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\attribution, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\network, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\storage, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\config, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\tabs, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\util, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\internals\storage, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\apps\titan, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\strategies, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\storage, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\internals, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\internals, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\apps, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\util, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients\network, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform\sandbox, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\extensions\mode, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\components, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\extensions, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\wrappers, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\storage, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\customstyles\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\customstyles, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\defaults\preferences, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\META-INF, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\defaults, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button.AppFlsh, C:\PROGRAM FILES (X86)\AMAZON\AMAZON1BUTTONAPP, In Quarantäne, 5728, 809559, 1.0.96058, , ame, , , 

Datei: 173
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\defaults\preferences\prefs.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\META-INF\manifest.mf, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D81B35D77F553B1714B274B57484F546, 211D9739B92E6110EBFCE4BFFB3F85B7562FD7B512A42532B7B64746C83BB40E
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\META-INF\zigbert.rsa, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , E38645A6E82531AD93CF1F27CBEFF4A4, AAADFA1D87543DA785C8C11240E76BC6C31985F477DBA577EA441AB8A662C7F2
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\META-INF\zigbert.sf, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 529E2F2E5F18A3DB3E6F473F336E315F, D3A9C40CF47DCDBFCD8F37EF50F3E6A55AF0944E4C30BAC99250C688F44BD0E5
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\internals\storage\async-in-memory-store.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B0AD0A364905B25E217768A549C9A292, E073C1580B9966CCEF028C2FECF7791D429BBC21AC4B814EFB88883DBBE5EEED
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\internals\session.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 9E7C86189F026F22E085E4B0CFEEFD20, D7CB00E7ED746B69A7906779773CBCE021B57522876EE70579851F9BF8F4431E
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\cherami\cherami-service.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1E78FBA55944AE658A88689637EA3626, DDA42218B3DFA56621EE8D290600BDA85345F4BF5E6BC4942D38EB1F6DB04796
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients\network\sdk-request-client.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 69B9BA89DE5038BAAB2BAA26E1FCCF26, 95FFB26C20CC06687305A68977EDAB5D451517D3B0F3AA82A4A322A2E017B500
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients\network\xhr-client.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D7B37DE2C69EB4FC6225BF43903F83F6, 6AF4E497BD4C60CBF89537019F2F2637F55AFEDE67B68AA5726B8CD2858FD87B
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\clients\s3-client.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , BC06173A64A72D784C2CEEEA006A2217, F6E1FBE582FB793D5A26348259771F689C5DF12F7EBD5DB95C9DC750A5A748DE
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\ajax.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3F240DAED44A6A35D8505DCD0F70E5CF, EF3800E3CB60AC60D68D92B5AE79E5178787324511CF2A160B3892ACFD2869CF
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\countdown-latch.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 072EADAC5ED0C9C17E9BE1284F32DE08, 59C30D59460DEFC76E927A6AFC7FB21A479D2839909A7464FBE964DBCD4B6F35
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\events.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 7675246E26F75237D4C9C7C0D6ACCE78, B0EFA2DBFAB3D542F065D9EA36C3C8D9822CA9A6206A6B85D9430DFC6140394C
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\flow.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3AABF2CF6D5D7A89AEC9499EAB451D26, 84D1B878B4806E3A108912415FC7A25605F62E5B2AFC74ADB434D3196E787EC9
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\lang.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F23A26CBB43F242F366BA64575761D43, 0789AA2D77854B1B0E5B9CBCE8D58916DBFE3B6A6789318EF2B4F8827444AF44
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\options.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 0D92B93731BDCBF6062FDEA0C1913501, AA9BFF5FA3ACAD1C6A4D3753A3FD1E6069C8C0BBBD95A03C5FF5ED906C2C8465
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\query-string-map.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F9F4BE7795ABF3905BCF3ED6AE9EA4D9, FCE174C7718C8F75558E06C092D282344DD92C7B513E0BA8117FEBDE3FA8D64F
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\ready-gate.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 83AF30538EE15FC625559681A5A82E06, 0EAA7E0F40072C8A0A9156ADEBCE13DB6156A0CEF14E94C66365EE2E2DC97706
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\serdes.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5BC6EFBDACCCA1B7B7FED122D259269C, 1F46FE2E62A66757C1EA7A9500209011F13CA442E892F62E9CBCBD1810B381D1
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\simple-future.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1B643C7D8622288997521BD63D6E5506, D3238797C53CBD5F3AF36C185C67B3DCC54C24B4C8533C4B00E930B091FD1883
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\state-guard.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 75003F461768BC3A2349AEC36CA090C7, EBBC2848E25B6C62A4FF011629951B8F6584A9AB6B534F11FB4E28E2B465BAD0
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\state-latch.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 18DBE0C4F4EB427703CCDF9EB2537DAD, 051939D04060C0F59F2F675D2ADD5A1B51893A990E03AFED7E89E5110075707D
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\state-machine.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 63AA36374A8A8FFEFFD80885FB74BC4A, 7E521081B7BFD363C1266E194DB866942424B059E55EA2023979750A916CA069
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\task-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 102C301977F44979A575A26D5CB6438E, D9500A5A1F0C4E668C6131FA7E1D84E606CD857AD2CB02AA91F5E44E450A90C7
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\timeout-hash.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 7A00500E0AAA8AE50129CBEE423CF5EB, 0BBBEE9CA4B4F08E0F941446A94AD0F8A5681F494C6B340A37E5BB01150F66F9
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\uri.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5EA97F1788BF5F5E6A2D8E2D963D1EC4, 7FFC220BE44A34BB7A91486D2885DA0FB01E833FE259E9B94DD49255E459ACD1
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\commons\uuid.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3C431156D5A3DEDEF82CFF5114C9C611, 7DE3449E20C4FAC48900B7B867CF93A679722FA620ED47FFD0948BDBC07238A9
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\internals\message-subscriber.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , BD88F1B9FD615197992E7717458B569A, 84EA9856E78D23F717954A96D1C37998A0CCAA73A7FDB209B29EFFB4D716E363
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\strategies\port-transport-strategy.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 353C6E2275EBE9F0323B3027D992F1DB, DFD596A02E6A68A089F8845C29F1C1F017DDB644E07359CA5B8C755630BF0B5B
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\strategies\post-message-transport-strategy.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 6FACA6302837455BAF06F916257089DF, ACC7992FB61095130FBC1D9590E13046CF20A62091EA9A875FAB44B4D5873B83
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\composite-message-channel.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 474C41B3C2AA74D1E0316C561D1D5866, 84C7B03378BB9C0ABFD86649A438CEEFCB590863DA06E32A691C6EF161A1C881
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\invocation-router.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 95840F0D781AEEA5D608F0C41C250EB1, AB49B20853931359EC4AD6F3FEAC76DEB3D3CC53DDCDB2007E613F15EB39C51C
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-bus.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B4E2FC8A6192768109AF4DD409EFA97F, 0FAFAE1D84B6B3CF3076607FEE4844B9F6147F36EF001B02362BF8240AD860ED
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-channel.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 0CF2F120690958C0640183D14763D185, C3E449081BED3D108C36273B7BCE8714F1529A7F10AB9A3CD21256996B3B737D
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-dispatcher.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F97825E6B7FDFA9D0F0AD6232952E2B8, 278836E781B4EBA0055CBF88081F939E8C99D6D70327651C77C3FE1DBA88FA53
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-exchange.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , AA4A650F925DA347644988CB0BF3858B, 6F25FF5545C61D2B65D888FB436165526A92C9E1F1A989485581E1BE46B6189A
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-factory.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , E40EF3A5326F476E40B1169D51D5501E, F1C3DC5CE824203FD8B3C9644A0BAF1DAAB44BF97FA80EA496586CB527787A2D
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\message-framework.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 81053355C1A197DE0EAF4B969BD8F669, BF717A1D948DCBCBE0F0F0C4F43E1E64B7B1B3DC4EAEC29B1BD8D2F35EA0D273
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\messaging\transport-strategy-factory.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 35640945985D7B7C76F69C9605F026F3, C0B18AD3D2162F5D9ABA8A1374BB3B199DC385932D4578103C1579D4E45B9831
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\base-process.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5B7BCDB861F0D357C429A1142D18679C, 1267D74C80911A5A1F394CB28DF06FE44E4BF0BFB0895061F0F661FBF366390D
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\handshake.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1084D9B4DEFE7706E1993C576A681433, 72FC8932009839CF16DB592FDCB67D339AA291820AFAB8B8C19832995A34F89E
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\health-checker.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 0FF5420CD38B47259DA5CFC12C5FE242, B7C0B962739896845728C941ACBCBE4B1CD0E6B03EAFC48D7D61F0F9561B723F
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\pid.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , FF6A1F30E17F6A55EEEF25565E20052B, D1DFBE3EB445CB9E31A54F4E2DDA9CF66C70F16BBF0CFD239922F12877F00D5D
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\process-state.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1823FE0A8537A3B226363C5E45574259, 4640E1604F37EAE1BCAA1036E42CC54251DDC8AE0902308477B324DBC955E468
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\internals\remote-process.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D5C83AB3D85B5179747F2995BC3BD534, 84E715FE3A6F4A139A80C8AF053C5DB2865017B28070BBA45BF28ED417041ED2
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\bit\os\process-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EFD24F7BDEAC6494AA856159409DAABE, 9F23E0320162625D70A30966CCA1913CBE6E3CDEB5FC3533CFE75B9F731E5679
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitbedrockjs\lib\underscore.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , DD9663BE9A71F3570BC35F0EDBA28712, 163189EF69A3C210A04BB4CAC2C336119D78B576FB84B4231977514419EB0FAF
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\apps\titan\spawner.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 95CA4A1B95F2B71FF3896230C5442F23, 518D8698FC62E6C75DA8D7607BE8CCAFEE495E907C1BA7AF88E45C00AC4D145E
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\campaign-attribution\ubp-feature-campaign-attribution.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5A3D34EDDA166A08A5ECDDC9DAA765C1, 53EFF9AA5C467C61527584B38A24B1D7778737BDCA57558922AC5469ED0DB8F1
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\addon-uninstaller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , C277A15207CD91465FF3FAA779B0D138, 03ACF34B7C828DEB337D33976B57711A97C31ADA55174A97F9AF0CF5F0D73D75
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\alerts-badge-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3E8E42D6ED7F8A73C706D2CED8766312, E1C0260B626E913363566D6F0678D34FD9D0BDE11AE44062386D50C5EF18F229
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\attribution-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B48DFE2718B762AB0800C912DC0C5623, 524EEF5132301DF7B668AC9CB10CE414AB9CAE2D2C3345306114A4FD03B66A2F
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\configuration-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 459677CE3DC5D6902A8FA47294A316BE, F87D4AC8AB0397697BA825C2B83ECD8F1EA0E401A8444BAC44A79AC1E976969D
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\guid-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 2B8DFED4E963C71853CAF7F96DF5CA38, DB256D6FA6BE79704F82F04018D37444805BBC99B7765500292224D9B7FAD1B2
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\mode-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 627D14465FFF631FE0A144CC013A3DB1, 08C60EEA36D01A6032F2786D745D6CFEA657597C3C064F413E45A46066E3DA00
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\ping-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3F557B74C21F38D839A4A05739C5A21E, F0DE0CFED940D6586E681DBA4753F84146522201DD837515F7BE3F1869C26697
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\promotion-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 2DBFF92796821310FF19C323E1371B46, E1A2CB0E1EEA2C307B5DADC4748DE0A1E926054C99EB36A5C5C18E5F8F7BB172
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\token-vendor.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , DCF2D043548A3E4F2038D597BCC97D3A, 9C919E7B7E8028B73CE993B02AA126139257809C9B755B119C9BEBCB38105488
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\components\uninstall-wishlist.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EC7FE501DA17F8B85F93ACACCA4F74BD, 1179C34BDB7B2E0A9683167FDE5554B614F42269944FBB2D19FC6B326C5194CB
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\attribution\attribution.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D5713BCF847747CA023B72A81B93B4A3, 2B02831EC9DD667DFB1EA7B8DDDD4D7181F2AF5FAFAD4CFE48D33271ECD8FA7A
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\config\config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 79F1471FD1448B74BFF3C474A2A3BB65, D7001C13B04DE678F6515AF9368D5614CA08387B12784399F27D709794CF07BB
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\config\user-settings.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 6397C7CF703A9DE673B5CF334EA83EAA, 2001DDF990E927C8C9AA0A04D27631102D947FCB305644E4CF98560C9AD20861
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\content.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , A78F7EBAB8DE7F084CB3A42B5E834FD4, 8E56C58A29BC76E1CFD66AB7B393701869B010DC8BAF998F9FC475B885D9007C
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\interaction.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D7CC29767BC26B5D477C4517F7DDE3D9, B606B9DD19D3AE138B8AB8C529E1215171E35A0F4DF273CAE1443CA3046A9D16
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\meta.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 35A9285F4DB4976011A4846E69AC8AFD, B409695A6421591E93C148DB5056B552FCAB8CDB2BC8C29139089E1ECF32F861
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\page-nav.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 59C24BBF3DD4A83F827B6512BBE33654, 23FE1431CF61E68E81F726D3559398D9FF6DE8B2960218F3169E545965D0ABAE
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\sandbox.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 4545FF7337A9E1201AC8E9C804E4C014, 0397C889A3980AAACD456D42E41262B9B092723D0BF2718581444CD91DA1E2CD
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\style.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1CD9210F0922B5B3202B4B9FD8ACBE5C, B58DEEEA0FB4675BD649A2985B7E779C67531EB583AD2E9C19548DAEF9E60AD8
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\contextual\system.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 2D2CE27524A400975F9B231A7FD2AED6, B615E36540E24FC9D53172E37E66857A65AF04F217CCCE8CC1DD91803E626C42
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\network\amazon-xhr-request.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 91AAFDCE1FF19FB2A8DAD53A11C3245C, A553F6EF78F53B50BFBE99069124839B371CDC706C151509173C0E1A52ACC2F9
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\storage\simple-storage.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 29068224FE2BC8DFEEE3DF3E30D91A4A, F91B1F01CB5D60963420F1CCFFAB6A8272444A70C85E5F77A2F5490A21807F46
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\tabs\active-tab.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EE6B06BFA0D05BB8E751274E435A887A, D641D9F77BB1B2D77D281085AF968F1BBA0B08344902EE704F6179E78FEA32DA
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\util\filtering-dispatcher.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 9FCE48161183AC17A2C6BDE91F907DCA, DBF9E0006BE391374A7D76D42EFD2E63E737E7C8C56D05798999AC363DD407AA
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\handlers\alerts-badge-count.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , BEC460148CB688E79C0C415026064363, 59FF72C7466B83CCBBCB0BB1B7D915F9B0303C448FA723E939AC9D7FD1ADCDA2
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\contextual-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 589B6931870A7517FDADB4D4B33CBCC5, 53EE9C7EFE0D82F4789036ECC1E398FD66DA4EC2F0231073E905B740F077D76A
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\interaction-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5FD1FF74D815E7B0A9E0B0C4FBD6892E, 1D8BD79335AA2C0F91562FD30BF9FABBA65348C982B958E8F14586A7E9DB1D05
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\meta-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , D834830EF2629F3E3428BDDA01CA3260, 18C3F8A073E865B6F49B0547B422F02AA3871F686EB083E04B84419713181845
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\platform-api-registry.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 96F6445548340231C4D5B55BD490E553, 3544C3943517959906797E1F20D10C16169D21A8CEF083586BBC47F6C887C00C
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\platform-service.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B3CC430A25F62B77E0140D738807169A, B901FD18EC2A1A58525ABF1521CB3714AF8095A8B88A6B83F58E6091E1F9FEE9
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\sandbox-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5CDE743111ABF7815C1562757A70E551, 675CFB0AA5FB4452537F8B658FFF945466A5AE5626A8B9EB4D87C1688D10862A
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\scraper-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 6A3208CCEC955ADA00953822B2491F42, 003EC655ADFD81683D753A283B9B05C476C12362D3C6FAE7BA89855E68AD86EF
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\platform\style-peer-controller.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 99DE027AF2848B5BBA43AD174D351782, 7599129B888AC3D31D30426106C35A18F426F2496BC8D3E89C3E16DC7096E3C8
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\storage\simple-storage.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F1A69D71C22C0107815376C8D8EF5852, 67AB5C3E0D1F1823C795016FDC183809A6414FED45BD34DB8486A26E0C9041DF
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\util\mode.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5D2DCC82B1F262ABF893A86DBA1A488E, 9F5431915225BBBD99B1E14C4B9C54B33CCFCABC90D1C95FC190803B551791DB
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\util\smile-mode.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 473298BA8A3BDFA6AA462EBC28027BD9, 1819013DBDBC92E8DDA98C95BF413D720681A09EAFD2A769E014CE182E439262
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bitonebuttoncore\lib\bit\ext\core\one-button-app.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 9D835527971B40FDD8353AD176750EA3, 3E2BEE9BCE73ECDCAC908FCFCFD7568FF68A8C3CB8B0B2943550AC05A69852DD
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\any.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\async.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\bluebird.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1AE945B7BE46E6A2513EE553AA082A3C, FD818A2C6DA503CFF4F69DE0BB8AE75A2805B17C7D0E2E8EBA7C56EC9E3204E9
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\call_get.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\cancel.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\captured_trace.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\catch_filter.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\direct_resolve.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\errors.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\errors_api_rejection.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\es5.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\filter.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\finally.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\generators.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\global.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\map.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\nodeify.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\progress.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promise.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promise_array.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promise_resolver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promise_spawn.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\promisify.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\properties_promise_array.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\props.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\queue.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\race.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\reduce.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\schedule.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\settle.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\settled_promise_array.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\some.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\some_promise_array.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\synchronous_inspection.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\thenables.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\timers.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\bluebird\lib\util.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , , 
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\customstyles\lib\customstyles.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EE6C8CB0DD6DA7FE35EB1204964FF2BC, 86703B569899CFD7D3D6FE635CACBF4EE6248B048A9713402BB7BCAD53310EB2
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\host-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5C3E44348811ED03DC423F8D4E525197, 9FF43CCBCEAA25AB00883A3EBE8D13848B6D83535E6B60520EA11D75C0FB307E
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\HOWTO, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 113589070A26155A369BC73B7DD41A1A, B59C4B053061C341ECF9B0F525FF0668A20B6B0CF0CE67F242962F660C288ADD
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\interaction-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , E796BEB30736847CE954678C922A1DA5, 73D0DD5E72E4A67C47C90E42EFD04576AD6B5768CD72650829D3E2A5FDD01447
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\meta-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 7CC0CC86DC1CBA2FC4418D33B86003D6, 93D16836C6C6ADFF4520ACCF216AEF54DC97328E5A737EE9187E9A4F59B6F239
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\sandbox-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 58B6A99C9C3CA2E217E4A31B8A814E78, 043D04B6FEEB5F78A56E32DE1F3DE83BECAB6DF937263ED4A0CAF7029B1CDECB
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\scraper-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 4495369043B226449ED6AD6B491B3DD7, 74F9F88805AAE47A0C836542B3BF1521F62C7DAE1DD95CC792C80194440D5B68
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-drivers\style-driver.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 4E121F0280145245B14DE520D67900D6, 2B841EC209B3466AA4480E742D4B9E097B9656D7DA64FA544F8679B9C3A9ADF4
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\hover-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B2EBF6E6FC61D1F3E3F61134A9DA2788, 343E72DDCE64C957FC3FEBBAE07701F586DBD16D12B013B54F5C986D44A5A837
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\interaction-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B572407E0C81C95BFEF763B7670D7DBE, 1D3B08270958AA70BE29973AE9B87F56EC6EC831F10F9A1E081CDCF44B4DC841
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\meta-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , B3EC9E97CA55CD6E1AD7BBB8206B2FC5, EA39B76F95F77950F74DE6E82287BE6B393B99BCC902D66B7772C747BE6A18BF
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\sandbox-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 6D1F883A71165DEB5BB95BACF79A641A, 5FCDF159AE4F1C91C0BC0F4E4BB69830D6EA19FF688F86E84553F60293BB0E07
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\scraper-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , FEF90B8B18A295A8F3BB97ACB03DBF7C, F95B7EB1962C83374D374B8D76711E79E6D34865DCA590A741BB897F858B54FD
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\contextual-libraries\style-library.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , F36F6000B96E3D9D511D2D72C81E7410, 01C19EE9123CFE306E128CFF12EC62A7214A824BE196F1585AA4D14DE34660C2
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\1button-asmile-16.ico, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , CAFF44101A0E9787F047CFBC4FBA2CF3, C3E8E6AD8D0AF2E2F1AEC62D47E3D7B980B558C561855B2C8399013B1E862623
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\1button-asmile-24.ico, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , DA4DC611243BCCBAF0CB9B8C78C653FA, B6792E577674E93A894027CFE936CC16DC8ED8FAAA49B767E4C5D8FC9DF4F072
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\buttonstyle.css, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 1D509F5CDC36D4850F4760AFB47AC8A5, D2712AF7F84E00925D100BE3DDA396BEB141DF24723B90E34C5E2304BBFA2840
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\injectedmessagelistener.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 0849CDB956CE37E8815F179908401B85, 681DC1D44A1F19035E265871101DD1C95999A055C73E2BBFFF342C4332BB2715
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\logo.png, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 8F396843950111F1944A62FEF9CEA6EB, 287F8A17B0D2F17A5862D64963AF328637680E060B087A7DB310ECD102CF7346
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\oneButton.xml, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 7A1DAD30F5092F981D6BB92329FA609E, EEBF12C5F5EE0FF471359398F9199ECABD0E9DFB05E77E71E8F54109BEC467CB
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\ubpmessage.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 65022B1949FA8290F1103CF708E4BC11, 0433560DCDAF252DE71DA9D7FE514AF00C915A39ADCE84948D6558AC89DB44A0
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\data\ubpmessagelistener.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , DE10F32FCEB63BEAE64E28F5C5ED769C, B5CA5A00E5C823AA42ED0033312E083B6B76AF45FC0357D2B72E06B486493F19
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\main-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , A24A1272009F489F9B3AA2D34B8BBCC3, 51CD77D6879101D7C7B9C236B360B3040943CF8CA04F257A67ADB06576F4A5B8
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\mode-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , E9B52326B928DD39CCE657E79DD11CC1, CCAFF80C835D9396A237A268594ACBC179C1601BB0D41AD0436EFDA6B502C8FD
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\notification-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5F2DFA225435279ABF4132BC1212A5D6, 4C9CF3E29A8D03FE0EFED23DC1D38600D5E8EFAE6310C196FD0EC8A5F4C7E755
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\product-compass-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 81F49DA89DF8B60D3C859912FB6B76DD, 4A5558F6367836A37B94FEAC2754B8C32B53F05C2C42D6629D716CD0D99172C7
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\bit\ext\core\config\titan-local-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 5B040F719CF378010C6E7FD512EFBFF2, BC5C54960B26553CA21AF487C9547118F1A4306D5C010BD37ACADD6607323E10
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\components\application-state.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 602D5F7E8BC379116C1434FF2A1A42AF, 60CFFF6B0BCC4610CDA795068DAA125FF0E68842F6E031DF6F4E32B97CD96CE3
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\components\campaign-attribution-agent.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 24B6B0FF2CC586DCC3169FFF8896E1AD, 578CE82FD9E41FED434E24F32B836464CA477F6B14D11A9085251D9CE3CD80D2
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\components\product-compass-manager.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 94A75D1B61E2F15A4F2204F05D713C28, 2ED3E70D4E9E82BC58AC11ED4A4CA1A949E14477A02D5783F029A583DD4CF7DC
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\extensions\mode\smile-mode-extension.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , BE798B15614495D5EC70978286D7EC68, 1A4D0FDBE6AF780D1D3F3B7C58C118FC0C9170DDDC8F1A3D3D867F080B6C3C8E
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform\sandbox\page-worker-remote-process-sandbox-delegate.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , C09A2664439B92D88BEC42A62FC061D7, 236E04CB4FFBF580E2CCEB1801B332D65BB12E97CC461E01D086540EAC5C4383
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform\platform-service-bootstrapper.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 96EF5A0F29076646AF96EEA0597C0A6B, 47AD3BA274A925355C8FE6F56E4DBBC0EFD8FAA1CC5D2FDC7DFCD2D9525AEAE9
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\platform\product-compass-frame.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 931CBA9F398B5A07D327CA32D9E9CEF3, 6F99303A5505E3641E8F19F490860A52DC8D770E82627F1941793733B6D50B59
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\storage\native-storage.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 8BF3B4F9FBA62D73198B434C75F87EA0, 641D8D4A93B364BACE045EF062CEAEA88A6FF26A88CBB801088BF553A0CC0860
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\wrappers\tab-map.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , C70A446FC69D88FBA8937B8A02FA0573, 1059FA7471D9C2EBAC1151EB7E1D75CE4EC2E01C6F015357F14E9242B0B5B06B
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\attribution-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 97D1877DB141DC8080926428E9C9C021, 155AC61755E3FB9A51B4BAC983AC4CD773352DAB05496B254C76DA6CF91BA29C
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\extension-config.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 3CA7DF0CAADA145BAFEC419B52C22F25, BCE95CB4877969D72144B01C18169EC4756007B8AA701A992D7BA159297EE3DB
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\main.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 281A480E76D5E867DA71197133A35305, 29DD44183411AF459B421B1596F22C943522DC2E2918CC10A717428A1E6DAF84
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\resources\ubp-install\lib\runtime.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , C9E6EE1B1026397DF744E14FD0C14C28, 93601312AFE28CD2C901A211C79C923C8ED587EB4C470F0DF89A90B943074E67
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\bootstrap.js, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , EDEEB3F4B254CCF86A7E0C9F85133384, 747EB3BE7184769237CDECBD8D6C03DCC2876CD4BA2A3DF69650608BA3B0CC8E
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\harness-options.json, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 74EBDC8BFE3B8E02D3DF92773232CB9E, 497118CD23AD382B1C0DE723EE86A87B7DCFECD0199B1417F0779CD57C5F20CF
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\icon.png, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 8F396843950111F1944A62FEF9CEA6EB, 287F8A17B0D2F17A5862D64963AF328637680E060B087A7DB310ECD102CF7346
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\install.rdf, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , 818498CAB8C952A945EEC2EE85516996, EC54551B9F32F61EE4D629EF89010E154E043BC51D37E8FB5FB36110C524AA68
PUP.Optional.Amazon1Button, C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\abb@amazon.com\locales.json, In Quarantäne, 3043, 493345, 1.0.96058, , ame, , A77421EB4FFAC031FF52E9D3B935998D, 8EBD8B8FF913E81C38A0C56E92417060D7CB578A662A601AA3EA98C5DA177682
PUP.Optional.ChipDe, C:\USERS\EMILIE\DOWNLOADS\ADWCLEANER - CHIP INSTALLER _AUZAV.EXE, In Quarantäne, 3874, 562568, 1.0.96058, , ame, , F5980F17F44DA870072C5CE396EB01BF, 2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B
PUP.Optional.ChipDe, C:\USERS\EMILIE\DOWNLOADS\ADWCLEANER - CHIP INSTALLER _UEUAV.EXE, In Quarantäne, 3874, 562568, 1.0.96058, , ame, , F5980F17F44DA870072C5CE396EB01BF, 2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B
PUP.Optional.BundleInstaller, C:\USERS\EMILIE\DOWNLOADS\SODAPDFDESKTOP14.EXE, In Quarantäne, 43, 1172329, 1.0.96058, , ame, , C88A0CEEFD336B577FA57E42D39D8886, F79AEDD0023456424EE3216A3EF9FA181546B0B0B6A21F191A4927527BBAED09
PUP.Optional.ChipDe, C:\USERS\EMILIE\DOWNLOADS\MICROSOFT EDGE - CHIP INSTALLER _MC6WP (1).EXE, In Quarantäne, 3874, 562568, 1.0.96058, , ame, , F5980F17F44DA870072C5CE396EB01BF, 2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B
PUP.Optional.ChipDe, C:\USERS\EMILIE\DOWNLOADS\MICROSOFT EDGE - CHIP INSTALLER _MC6WP.EXE, In Quarantäne, 3874, 562568, 1.0.96058, , ame, , F5980F17F44DA870072C5CE396EB01BF, 2F9079DF89E96A997A910F9243173AC60BFE625501452152F8AB281778E5696B

Physischer Sektor: 0
(keine bösartigen Elemente erkannt)

WMI: 0
(keine bösartigen Elemente erkannt)


(end)
         

ADW (ist der letzte Log, solltest du die vorhergehenden auch benötigen, gib gerne Bescheid):

Code:
ATTFilter
# -------------------------------
# Malwarebytes AdwCleaner 8.4.2.0
# -------------------------------
# Build:    03-04-2024
# Database: 2024-03-04.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    02-18-2025
# Duration: 00:00:12
# OS:       Windows 10 (Build 19045.5487)
# Scanned:  32104
# Detected: 70


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Adware.Heuristic            HKCU\SOFTWARE\438f84b93ab73e6e9ccd233d1abe724b

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

Preinstalled.ACERAOPFramework   Folder   C:\Program Files (x86)\ACER\AOP FRAMEWORK 
Preinstalled.ACERAOPFramework   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Run|BacKGround Agent 
Preinstalled.ACERAOPFramework   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{4A37A114-702F-4055-A4B6-16571D4A5353} 
Preinstalled.ACERClear.fiShellExtension   Registry   HKLM\Software\Classes\CLSID\{ED32C084-BABB-11E1-B491-D4D66088709B} 
Preinstalled.ACERClear.fiShellExtension   Registry   HKLM\Software\Wow6432Node\\Classes\CLSID\{ED32C084-BABB-11E1-B491-D4D66088709B} 
Preinstalled.AcerCareCenter   File   C:\Users\Public\Desktop\Acer Care Center.lnk 
Preinstalled.AcerCareCenter   Folder   C:\Program Files (x86)\ACER\CARE CENTER 
Preinstalled.AcerCareCenter   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A1AECEC-0766-473B-AE79-EAAA31DE758F}  
Preinstalled.AcerCareCenter   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A1AECEC-0766-473B-AE79-EAAA31DE758F}  
Preinstalled.AcerCareCenter   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A250F7B-4F8A-4FEA-8CAE-31F28DA85202}  
Preinstalled.AcerCareCenter   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACCAgent 
Preinstalled.AcerCareCenter   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACCBackgroundApplication 
Preinstalled.AcerCareCenter   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{1AF41E84-3408-499A-8C93-8891F0612719} 
Preinstalled.AcerExplorerAgent   Folder   C:\Program Files\ACER\ACER EXPLORER AGENT 
Preinstalled.AcerExplorerAgent   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{4D0F42CF-1693-43D9-BDC8-19141D023EE0} 
Preinstalled.AcerPortal   Folder   C:\Program Files (x86)\ACER\ACER PORTAL 
Preinstalled.AcerPortal   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{932EC946-767B-4FAA-9B54-A4A4A2DF1822}  
Preinstalled.AcerPortal   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AcerCloud 
Preinstalled.AcerPortal   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13} 
Preinstalled.AcerPowerManagement   Folder   C:\Program Files\ACER\ACER POWER MANAGEMENT 
Preinstalled.AcerQuickAccess   File   C:\Users\Emilie\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Acer Quick Access.lnk 
Preinstalled.AcerQuickAccess   Folder   C:\Program Files\ACER\ACER QUICK ACCESS 
Preinstalled.AcerQuickAccess   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25746121-EB7E-4B7E-9BA4-27CAC8316AA5}  
Preinstalled.AcerQuickAccess   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D20A4DC-B257-40AB-809F-565BEC5D3B5E}  
Preinstalled.AcerQuickAccess   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Power Button 
Preinstalled.AcerQuickAccess   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Quick Access 
Preinstalled.AcerQuickAccess   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{E3678E72-78E3-4F91-A9FB-913876FF6DA2} 
Preinstalled.AcerUEIPFramework   Folder   C:\Program Files\ACER\USER EXPERIENCE IMPROVEMENT PROGRAM\FRAMEWORK 
Preinstalled.AcerUEIPFramework   Folder   C:\Program Files\ACER\USER EXPERIENCE IMPROVEMENT PROGRAM\PLUGIN\APPMONITOR 
Preinstalled.AcerUEIPFramework   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6}  
Preinstalled.AcerUEIPFramework   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UbtFrameworkService 
Preinstalled.AcerUEIPFramework   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{12A718F2-2357-4D41-9E1F-18583A4745F7} 
Preinstalled.AcerabBox   Registry   HKLM\Software\Classes\CLSID\{5CCE71FA-9F61-4F24-9CD1-98D819B40D68} 
Preinstalled.GatewayPowerManagement   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59}  
Preinstalled.GatewayPowerManagement   Registry   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Power Management 
Preinstalled.HPCleanFLC   File   C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office.lnk 
Preinstalled.LenovoPowerDVD   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A} 
Preinstalled.LenovoPowerDVD   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{B46BEA36-0B71-4A4E-AE41-87241643FA0A} 
Preinstalled.PackardBellPowerManagement   Registry   HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{91F52DE4-B789-42B0-9311-A349F10E5479} 
Preinstalled.WildTangentGamesBundle   File   C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WildTangent Games App - acer.lnk 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDGAMES 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDGAMES\12 LABOURS OF HERCULES III GIRL POWER 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDGAMES\HOME MAKEOVER 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDGAMES\JEWEL MATCH 3 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDGAMES\JEWEL MATCH SNOWSCAPES 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDGAMES\MAGIC ACADEMY 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDGAMES\POLAR BOWLER 1ST FRAME 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDGAMES\RUNEFALL 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDTANGENT GAMES 
Preinstalled.WildTangentGamesBundle   Folder   C:\Program Files (x86)\WILDTANGENT GAMES\APP 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Classes\CLSID\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6} 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Ext\Preapproved\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6} 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-4527bc60-c537-4ef8-8c87-cc9539bb1241 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-4c57b906-a5ca-4c03-9798-68e13f3261f1 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-679326c7-f13f-4d56-ae2e-6a7fee2304c7 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-6e35cc10-c9f5-48e9-baf9-e03aec7ff14d 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-8d9b4f73-bb47-4fea-917d-c50dd2ffed5c 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-ad853ef4-00ea-4eae-8b6e-18dee9cd5722 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-d421feba-0407-4288-b40c-de6252d31e83 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WTA-ff512562-ab4b-4aae-9e8c-1d09bd47ac58 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangent wildgames Master Uninstall 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-acer-vegasworld 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-acer-villagersandheroes 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-acer-genres 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-acer-main 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App 
Preinstalled.WildTangentGamesBundle   Registry   HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer 
Preinstalled.WildTangentGamesBundle   Registry   HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6} 
Preinstalled.WildTangentGamesBundle   Registry   HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7A97880C-7DD3-4C6E-8DE0-881B1FC02BE6} 


AdwCleaner[S00].txt - [9475 octets] - [17/02/2025 13:29:23]
AdwCleaner[C00].txt - [9839 octets] - [17/02/2025 13:36:51]
AdwCleaner[S01].txt - [2005 octets] - [17/02/2025 19:40:32]
AdwCleaner[C01].txt - [2081 octets] - [17/02/2025 19:42:15]
AdwCleaner[S02].txt - [1706 octets] - [17/02/2025 19:58:02]
AdwCleaner[C02].txt - [1876 octets] - [17/02/2025 19:58:18]
AdwCleaner[S03].txt - [1786 octets] - [17/02/2025 20:00:33]
AdwCleaner[C03].txt - [1976 octets] - [17/02/2025 20:01:03]
AdwCleaner[S04].txt - [1950 octets] - [17/02/2025 21:21:16]
AdwCleaner[C04].txt - [2236 octets] - [17/02/2025 21:21:32]
AdwCleaner[S05].txt - [17036 octets] - [18/02/2025 08:03:33]
AdwCleaner[C05].txt - [6839 octets] - [18/02/2025 08:04:54]
AdwCleaner[S06].txt - [11462 octets] - [18/02/2025 08:45:38]
AdwCleaner[C06].txt - [2504 octets] - [18/02/2025 08:46:03]
AdwCleaner[S07].txt - [11585 octets] - [18/02/2025 08:57:08]
AdwCleaner[C07].txt - [2627 octets] - [18/02/2025 08:57:22]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S08].txt ##########
         

Alt Heute, 16:21   #5
cosinus
/// Winkelfunktion
/// TB-Süch-Tiger™
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic



Und noch ein 2. Hinweis vorab:

Zitat:
BIOS: Insyde Corp. V1.09 05/17/2016
Motherboard: Acer Aspire VN7-792G
Processor: Intel(R) Core(TM) i5-6300HQ CPU @ 2.30GHz
Der Rechner wird mit Windows keine Zukunft mehr haben; zwei Generationen zu alt für Windows 11.

__________________
Logfiles bitte immer in CODE-Tags posten

Alt Heute, 16:26   #6
M-K-D-B
/// TB-Ausbilder
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic



Danke für die Logs, ich bereite eine Reparatur vor.

Ursache für deine "Infektionen" sind deine Downloadquellen. Halte dich von Chip.de fern!

Eine kurze Information vorab:

Downloadquellen
Die folgenden Seiten verteilen Software häufig mit einem sog. "Installer", mit dem Potentiell Unerwünschte Programme (PUP) oder Adware installiert werden können.
Vereinzelt beinhalten diese "Installer" sogar Trojaner.
Vermeide daher unbedingt die folgenden Seiten:
  • Chip.de
  • Softonic.de
  • sourceforge.net
  • openoffice.de
  • VLC.de
  • audacity.de
  • gimp24.de
  • jdownloader.org
  • computerbild.de
  • updatestar.com

Für Windows gibt es seit einiger Zeit einen brauchbaren Paketmanager, der mit einfachen Befehlen es erlaubt, automatisiert Software herunterzuladen und zu installieren. Das erspart eine Menge Arbeit, denn ohne einen Paketmanager muss man jedes Programm selbst prüfen und separat manuell updaten, vorher manuell noch runterladen etc. pp. - siehe auch --> chocolatey Paketmanager für Windows

Wir empfehlen dringend, alle Programme, sofern verfügbar, über chocolatey zu installieren. Falls du schon mit Linux zu tun hattest, wird dir die Syntax sehr vertraut sein.
Die FAQs zu choco findest du da --> Chocolatey: Häufig gestellte Fragen (englisch)
Selbstverständlich darfst du auch Fragen zu chocolatey im o.g. Thread zu chocolatey stellen.


Für den seltenen Fall, dass du das benötigte Programm nicht im repository von chocolatey findest: Lade diese Software immer direkt beim jeweiligen Hersteller / Entwickler.

Alt Heute, 16:31   #7
Emma88
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic



Danke dir für die schnelle Hilfe und die Hinweise! Das werde ich in Zukunft beachten! Den Paketmanager schaue ich mir an, sobald ich die Reparatur vollzogen habe.

Alt Heute, 16:38   #8
M-K-D-B
/// TB-Ausbilder
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic



Wir führen eine Reparatur mit FRST durch.
Diese wird bestimmt ein paar Minuten dauern, weil wir die Systemdateien auch gleich noch auf Fehler hin überprüfen.
Du solltest nebenbei nichts anderes am System machen.




Reparatur mit FRST
HINWEIS AN ALLE MITLESER:
Dieses FRST-Skript ist ausschließlich für diesen Nutzer gedacht und sollte niemals 1:1 für ein anderes System verwendet werden!
  • Speichere deine Arbeiten und schließe alle offenen Programme, damit keine Daten verloren gehen.
  • Markiere den gesamten Inhalt der folgenden Code-Box mit der Maus und kopiere ihn (gleichzeitiges Drücken der beiden Tasten "STRG" + "C"):
    Code:
    ATTFilter
    Start::
    CreateRestorePoint:
    CloseProcesses:
    AlternateDataStreams: C:\Users\Emilie\Downloads:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Pictures:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Desktop\.dbxignore:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Desktop\Die ästhetische Psychologie Hugo Münsterbergs.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Desktop\Elements 10B8 - Verknüpfung.lnk:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Desktop\Masterarbeit_Final_Mutti.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Desktop\Office Home and Student 2016:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Desktop\Spotify.lnk:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\.dbxignore:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\0307190535.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020 (1).pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2021.pdf:com.dropbox.attrs [52]
    AlternateDataStreams: C:\Users\Emilie\Downloads\2021-10141374.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\2022-12197991.pdf:com.dropbox.attrs [13]
    AlternateDataStreams: C:\Users\Emilie\Downloads\2307191224.pdf:com.dropbox.attrs [13]
    AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17(1).pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\4661823_t201402060_mit_Zusatzinfos.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\5072581_Wertermittlungsliste.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\9MYHZ8.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\Angebot-7099991-41393-00_2020-05-01_13-55.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\Anleitung_WISOSB20.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750(1).pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Downloads\FRSTEnglish.exe:MBAM.Zone.Identifier [225]
    AlternateDataStreams: C:\Users\Emilie\Documents\.dbxignore:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\AirDroid:com.dropbox.attrs [13]
    AlternateDataStreams: C:\Users\Emilie\Documents\amazon_bestellung_glühbirne_a.PNG:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\ausschreibung_projektbearbeiter_in_zip_2022_0.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Barmer_Unterlagen:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Benutzerdefinierte Office-Vorlagen:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Bewerbungen_Alt:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Bürgeramt:com.dropbox.attrs [13]
    AlternateDataStreams: C:\Users\Emilie\Documents\CyberLink:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Deutsche Bank:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\DKB:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Eigene Bilder:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Erasmus+2018:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Favorites:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Fax:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\FitX-2020-04-06_Kuendigung.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Flamenco:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\HandyHüllle_Bestellung.PNG:com.dropbox.attrs [52]
    AlternateDataStreams: C:\Users\Emilie\Documents\Hörbücher und Comedy:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Immatrikulationsbescheinigungen_BA:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Indien-Unterlagen:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Jobs2022.PNG:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\JobsNGO_Savethechildren.PNG:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Kottbusser Damm 8:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Kreuzworträtsel_Geburtstag_Kerstin.docx:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:3or4kl4x13tuuug3Byamue2s4b [93]
    AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
    AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.pdf:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\*****, Emilie - Einkommensteuer 2019.steuer2019:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Lebenslauf_Emilie*****_Therapie.docx:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\MADRID_2017_2018:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Master_Imma_Exma:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\NIE:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Outlook-Dateien:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Podcast.docx:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Rückenkurs:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Sanitas:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Scanned Documents:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Smartmobil:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Steuer:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Synchronbuchautorin Kurs.docx:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Tickets:com.dropbox.attrs [52]
    AlternateDataStreams: C:\Users\Emilie\Documents\VID_20210121_191050.mp4:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Wirbelsäulengymnastik:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\WS2016_2017 Masterarbeit:com.dropbox.attrs [54]
    AlternateDataStreams: C:\Users\Emilie\Documents\Übergabeprotokoll_Feuerbachstraße.pdf:com.dropbox.attrs [54]
    HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
    Startup: C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BitCleaner Tasker.lnk [2025-02-18] <==== ATTENTION
    ShortcutTarget: BitCleaner Tasker.lnk -> C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner\BitCleaner Tasker.exe (BINARYLABS LIMITED -> Binarylabs LTD) <==== ATTENTION
    C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner
    Task: {25746121-EB7E-4B7E-9BA4-27CAC8316AA5} - \Power Button -> No File <==== ATTENTION
    Task: {4F117C79-2706-4FBF-A748-C0259F51CEFA} - \Software Update Application -> No File <==== ATTENTION
    Task: {511D4F70-5C34-4428-AFAE-10D347114DCB} - \Microsoft\Windows\Windows Defender\Windows Defender Verification -> No File <==== ATTENTION
    Task: {611C823C-437B-46E7-9683-5312DFFCFD7B} - \Microsoft\Windows\UpdateOrchestrator\Policy Install -> No File <==== ATTENTION
    Task: {6A1AECEC-0766-473B-AE79-EAAA31DE758F} - \ACCAgent -> No File <==== ATTENTION
    Task: {6A250F7B-4F8A-4FEA-8CAE-31F28DA85202} - \ACCBackgroundApplication -> No File <==== ATTENTION
    Task: {6C488413-8509-4D62-94EB-159DC0C33122} - \Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan -> No File <==== ATTENTION
    Task: {7A003965-A297-4DC6-B15B-852D798391E0} - \Microsoft\Windows\UpdateOrchestrator\Reboot -> No File <==== ATTENTION
    Task: {7F4D5DE3-08C8-4008-AC82-C84BCA4B16DB} - \FUBTrackingByPLD -> No File <==== ATTENTION
    Task: {848DCC36-520C-4946-BF68-C7EFFEFA2F84} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot -> No File <==== ATTENTION
    Task: {8D20A4DC-B257-40AB-809F-565BEC5D3B5E} - \Quick Access -> No File <==== ATTENTION
    Task: {932EC946-767B-4FAA-9B54-A4A4A2DF1822} - \AcerCloud -> No File <==== ATTENTION
    Task: {93C99DC9-B400-40D5-A6DF-4310EAF3F1A6} - \Avast SecureLine -> No File <==== ATTENTION
    Task: {992AC68E-7168-40E1-B170-A736E71585A5} - \Microsoft\Office\Microsoft Office Touchless Attach Notification -> No File <==== ATTENTION
    Task: {A364E297-00AD-490D-900E-22AC34598C71} - \Microsoft\Windows\UpdateOrchestrator\Maintenance Install -> No File <==== ATTENTION
    Task: {BD02C08D-BA88-414E-A5E4-15FAFEB09DF3} - \Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance -> No File <==== ATTENTION
    Task: {C33F4607-C279-4257-9039-34FF9FE1F21A} - \Microsoft\Windows\AppID\SmartScreenSpecific -> No File <==== ATTENTION
    Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - \Microsoft\Windows\WindowsUpdate\sih -> No File <==== ATTENTION
    Task: {E135F27F-CC77-4798-8095-E4F7E716DE31} - \Microsoft\Windows\Windows Defender\Windows Defender Cleanup -> No File <==== ATTENTION
    Task: {E6010D43-6AE7-4B59-8E67-EC78FD8E8E96} - \Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler -> No File <==== ATTENTION
    Task: {E98AFDFB-4B5D-4DC1-9DCF-5DD16ED4B901} - \Microsoft\Windows\Plug and Play\Plug and Play Cleanup -> No File <==== ATTENTION
    Task: {EA3F661E-B31C-44A9-B40C-E3D5D56149D4} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display -> No File <==== ATTENTION
    Task: {F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6} - \UbtFrameworkService -> No File <==== ATTENTION
    Task: {FBE1992D-A1B2-44DD-9601-A1A2F799B096} - \ACC -> No File <==== ATTENTION
    Task: {FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59} - \Power Management -> No File <==== ATTENTION
    C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\abb@amazon.com
    S2 DCIService; C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe [X] <==== ATTENTION
    C:\Users\AllUserName\AppData\Roaming\BitCleaner
    C:\Program Files (x86)\Lavasoft
    C:\ProgramData\Application Data\Lavasoft
    C:\ProgramData\Lavasoft
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
    C:\Users\AllUserName\AppData\Local\Lavasoft
    C:\Users\AllUserName\AppData\Roaming\Lavasoft
    DeleteKey: HKCU\Software\Lavasoft
    DeleteKey: HKLM\Software\Wow6432Node\Lavasoft
    DeleteKey: HKCU\SOFTWARE\438f84b93ab73e6e9ccd233d1abe724b
    CMD: cscript /nologo %systemroot%\System32\slmgr.vbs /dlv
    CMD: netsh winsock reset
    CMD: netsh advfirewall reset
    CMD: netsh advfirewall set allprofiles state ON
    CMD: netsh winhttp reset proxy
    CMD: Bitsadmin /Reset /Allusers
    CMD: Winmgmt /salvagerepository 
    CMD: Winmgmt /verifyrepository
    CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
    CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
    CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
    CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
    CMD: sfc /scannow
    Hosts:
    RemoveProxy:
    EmptyTemp:
    End::
             
  • Starte nun FRST und klicke direkt auf den Button Reparieren.
    Wichtig: Du brauchst den Inhalt der Code-Box nirgends einfügen, da sich FRST den Code aus der Zwischenablage holt!
  • Das Tool führt die gewünschten Schritte aus und erstellt die Datei fixlog.txt im selben Verzeichnis, in dem sich FRST befindet.
  • Zum Abschluss wird das System neu gestartet.
  • Poste mir den Inhalt der Datei fixlog.txt mit deiner nächsten Antwort.

Alt Heute, 17:36   #9
Emma88
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic



Das hat etwas länger gedauert aber hier ist die Datei fixlog.txt:

Code:
ATTFilter
Fix result of Farbar Recovery Scan Tool (x64) Version: 18-02-2025
Ran by Emilie (18-02-2025 16:44:18) Run:1
Running from C:\Users\Emilie\Downloads
Loaded Profiles: Emilie
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start::
CreateRestorePoint:
CloseProcesses:
AlternateDataStreams: C:\Users\Emilie\Downloads:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Pictures:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\.dbxignore:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Die ästhetische Psychologie Hugo Münsterbergs.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Elements 10B8 - Verknüpfung.lnk:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Masterarbeit_Final_Mutti.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Office Home and Student 2016:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Desktop\Spotify.lnk:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\.dbxignore:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\0307190535.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020 (1).pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2021.pdf:com.dropbox.attrs [52]
AlternateDataStreams: C:\Users\Emilie\Downloads\2021-10141374.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\2022-12197991.pdf:com.dropbox.attrs [13]
AlternateDataStreams: C:\Users\Emilie\Downloads\2307191224.pdf:com.dropbox.attrs [13]
AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17(1).pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\4661823_t201402060_mit_Zusatzinfos.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\5072581_Wertermittlungsliste.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\9MYHZ8.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\Angebot-7099991-41393-00_2020-05-01_13-55.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\Anleitung_WISOSB20.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750(1).pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\ARC6903138750.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Downloads\FRSTEnglish.exe:MBAM.Zone.Identifier [225]
AlternateDataStreams: C:\Users\Emilie\Documents\.dbxignore:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\AirDroid:com.dropbox.attrs [13]
AlternateDataStreams: C:\Users\Emilie\Documents\amazon_bestellung_glühbirne_a.PNG:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\ausschreibung_projektbearbeiter_in_zip_2022_0.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Barmer_Unterlagen:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Benutzerdefinierte Office-Vorlagen:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Bewerbungen_Alt:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Bürgeramt:com.dropbox.attrs [13]
AlternateDataStreams: C:\Users\Emilie\Documents\CyberLink:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Deutsche Bank:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\DKB:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Eigene Bilder:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Erasmus+2018:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Favorites:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Fax:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\FitX-2020-04-06_Kuendigung.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Flamenco:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\HandyHüllle_Bestellung.PNG:com.dropbox.attrs [52]
AlternateDataStreams: C:\Users\Emilie\Documents\Hörbücher und Comedy:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Immatrikulationsbescheinigungen_BA:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Indien-Unterlagen:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Jobs2022.PNG:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\JobsNGO_Savethechildren.PNG:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Kottbusser Damm 8:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Kreuzworträtsel_Geburtstag_Kerstin.docx:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:3or4kl4x13tuuug3Byamue2s4b [93]
AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.pdf:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\*****, Emilie - Einkommensteuer 2019.steuer2019:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Lebenslauf_Emilie*****_Therapie.docx:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\MADRID_2017_2018:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Master_Imma_Exma:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\NIE:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Outlook-Dateien:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Podcast.docx:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Rückenkurs:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Sanitas:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Scanned Documents:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Smartmobil:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Steuer:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Synchronbuchautorin Kurs.docx:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Tickets:com.dropbox.attrs [52]
AlternateDataStreams: C:\Users\Emilie\Documents\VID_20210121_191050.mp4:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Wirbelsäulengymnastik:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\WS2016_2017 Masterarbeit:com.dropbox.attrs [54]
AlternateDataStreams: C:\Users\Emilie\Documents\Übergabeprotokoll_Feuerbachstraße.pdf:com.dropbox.attrs [54]
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction <==== ATTENTION
Startup: C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BitCleaner Tasker.lnk [2025-02-18] <==== ATTENTION
ShortcutTarget: BitCleaner Tasker.lnk -> C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner\BitCleaner Tasker.exe (BINARYLABS LIMITED -> Binarylabs LTD) <==== ATTENTION
C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner
Task: {25746121-EB7E-4B7E-9BA4-27CAC8316AA5} - \Power Button -> No File <==== ATTENTION
Task: {4F117C79-2706-4FBF-A748-C0259F51CEFA} - \Software Update Application -> No File <==== ATTENTION
Task: {511D4F70-5C34-4428-AFAE-10D347114DCB} - \Microsoft\Windows\Windows Defender\Windows Defender Verification -> No File <==== ATTENTION
Task: {611C823C-437B-46E7-9683-5312DFFCFD7B} - \Microsoft\Windows\UpdateOrchestrator\Policy Install -> No File <==== ATTENTION
Task: {6A1AECEC-0766-473B-AE79-EAAA31DE758F} - \ACCAgent -> No File <==== ATTENTION
Task: {6A250F7B-4F8A-4FEA-8CAE-31F28DA85202} - \ACCBackgroundApplication -> No File <==== ATTENTION
Task: {6C488413-8509-4D62-94EB-159DC0C33122} - \Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan -> No File <==== ATTENTION
Task: {7A003965-A297-4DC6-B15B-852D798391E0} - \Microsoft\Windows\UpdateOrchestrator\Reboot -> No File <==== ATTENTION
Task: {7F4D5DE3-08C8-4008-AC82-C84BCA4B16DB} - \FUBTrackingByPLD -> No File <==== ATTENTION
Task: {848DCC36-520C-4946-BF68-C7EFFEFA2F84} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot -> No File <==== ATTENTION
Task: {8D20A4DC-B257-40AB-809F-565BEC5D3B5E} - \Quick Access -> No File <==== ATTENTION
Task: {932EC946-767B-4FAA-9B54-A4A4A2DF1822} - \AcerCloud -> No File <==== ATTENTION
Task: {93C99DC9-B400-40D5-A6DF-4310EAF3F1A6} - \Avast SecureLine -> No File <==== ATTENTION
Task: {992AC68E-7168-40E1-B170-A736E71585A5} - \Microsoft\Office\Microsoft Office Touchless Attach Notification -> No File <==== ATTENTION
Task: {A364E297-00AD-490D-900E-22AC34598C71} - \Microsoft\Windows\UpdateOrchestrator\Maintenance Install -> No File <==== ATTENTION
Task: {BD02C08D-BA88-414E-A5E4-15FAFEB09DF3} - \Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance -> No File <==== ATTENTION
Task: {C33F4607-C279-4257-9039-34FF9FE1F21A} - \Microsoft\Windows\AppID\SmartScreenSpecific -> No File <==== ATTENTION
Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - \Microsoft\Windows\WindowsUpdate\sih -> No File <==== ATTENTION
Task: {E135F27F-CC77-4798-8095-E4F7E716DE31} - \Microsoft\Windows\Windows Defender\Windows Defender Cleanup -> No File <==== ATTENTION
Task: {E6010D43-6AE7-4B59-8E67-EC78FD8E8E96} - \Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler -> No File <==== ATTENTION
Task: {E98AFDFB-4B5D-4DC1-9DCF-5DD16ED4B901} - \Microsoft\Windows\Plug and Play\Plug and Play Cleanup -> No File <==== ATTENTION
Task: {EA3F661E-B31C-44A9-B40C-E3D5D56149D4} - \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display -> No File <==== ATTENTION
Task: {F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6} - \UbtFrameworkService -> No File <==== ATTENTION
Task: {FBE1992D-A1B2-44DD-9601-A1A2F799B096} - \ACC -> No File <==== ATTENTION
Task: {FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59} - \Power Management -> No File <==== ATTENTION
C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\abb@amazon.com
S2 DCIService; C:\Program Files (x86)\Lavasoft\Web Companion\Service\x64\DCIService.exe [X] <==== ATTENTION
C:\Users\AllUserName\AppData\Roaming\BitCleaner
C:\Program Files (x86)\Lavasoft
C:\ProgramData\Application Data\Lavasoft
C:\ProgramData\Lavasoft
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
C:\Users\AllUserName\AppData\Local\Lavasoft
C:\Users\AllUserName\AppData\Roaming\Lavasoft
DeleteKey: HKCU\Software\Lavasoft
DeleteKey: HKLM\Software\Wow6432Node\Lavasoft
DeleteKey: HKCU\SOFTWARE\438f84b93ab73e6e9ccd233d1abe724b
CMD: cscript /nologo %systemroot%\System32\slmgr.vbs /dlv
CMD: netsh winsock reset
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: netsh winhttp reset proxy
CMD: Bitsadmin /Reset /Allusers
CMD: Winmgmt /salvagerepository 
CMD: Winmgmt /verifyrepository
CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
CMD: "%WINDIR%\SYSTEM32\lodctr.exe" /R
CMD: "%WINDIR%\SysWOW64\lodctr.exe" /R
CMD: sfc /scannow
Hosts:
RemoveProxy:
EmptyTemp:
End::
*****************

Restore point was successfully created.
Processes closed successfully.
C:\Users\Emilie\Downloads => ":com.dropbox.attrs" ADS could not remove.
C:\Users\Emilie\Pictures => ":com.dropbox.attrs" ADS could not remove.
C:\Users\Emilie\Desktop\.dbxignore => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Desktop\Die ästhetische Psychologie Hugo Münsterbergs.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Desktop\Elements 10B8 - Verknüpfung.lnk => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Desktop\Masterarbeit_Final_Mutti.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Desktop\Office Home and Student 2016 => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Desktop\Spotify.lnk => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\.dbxignore => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\0307190535.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020 (1).pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2020.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\14_082_13727_Uebertragungsprotokoll_ESt_unbeschraenkt__ESt_1_A__2021.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\2021-10141374.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\2022-12197991.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\2307191224.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17(1).pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\3E1D7D1F1242A569B31895DA3C0013B93465FE17.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\4661823_t201402060_mit_Zusatzinfos.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\5072581_Wertermittlungsliste.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\9MYHZ8.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\Angebot-7099991-41393-00_2020-05-01_13-55.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\Anleitung_WISOSB20.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\ARC6903138750(1).pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Downloads\ARC6903138750.pdf => ":com.dropbox.attrs" ADS removed successfully
"C:\Users\Emilie\Downloads\FRSTEnglish.exe" => ":MBAM.Zone.Identifier" ADS not found.
C:\Users\Emilie\Documents\.dbxignore => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\AirDroid => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\amazon_bestellung_glühbirne_a.PNG => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\ausschreibung_projektbearbeiter_in_zip_2022_0.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Barmer_Unterlagen => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Benutzerdefinierte Office-Vorlagen => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Bewerbungen_Alt => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Bürgeramt => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\CyberLink => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Deutsche Bank => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\DKB => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Eigene Bilder => ":com.dropbox.attrs" ADS could not remove.
C:\Users\Emilie\Documents\Erasmus+2018 => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Favorites => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Fax => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\FitX-2020-04-06_Kuendigung.pdf => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Flamenco => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\HandyHüllle_Bestellung.PNG => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Hörbücher und Comedy => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Immatrikulationsbescheinigungen_BA => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Indien-Unterlagen => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Jobs2022.PNG => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\JobsNGO_Savethechildren.PNG => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Kottbusser Damm 8 => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Kreuzworträtsel_Geburtstag_Kerstin.docx => ":com.dropbox.attrs" ADS removed successfully
"C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg" => ":3or4kl4x13tuuug3Byamue2s4b" ADS not found.
"C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg" => ":com.dropbox.attrs" ADS not found.
"C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.jpg" => ":{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}" ADS not found.
"C:\Users\Emilie\Documents\Kurzarbeit_Vereinbarung_Emilie*****.pdf" => ":com.dropbox.attrs" ADS not found.
"C:\Users\Emilie\Documents\*****, Emilie - Einkommensteuer 2019.steuer2019" => ":com.dropbox.attrs" ADS not found.
"C:\Users\Emilie\Documents\Lebenslauf_Emilie*****_Therapie.docx" => ":com.dropbox.attrs" ADS not found.
C:\Users\Emilie\Documents\MADRID_2017_2018 => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Master_Imma_Exma => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\NIE => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Outlook-Dateien => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Podcast.docx => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Rückenkurs => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Sanitas => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Scanned Documents => ":com.dropbox.attrs" ADS could not remove.
C:\Users\Emilie\Documents\Smartmobil => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Steuer => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Synchronbuchautorin Kurs.docx => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Tickets => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\VID_20210121_191050.mp4 => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Wirbelsäulengymnastik => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\WS2016_2017 Masterarbeit => ":com.dropbox.attrs" ADS removed successfully
C:\Users\Emilie\Documents\Übergabeprotokoll_Feuerbachstraße.pdf => ":com.dropbox.attrs" ADS removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate => removed successfully
C:\Users\Emilie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BitCleaner Tasker.lnk => moved successfully
C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner\BitCleaner Tasker.exe => moved successfully

"C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner" Folder move:

C:\Windows.old\Users\Emilie\AppData\Roaming\BitCleaner => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{25746121-EB7E-4B7E-9BA4-27CAC8316AA5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25746121-EB7E-4B7E-9BA4-27CAC8316AA5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Power Button" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4F117C79-2706-4FBF-A748-C0259F51CEFA}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4F117C79-2706-4FBF-A748-C0259F51CEFA}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Software Update Application" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{511D4F70-5C34-4428-AFAE-10D347114DCB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{511D4F70-5C34-4428-AFAE-10D347114DCB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Verification" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{611C823C-437B-46E7-9683-5312DFFCFD7B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{611C823C-437B-46E7-9683-5312DFFCFD7B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Policy Install" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A1AECEC-0766-473B-AE79-EAAA31DE758F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A1AECEC-0766-473B-AE79-EAAA31DE758F}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACCAgent" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6A250F7B-4F8A-4FEA-8CAE-31F28DA85202}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A250F7B-4F8A-4FEA-8CAE-31F28DA85202}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACCBackgroundApplication" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6C488413-8509-4D62-94EB-159DC0C33122}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6C488413-8509-4D62-94EB-159DC0C33122}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7A003965-A297-4DC6-B15B-852D798391E0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A003965-A297-4DC6-B15B-852D798391E0}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Reboot" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7F4D5DE3-08C8-4008-AC82-C84BCA4B16DB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7F4D5DE3-08C8-4008-AC82-C84BCA4B16DB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\FUBTrackingByPLD" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{848DCC36-520C-4946-BF68-C7EFFEFA2F84}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{848DCC36-520C-4946-BF68-C7EFFEFA2F84}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8D20A4DC-B257-40AB-809F-565BEC5D3B5E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8D20A4DC-B257-40AB-809F-565BEC5D3B5E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Quick Access" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{932EC946-767B-4FAA-9B54-A4A4A2DF1822}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{932EC946-767B-4FAA-9B54-A4A4A2DF1822}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AcerCloud" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{93C99DC9-B400-40D5-A6DF-4310EAF3F1A6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{93C99DC9-B400-40D5-A6DF-4310EAF3F1A6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast SecureLine" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{992AC68E-7168-40E1-B170-A736E71585A5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{992AC68E-7168-40E1-B170-A736E71585A5}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Office\Microsoft Office Touchless Attach Notification" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A364E297-00AD-490D-900E-22AC34598C71}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A364E297-00AD-490D-900E-22AC34598C71}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\Maintenance Install" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BD02C08D-BA88-414E-A5E4-15FAFEB09DF3}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BD02C08D-BA88-414E-A5E4-15FAFEB09DF3}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C33F4607-C279-4257-9039-34FF9FE1F21A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C33F4607-C279-4257-9039-34FF9FE1F21A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\AppID\SmartScreenSpecific" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsUpdate\sih" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E135F27F-CC77-4798-8095-E4F7E716DE31}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E135F27F-CC77-4798-8095-E4F7E716DE31}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Defender\Windows Defender Cleanup" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{E6010D43-6AE7-4B59-8E67-EC78FD8E8E96}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6010D43-6AE7-4B59-8E67-EC78FD8E8E96}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E98AFDFB-4B5D-4DC1-9DCF-5DD16ED4B901}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E98AFDFB-4B5D-4DC1-9DCF-5DD16ED4B901}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Plug and Play\Plug and Play Cleanup" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA3F661E-B31C-44A9-B40C-E3D5D56149D4}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA3F661E-B31C-44A9-B40C-E3D5D56149D4}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F8006B03-D7A9-4E99-BFB0-2AF3AE5864F6}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UbtFrameworkService" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FBE1992D-A1B2-44DD-9601-A1A2F799B096}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FBE1992D-A1B2-44DD-9601-A1A2F799B096}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ACC" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FCC7232B-E99C-4A76-A1EE-F33DDD5CAE59}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Power Management" => removed successfully

"C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\abb@amazon.com" Folder move:

C:\Users\Emilie\AppData\Roaming\Mozilla\Firefox\Profiles\now364od.default\Extensions\abb@amazon.com => moved successfully
HKLM\System\CurrentControlSet\Services\DCIService => removed successfully
DCIService => service removed successfully
"C:\Users\ProgramData\AppData\Roaming\BitCleaner" => not found
"C:\Users\Default\AppData\Roaming\BitCleaner" => not found
"C:\Users\Emilie\AppData\Roaming\BitCleaner" => not found
"C:\Users\Public\AppData\Roaming\BitCleaner" => not found

"C:\Program Files (x86)\Lavasoft" Folder move:

C:\Program Files (x86)\Lavasoft => moved successfully

"C:\ProgramData\Application Data\Lavasoft" Folder move:

C:\ProgramData\Application Data\Lavasoft => moved successfully

"C:\ProgramData\Lavasoft" Folder move:

C:\ProgramData\Lavasoft => moved successfully

"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft" Folder move:

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft => moved successfully
"C:\Users\ProgramData\AppData\Local\Lavasoft" => not found
"C:\Users\Default\AppData\Local\Lavasoft" => not found

"C:\Users\Emilie\AppData\Local\Lavasoft" Folder move:

C:\Users\Emilie\AppData\Local\Lavasoft => moved successfully
"C:\Users\Public\AppData\Local\Lavasoft" => not found
"C:\Users\ProgramData\AppData\Roaming\Lavasoft" => not found
"C:\Users\Default\AppData\Roaming\Lavasoft" => not found

"C:\Users\Emilie\AppData\Roaming\Lavasoft" Folder move:

C:\Users\Emilie\AppData\Roaming\Lavasoft => moved successfully
"C:\Users\Public\AppData\Roaming\Lavasoft" => not found
HKCU\Software\Lavasoft => removed successfully
HKLM\Software\Wow6432Node\Lavasoft => removed successfully
HKCU\SOFTWARE\438f84b93ab73e6e9ccd233d1abe724b => not found

========= cscript /nologo %systemroot%\System32\slmgr.vbs /dlv =========

Softwarelizenzierungsdienst-Version: 10.0.19041.5486

Name: Windows(R), Core edition
Beschreibung: Windows(R) Operating System, OEM_DM channel
Aktivierungs-ID: 8db63db6-4f8f-46d6-a448-66444faaaa72
Anwendungs-ID: 55c92734-d682-4d71-983e-d6ec3f16059f
Erweiterte PID: 03612-03259-590-980202-02-1031-19045.0000-0492025
Product Key-Kanal: OEM:DM
Installations-ID: 712397573211500936751740479633014131501740885649006386437620724
Lizenz-URL verwenden: https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=DM
URL fr die šberprfung: https://validation-v2.sls.microsoft.com/SLWGA/slwga.asmx
Teil-Product Key: QJ3DR
Lizenzstatus: Lizenziert
Verbleibende Windows Rearm-Anzahl: 1001
Verbleibende SKU Rearm-Anzahl: 1001
Vertrauenswrdige Zeit: 18.02.2025 16:46:14




========= End of CMD: =========


========= netsh winsock reset =========


Der Winsock-Katalog wurde zurckgesetzt.
Sie mssen den Computer neu starten, um den Vorgang abzuschlieáen.



========= End of CMD: =========


========= netsh advfirewall reset =========

OK.



========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

OK.



========= End of CMD: =========


========= netsh winhttp reset proxy =========


Aktuelle WinHTTP-Proxyeinstellungen:

    DirectAccess (kein Proxyserver).



========= End of CMD: =========


========= Bitsadmin /Reset /Allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

{144701F6-5688-4268-8BA6-14DF94124BA1} canceled.
1 out of 1 jobs canceled.


========= End of CMD: =========


========= Winmgmt /salvagerepository =========

Das WMI-Repository ist konsistent.


========= End of CMD: =========


========= Winmgmt /verifyrepository =========

Das WMI-Repository ist konsistent.


========= End of CMD: =========


========= "%WINDIR%\SYSTEM32\lodctr.exe" /R =========


Fehler: Die Leistungsindikatoreinstellung konnte nicht aus dem Systemsicherungsspeicher neu erstellt werden. Fehlercode: 2.

========= End of CMD: =========


========= "%WINDIR%\SysWOW64\lodctr.exe" /R =========


Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.

========= End of CMD: =========


========= "%WINDIR%\SYSTEM32\lodctr.exe" /R =========


Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.

========= End of CMD: =========


========= "%WINDIR%\SysWOW64\lodctr.exe" /R =========


Info: Die Leistungsindikatoreinstellung konnte erfolgreich aus dem Systemsicherungsspeicher neu erstellt werden.

========= End of CMD: =========


========= sfc /scannow =========



Systemsuche wird gestartet. Dieser Vorgang kann einige Zeit dauern.



Überprüfungsphase der Systemsuche wird gestartet.


Überprüfung 0 % abgeschlossen.
Überprüfung 1 % abgeschlossen.
Überprüfung 1 % abgeschlossen.
Überprüfung 2 % abgeschlossen.
Überprüfung 3 % abgeschlossen.
Überprüfung 3 % abgeschlossen.
Überprüfung 4 % abgeschlossen.
Überprüfung 5 % abgeschlossen.
Überprüfung 5 % abgeschlossen.
Überprüfung 6 % abgeschlossen.
Überprüfung 7 % abgeschlossen.
Überprüfung 7 % abgeschlossen.
Überprüfung 8 % abgeschlossen.
Überprüfung 9 % abgeschlossen.
Überprüfung 9 % abgeschlossen.
Überprüfung 10 % abgeschlossen.
Überprüfung 11 % abgeschlossen.
Überprüfung 11 % abgeschlossen.
Überprüfung 12 % abgeschlossen.
Überprüfung 12 % abgeschlossen.
Überprüfung 13 % abgeschlossen.
Überprüfung 14 % abgeschlossen.
Überprüfung 14 % abgeschlossen.
Überprüfung 15 % abgeschlossen.
Überprüfung 16 % abgeschlossen.
Überprüfung 16 % abgeschlossen.
Überprüfung 17 % abgeschlossen.
Überprüfung 18 % abgeschlossen.
Überprüfung 18 % abgeschlossen.
Überprüfung 19 % abgeschlossen.
Überprüfung 20 % abgeschlossen.
Überprüfung 20 % abgeschlossen.
Überprüfung 21 % abgeschlossen.
Überprüfung 22 % abgeschlossen.
Überprüfung 22 % abgeschlossen.
Überprüfung 23 % abgeschlossen.
Überprüfung 23 % abgeschlossen.
Überprüfung 24 % abgeschlossen.
Überprüfung 25 % abgeschlossen.
Überprüfung 25 % abgeschlossen.
Überprüfung 26 % abgeschlossen.
Überprüfung 27 % abgeschlossen.
Überprüfung 27 % abgeschlossen.
Überprüfung 28 % abgeschlossen.
Überprüfung 29 % abgeschlossen.
Überprüfung 29 % abgeschlossen.
Überprüfung 30 % abgeschlossen.
Überprüfung 31 % abgeschlossen.
Überprüfung 31 % abgeschlossen.
Überprüfung 32 % abgeschlossen.
Überprüfung 33 % abgeschlossen.
Überprüfung 33 % abgeschlossen.
Überprüfung 34 % abgeschlossen.
Überprüfung 34 % abgeschlossen.
Überprüfung 35 % abgeschlossen.
Überprüfung 36 % abgeschlossen.
Überprüfung 36 % abgeschlossen.
Überprüfung 37 % abgeschlossen.
Überprüfung 38 % abgeschlossen.
Überprüfung 38 % abgeschlossen.
Überprüfung 39 % abgeschlossen.
Überprüfung 40 % abgeschlossen.
Überprüfung 40 % abgeschlossen.
Überprüfung 41 % abgeschlossen.
Überprüfung 42 % abgeschlossen.
Überprüfung 42 % abgeschlossen.
Überprüfung 43 % abgeschlossen.
Überprüfung 44 % abgeschlossen.
Überprüfung 44 % abgeschlossen.
Überprüfung 45 % abgeschlossen.
Überprüfung 45 % abgeschlossen.
Überprüfung 46 % abgeschlossen.
Überprüfung 47 % abgeschlossen.
Überprüfung 47 % abgeschlossen.
Überprüfung 48 % abgeschlossen.
Überprüfung 49 % abgeschlossen.
Überprüfung 49 % abgeschlossen.
Überprüfung 50 % abgeschlossen.
Überprüfung 51 % abgeschlossen.
Überprüfung 51 % abgeschlossen.
Überprüfung 52 % abgeschlossen.
Überprüfung 53 % abgeschlossen.
Überprüfung 53 % abgeschlossen.
Überprüfung 54 % abgeschlossen.
Überprüfung 55 % abgeschlossen.
Überprüfung 55 % abgeschlossen.
Überprüfung 56 % abgeschlossen.
Überprüfung 56 % abgeschlossen.
Überprüfung 57 % abgeschlossen.
Überprüfung 58 % abgeschlossen.
Überprüfung 58 % abgeschlossen.
Überprüfung 59 % abgeschlossen.
Überprüfung 60 % abgeschlossen.
Überprüfung 60 % abgeschlossen.
Überprüfung 61 % abgeschlossen.
Überprüfung 62 % abgeschlossen.
Überprüfung 62 % abgeschlossen.
Überprüfung 63 % abgeschlossen.
Überprüfung 64 % abgeschlossen.
Überprüfung 64 % abgeschlossen.
Überprüfung 65 % abgeschlossen.
Überprüfung 66 % abgeschlossen.
Überprüfung 66 % abgeschlossen.
Überprüfung 67 % abgeschlossen.
Überprüfung 68 % abgeschlossen.
Überprüfung 68 % abgeschlossen.
Überprüfung 69 % abgeschlossen.
Überprüfung 69 % abgeschlossen.
Überprüfung 70 % abgeschlossen.
Überprüfung 71 % abgeschlossen.
Überprüfung 71 % abgeschlossen.
Überprüfung 72 % abgeschlossen.
Überprüfung 73 % abgeschlossen.
Überprüfung 73 % abgeschlossen.
Überprüfung 74 % abgeschlossen.
Überprüfung 75 % abgeschlossen.
Überprüfung 75 % abgeschlossen.
Überprüfung 76 % abgeschlossen.
Überprüfung 77 % abgeschlossen.
Überprüfung 77 % abgeschlossen.
Überprüfung 78 % abgeschlossen.
Überprüfung 79 % abgeschlossen.
Überprüfung 79 % abgeschlossen.
Überprüfung 80 % abgeschlossen.
Überprüfung 80 % abgeschlossen.
Überprüfung 81 % abgeschlossen.
Überprüfung 82 % abgeschlossen.
Überprüfung 82 % abgeschlossen.
Überprüfung 83 % abgeschlossen.
Überprüfung 84 % abgeschlossen.
Überprüfung 84 % abgeschlossen.
Überprüfung 85 % abgeschlossen.
Überprüfung 86 % abgeschlossen.
Überprüfung 86 % abgeschlossen.
Überprüfung 87 % abgeschlossen.
Überprüfung 88 % abgeschlossen.
Überprüfung 88 % abgeschlossen.
Überprüfung 89 % abgeschlossen.
Überprüfung 90 % abgeschlossen.
Überprüfung 90 % abgeschlossen.
Überprüfung 91 % abgeschlossen.
Überprüfung 91 % abgeschlossen.
Überprüfung 92 % abgeschlossen.
Überprüfung 93 % abgeschlossen.
Überprüfung 93 % abgeschlossen.
Überprüfung 94 % abgeschlossen.
Überprüfung 95 % abgeschlossen.
Überprüfung 95 % abgeschlossen.
Überprüfung 96 % abgeschlossen.
Überprüfung 97 % abgeschlossen.
Überprüfung 97 % abgeschlossen.
Überprüfung 98 % abgeschlossen.
Überprüfung 99 % abgeschlossen.
Überprüfung 99 % abgeschlossen.
Überprüfung 100 % abgeschlossen.


Der Windows-Ressourcenschutz hat keine Integritätsverletzungen gefunden.



========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

========= RemoveProxy: =========

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
"HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
"HKU\S-1-5-21-2862171838-2850908273-2982186409-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully


========= End of RemoveProxy: =========


=========== EmptyTemp: ==========

FlushDNS => completed
BITS transfer queue => 1310720 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 25345394 B
Java, Discord, Steam htmlcache, WinHttpAutoProxySvc/winhttp *.cache => 0 B
Windows/system/drivers => 956385 B
Edge => 0 B
Firefox => 2815187 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 7680 B
ProgramData => 7680 B
Public => 7680 B
systemprofile => 7680 B
systemprofile32 => 7680 B
LocalService => 27036 B
NetworkService => 30762 B
Emilie => 106848282 B

RecycleBin => 2274352204 B
EmptyTemp: => 2.2 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 17:11:46 ====
         
Danke für den Hinweis. Könntest du mir ein gutes Antivirus Programm empfehlen? Was eventuell kostenlos ist aber die Basics abdeckt...

Alt Heute, 19:37   #10
M-K-D-B
/// TB-Ausbilder
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic



Gut gemacht.



Der in Windows integrierte Windows Defender genügt. Dieser aktiviert sich automatisch, sobald McAfee deinstalliert ist.
Aber kein Tool erkennt 100%, das musst du dir immer bewusst machen.


Findet AdwCleaner jetzt noch was? Mach mal einen neuen Suchlauf und berichte.

Führe bitte SecurityCheck (SC) gemäß der bebilderten Anleitung aus und poste abschließend die Logdatei.


Tipps gibts dann am Ende.

Geändert von M-K-D-B (Heute um 19:46 Uhr)

Alt Heute, 20:32   #11
Emma88
 
Windows 10: PUP.Adware.Heuristic - Standard

Windows 10: PUP.Adware.Heuristic



Danke dir für die ganze Hilfe! Den McAfee würde ich dann gleich mal deinstallieren!

Der AdwCleaner hat folgendes gemeldet:

Sie sind frei von PUPs und Adware.
Wir haben jedoch festgestellt, dass eine oder mehrere vorinstallierte Software auf ihrem Computer vorhanden ist.
Im nächsten Bildschirm haben Sie die Möglichkeit, diese zu behalten oder zu entfernen.

Ich habe die vorinstallierte Software jetzt nicht entfernt. Ist es ratsam das zu tun?

Hier die SC Logdatei:

Code:
ATTFilter
SecurityCheck by glax24 & Severnyj v.1.4.0.58 [15.08.24]
WebSite: www.safezone.cc
DateLog: 18.02.2025 20:24:22
Path starting: C:\Users\Emilie\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: Emilie
VersionXML: 13.36is-18.02.2025
___________________________________________________________________________

Windows 10 Core (x64) Release: 22H2 (10.0.19045.5487) Lang: German(0407)
Installation date OS: 18.02.2025 02:00:51
LicenseStatus: Office 16, Office16O365ProPlusR_Subscription1 edition Windows is in Notification mode
LicenseStatus: Office 16, Office16O365ProPlusR_Grace edition Windows is in Notification mode
LicenseStatus: Windows(R), Core edition The machine is permanently activated.
LicenseStatus: Office 16, Office16HomeStudentR_Retail edition The machine is permanently activated.
Boot Mode: Normal
Default Browser: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
SystemDrive: C: FS: [NTFS] Capacity: [930.9 Gb] Used: [167.7 Gb] Free: [763.2 Gb]
------------------------------- [ Windows ] -------------------------------
User Account Control enabled (Level 3)
Sicherheitscenter (wscsvc) - The service is running
Remoteregistrierung (RemoteRegistry) - The service has stopped
SSDP-Suche (SSDPSRV) - The service is running
Remotedesktopdienste (TermService) - The service has stopped
Windows-Remoteverwaltung (WS-Verwaltung) (WinRM) - The service has stopped
Background Intelligent Transfer Service (BITS) - The service has stopped
Übermittlungsoptimierung (DoSvc) - The service is running
Windows-Sicherheitsdienst (SecurityHealthService) - The service is running
Update Orchestrator Service (UsoSvc) - The service is running
Windows Update Medic Service (WaaSMedicSvc) - The service has stopped
Windows Update (wuauserv) - The service is running
------------------------------ [ MS Office ] ------------------------------
Microsoft Office 2013 x86 v.15.0.4693.1005
---------------------------- [ Antivirus_WMI ] ----------------------------
Malwarebytes (enabled and up to date)
Windows Defender (disabled and up to date)
McAfee Anti-Virus und Anti-Spyware (disabled)
---------------------------- [ Firewall_WMI ] -----------------------------
McAfee Firewall
--------------------------- [ AntiSpyware_WMI ] ---------------------------
Windows Defender (enabled and up to date)
---------------------- [ AntiVirusFirewallInstall ] -----------------------
Malwarebytes version 5.2.6.163 v.5.2.6.163
McAfee LiveSafe – Internet Security v.14.0.1122 Warning! Download Update
--------------------------- [ OtherUtilities ] ----------------------------
NVIDIA GeForce Experience 2.5.11.45 v.2.5.11.45 Warning! Download Update
Microsoft Edge WebView2-Laufzeit v.133.0.3065.69
Microsoft Office v.15.0.4693.1005
------------------------------- [ Backup ] --------------------------------
Microsoft OneDrive v.21.220.1024.0005 Warning! Download Update
---------------------------- [ ProxyAndVPNs ] -----------------------------
Avast SecureLine VPN v.25.1.11083.14496
------------------------------- [ Browser ] -------------------------------
Microsoft Edge v.133.0.3065.69
Mozilla Firefox 43.0.1 (x86 en-US) v.43.0.1 Warning! Download Update
------------------ [ AntivirusFirewallProcessServices ] -------------------
Avast SecureLine VPN (SecureLine) - The service is running
C:\Program Files\AVAST Software\SecureLine VPN\VpnSvc.exe v.25.1.11083.0
C:\Program Files\Malwarebytes\Anti-Malware\MbamBgNativeMsg.exe v.4.1.0.179
Malwarebytes Service (MBAMService) - The service is running
C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe v.3.2.0.1372
C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe v.15.4.0.674
McAfee Validation Trust Protection Service (mfevtp) - The service is running
C:\Windows\System32\mfevtps.exe
McAfee Firewall Core Service (mfefire) - The service is running
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe v.15.4.0.674
McAfee AP Service (McAPExe) - The service is running
C:\Program Files\mcafee\msc\McAPExe.exe v.14.0.1122.0
McAfee Personal Firewall Service (McMPFSvc) - The service is running
C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe v.5.0.281.0
C:\Program Files\Common Files\McAfee\platform\McUICnt.exe v.7.0.285.0
McAfee CSP Service (mccspsvc) - The service is running
C:\Program Files\Common Files\McAfee\CSP\1.5.471.0\McCSPServiceHost.exe v.1.5.471.0
McAfee Scanner (McODS) - The service has stopped
McAfee Service Controller (mfemms) - The service is running
C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe v.15.4.0.674
McAfee Home Network (HomeNetSvc) - The service is running
McAfee VirusScan Announcer (McNaiAnn) - The service is running
McAfee OOBE Service2 (McOobeSv2) - The service has stopped
McAfee Platform Services (mcpltsvc) - The service is running
McAfee Proxy Service (McProxy) - The service is running
McAfee Boot Delay Start Service (mcbootdelaystartsvc) - The service is running
McAfee Platform Services (mcpltsvc) - The service is running
C:\Program Files\AVAST Software\SecureLine VPN\VpnSvc.exe v.25.1.11083.0
Microsoft Defender Antivirus-Dienst (WinDefend) - The service has stopped
Microsoft Defender Antivirus-Netzwerkinspektionsdienst (WdNisSvc) - The service has stopped
----------------------------- [ End of Log ] ------------------------------
         

Eine kurze Frage noch: Auf meinem Desktop ist eine DBXIGNORE-Datei (.dbxignore) erschienen. Sollte ich die löschen?

Geändert von Emma88 (Heute um 20:57 Uhr)

Antwort

Themen zu Windows 10: PUP.Adware.Heuristic
avast, browser, computer, cpu, defender, desktop, fehler, home, installation, internet, internet explorer, malware, mozilla, pup.optional.amazon1button, pup.optional.amazon1button.appflsh, pup.optional.bundleinstaller, pup.optional.chipde, realtek, registry, rundll, security, services.exe, software, sparbuch, svchost.exe, trojaner, usb, windows, wiso




Ähnliche Themen: Windows 10: PUP.Adware.Heuristic


  1. Windows 10 PUP.Adware.Heuristic
    Log-Analyse und Auswertung - 13.02.2025 (11)
  2. Windows 11: Adw-Cleaner findet PUP.Adware.Heuristic
    Log-Analyse und Auswertung - 01.04.2024 (27)
  3. Adware/Malware in Firefox? PUP.Optional.StartFenster & Adware.KeenValue
    Plagegeister aller Art und deren Bekämpfung - 05.11.2019 (14)
  4. MS Jigsaw öffnet Chrome selbstständig. Scan findet - Adware.KeenValue - PUP.Adware.Heuristic - PUP.Optional.InstallCore
    Log-Analyse und Auswertung - 25.09.2019 (18)
  5. PUP.Conduit.Heuristic
    Plagegeister aller Art und deren Bekämpfung - 20.01.2019 (19)
  6. PUP.Winlogon.Heuristic entfernen
    Anleitungen, FAQs & Links - 16.12.2018 (2)
  7. Neuer 2 Fragen: Windows10 PC PUP.DownloadProtect.Heuristic / Anrufe von den Osterinseln
    Plagegeister aller Art und deren Bekämpfung - 11.07.2018 (4)
  8. Neuer 2 Fragen: Windows10 PC PUP.DownloadProtect.Heuristic / Anrufe von den Osterinseln
    Mülltonne - 07.07.2018 (1)
  9. Kriege ständig Adware Pup Heuristic angezeigt und nicht gelöscht - Adw Cleaner
    Plagegeister aller Art und deren Bekämpfung - 03.04.2018 (7)
  10. adw cleaner findet pup adware heuristic
    Plagegeister aller Art und deren Bekämpfung - 21.01.2018 (29)
  11. Window 7 - PUP.Adware.Heuristic in Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864
    Log-Analyse und Auswertung - 24.10.2017 (5)
  12. AdwCleaner 3 Funde PUP.Adware.Heuristic
    Plagegeister aller Art und deren Bekämpfung - 07.08.2017 (5)
  13. Malwarebytes-Fund: zahlreiche PUP und Adware.AdInstaller (Windows 7)
    Log-Analyse und Auswertung - 22.09.2016 (16)
  14. Windows 7: Junkware (PUP): Script.Adware.DealPly.G (Engine B)
    Log-Analyse und Auswertung - 27.05.2016 (51)
  15. Adware BDSearch, TrojanCinmus, PUP.Baidu, PUP-Optional.ConduitA
    Log-Analyse und Auswertung - 08.12.2013 (7)
  16. Windows 8: Adware.Agent und PUP.Optional
    Log-Analyse und Auswertung - 14.10.2013 (7)
  17. Avast findet NSIS:Adware-CE [Adw] und Win32:PUP-gen [PUP]. Was tun?
    Plagegeister aller Art und deren Bekämpfung - 12.01.2012 (11)

Zum Thema Windows 10: PUP.Adware.Heuristic - Hallo zusammen, seit ein paar Monaten hat sich hin und wieder in meinem Browser (Microsoft Edge) ein Fenster ohne Inhalt kurz geöffnet und schnell wieder geschlossen. Gestern kam es öfter - Windows 10: PUP.Adware.Heuristic...
Archiv
Du betrachtest: Windows 10: PUP.Adware.Heuristic auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.