Und weiter gehts:
GMER: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-03-27 18:27:01
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD10EARS-00Y5B1 rev.80.00A80 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Barbara\AppData\Local\Temp\uxtiyfob.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff800035f8000 16 bytes [8B, E3, 41, 5F, 41, 5E, 41, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 545 fffff800035f8011 35 bytes {LEA ECX, [RSP+0x70]; CALL 0x3d64f}
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\wininit.exe[644] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\services.exe[704] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\winlogon.exe[796] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[888] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[988] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\atiesrxx.exe[140] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\System32\svchost.exe[392] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\System32\svchost.exe[468] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[600] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[656] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[1180] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files\AVAST Software\Avast\afwServ.exe[1496] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Windows\System32\spoolsv.exe[1868] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[1896] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe[2008] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2020] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Windows\system32\svchost.exe[1204] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2044] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\AM\dtsslsrv.exe[2076] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\DeltaCopy\DCServce.exe[2188] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\DeltaCopy\rsync.exe[2236] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe[2260] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Windows\system32\svchost.exe[2288] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files\Lupinho.Net\HardlinkBackup\HardlinkBackup.Service.exe[2404] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\taskhost.exe[2544] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\inetsrv\inetinfo.exe[2920] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\Explorer.EXE[3000] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2684] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2684] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076cf1465 2 bytes [CF, 76]
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2684] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076cf14bb 2 bytes [CF, 76]
.text ... * 2
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2812] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe[3096] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3384] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe[3464] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3492] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3620] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076cf1465 2 bytes [CF, 76]
.text C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076cf14bb 2 bytes [CF, 76]
.text ... * 2
.text C:\Program Files\Lupinho.Net\HardlinkBackup\HardlinkBackupTray.exe[3628] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe[3676] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe[3796] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe[3796] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076cf1465 2 bytes [CF, 76]
.text C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe[3796] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076cf14bb 2 bytes [CF, 76]
.text ... * 2
.text C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe[3844] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe[3948] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files\AVAST Software\Avast\avastui.exe[3236] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4040] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\iTunes\iTunesHelper.exe[3176] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe[3296] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe[4516] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Windows\system32\svchost.exe[4608] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[4908] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[4984] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
? C:\Windows\system32\mssprxy.dll [4984] entry point in ".rdata" section 00000000622e71e6
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5504] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076cf1465 2 bytes [CF, 76]
.text C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076cf14bb 2 bytes [CF, 76]
.text ... * 2
.text C:\Windows\system32\SearchIndexer.exe[5264] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files\iPod\bin\iPodService.exe[6096] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Windows\system32\svchost.exe[6728] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[6528] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe[1392] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[3264] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5184] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
.text C:\Windows\system32\AUDIODG.EXE[6164] C:\Windows\System32\kernel32.dll!GetBinaryTypeW + 189 000000007718eecd 1 byte [62]
.text C:\Users\proworx\Desktop\Gmer-19357.exe[4092] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007521a2ba 1 byte [62]
---- Threads - GMER 2.1 ----
Thread C:\Windows\System32\svchost.exe [6028:3348] 000007fee4a49688
---- EOF - GMER 2.1 ---- Malwarebytes: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 26.03.2014
Scan Time: 00:42:50
Logfile: Malwarebytes_log.txt
Administrator: Yes
Version: 2.00.0.1000
Malware Database: v2014.03.25.09
Rootkit Database: v2014.03.18.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Barbara
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 473223
Time Elapsed: 26 min, 43 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 1
PUP.Optional.SnapDo.A, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, Quarantined, [a9d458af7ffc24127cf76ef3a260ab55],
Registry Values: 1
PUP.Optional.SnapDo.A, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, SnapdoOCYB, Quarantined, [a9d458af7ffc24127cf76ef3a260ab55]
Registry Data: 9
PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[4c31ed1a3744c274eba78182709418e8]
PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[a5d8798e83f8c373830e50b3788c8977]
PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[f28b16f1750604322470e122c4406e92]
PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[592416f1126977bf266f847f040044bc]
PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[314c996e6c0fdf572b6790733fc51be5]
PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013),Replaced,[e39abe49fe7d12242370fb08a95b857b]
PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[e994df28166571c59ff207fc8a7ac53b]
PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[57263acd4d2e082e1a7a08fbd92b52ae]
PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[afce7790502b83b3dbba0003c63e629e]
Folders: 19
PUP.Optional.OpenCandy, C:\Users\Barbara\AppData\Roaming\OpenCandy, Quarantined, [631a42c5f88395a19d806ede09f9639d],
PUP.Optional.OpenCandy, C:\Users\Barbara\AppData\Roaming\OpenCandy\B4C79BD4279644F4A0111551124D3A10, Quarantined, [631a42c5f88395a19d806ede09f9639d],
PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\FE30E2B520264DF8B6D59FEB193B05D1, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\CSS, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales\en, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales\es, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
Files: 96
PUP.Optional.Linkury.A, C:\Users\Barbara\AppData\Roaming\OpenCandy\B4C79BD4279644F4A0111551124D3A10\Installer.exe, Quarantined, [6914c2453f3c6acc80a41cbebd46f10f],
PUP.Optional.OpenCandy, C:\Users\proworx\Downloads\FreeFileSync_5.8_setup.exe, Quarantined, [681552b57605f244f62759ceb84c5ba5],
PUP.Optional.WebSearch.A, C:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\ao5y6bz5.default\searchplugins\Web Search.xml, Quarantined, [6a134abdea91b086c77284d325ddd030],
PUP.Optional.WebSearch.A, C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\aaqcgp11.default\searchplugins\Web Search.xml, Quarantined, [7c01ea1d8eed3df9a2978bcc877b847c],
PUP.Optional.WebSearch.A, C:\Users\Konstantin\AppData\Roaming\Mozilla\Firefox\Profiles\65yiqvla.default\searchplugins\Web Search.xml, Quarantined, [4f2ebf48a1da7bbbc9707cdb52b0619f],
PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A\3975.ico, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A\EBB77268-338F-4C6A-8590-AD88FED26F4A, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A\OCBrowserHelper_1.0.3.85.dll, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A\setup_759.exe, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\FE30E2B520264DF8B6D59FEB193B05D1\TuneUpUtilities2013_2200213_de-DE.exe, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\chLogic.exe, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\CT3244149.txt, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\dtime.csf, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\initData.json, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\manifest.json, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\statisticsStub.exe, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\bg.html, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\bg.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\manifest.json, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\options.htm, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\options.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\popup.html, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\popup.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\redirect.html, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\redirect.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\CSS\border.css, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\fb.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\fblike.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\gmail.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\google.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\googleplus.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\left.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\mgsplusvideo.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\pinit.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\right.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\searchBox.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\twitter.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\BackPageRemove.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\defaultBlockList.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\documentEvents.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\externalJS.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\FBImagePreview.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\InternalJS.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\jquery-1.9.0.min.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\PluginWrapper.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\publisherDefinitions.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\tabReload.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\TopFrameJS.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\homePage.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\SnapDo.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\SnapDo128.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\SnapDo16.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\SnapDo48.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\manifest.json, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\ajax.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\background.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\common.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\content.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\notifier.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\notify.css, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\back.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\bitty.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\close.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\logo-sm.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\logo.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales\en\messages.json, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales\es\messages.json, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
PUP.Optional.Snapdo.A, C:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\ao5y6bz5.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013");), Replaced,[59240403eb9081b5706c59d454b022de]
PUP.Optional.Snapdo.A, C:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\ao5y6bz5.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&installDate=27/12/2013&q=");), Replaced,[720b92754338bf778755a08d1ce8d729]
PUP.Optional.Snapdo.A, C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\aaqcgp11.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013");), Replaced,[88f5d334651688aea53756d722e2ed13]
PUP.Optional.Snapdo.A, C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\aaqcgp11.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&installDate=27/12/2013&q=");), Replaced,[3746b750304b42f42ab2d459fa0ad32d]
PUP.Optional.Snapdo.A, C:\Users\Konstantin\AppData\Roaming\Mozilla\Firefox\Profiles\65yiqvla.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013");), Replaced,[7b0250b73447a294716b0924f11343bd]
PUP.Optional.Snapdo.A, C:\Users\Konstantin\AppData\Roaming\Mozilla\Firefox\Profiles\65yiqvla.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&installDate=27/12/2013&q=");), Replaced,[dca1b255e19ada5cf9e3959861a302fe]
PUP.Optional.Snapdo.A, C:\Users\proworx\AppData\Roaming\Mozilla\Firefox\Profiles\vsts9pc7.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=nt&installDate=27/12/2013");), Replaced,[671638cfbcbf95a1528a51dca26220e0]
PUP.Optional.Snapdo.A, C:\Users\proworx\AppData\Roaming\Mozilla\Firefox\Profiles\vsts9pc7.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&installDate=27/12/2013&q=");), Replaced,[3d4032d58bf0ed499745220b39cbff01]
Physical Sectors: 0
(No malicious items detected)
(end) AdwCleaner 1.Mal: Code:
# AdwCleaner v3.022 - Bericht erstellt am 26/03/2014 um 12:43:08
# Aktualisiert 13/03/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Barbara - PROWORX-PC
# Gestartet von : C:\Users\Barbara\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\FreeRIP
Ordner Gelöscht : C:\Program Files (x86)\software4u
Ordner Gelöscht : C:\Users\proworx\AppData\Local\apn
Ordner Gelöscht : C:\Users\proworx\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\proworx\AppData\Local\Temp\AskSearch
Ordner Gelöscht : C:\Users\proworx\AppData\Local\Temp\boost_interprocess
Ordner Gelöscht : C:\Users\proworx\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Barbara\AppData\Roaming\software4u
Ordner Gelöscht : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
Ordner Gelöscht : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
[!] Ordner Gelöscht : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
[!] Ordner Gelöscht : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
Datei Gelöscht : \END
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\kfkcangbigakljkjeglcofaomihpejif
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{501451DE-5808-4599-B544-8BD0915B6B24}_is1
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
-\\ Google Chrome v33.0.1750.154
[ Datei : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht : homepage
Gelöscht : icon_url
Gelöscht : search_url
Gelöscht : keyword
[ Datei : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht : homepage
Gelöscht : icon_url
Gelöscht : search_url
Gelöscht : keyword
[ Datei : C:\Users\Konstantin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht : homepage
Gelöscht : icon_url
Gelöscht : search_url
Gelöscht : keyword
[ Datei : C:\Users\Jakob\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht : homepage
Gelöscht : icon_url
Gelöscht : search_url
Gelöscht : keyword
*************************
AdwCleaner[R0].txt - [5285 octets] - [26/03/2014 12:32:45]
AdwCleaner[S0].txt - [4690 octets] - [26/03/2014 12:43:08]
########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [4750 octets] ########## AdwCleaner 2.Mal: Code:
# AdwCleaner v3.022 - Bericht erstellt am 26/03/2014 um 12:32:45
# Aktualisiert 13/03/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Barbara - PROWORX-PC
# Gestartet von : C:\Users\Barbara\Downloads\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : \END
Ordner Gefunden : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
Ordner Gefunden : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
Ordner Gefunden : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
Ordner Gefunden : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
Ordner Gefunden C:\Program Files (x86)\FreeRIP
Ordner Gefunden C:\Program Files (x86)\software4u
Ordner Gefunden C:\Users\Barbara\AppData\Roaming\software4u
Ordner Gefunden C:\Users\proworx\AppData\Local\apn
Ordner Gefunden C:\Users\proworx\AppData\Local\PackageAware
Ordner Gefunden C:\Users\proworx\AppData\Local\Temp\AskSearch
Ordner Gefunden C:\Users\proworx\AppData\Local\Temp\boost_interprocess
Ordner Gefunden C:\Users\proworx\AppData\LocalLow\Conduit
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\kfkcangbigakljkjeglcofaomihpejif
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\kfkcangbigakljkjeglcofaomihpejif
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{501451DE-5808-4599-B544-8BD0915B6B24}_is1
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Wert Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] - hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013
Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default] - hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013
-\\ Google Chrome v33.0.1750.154
[ Datei : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gefunden : homepage
Gefunden : icon_url
Gefunden : search_url
Gefunden : keyword
[ Datei : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gefunden : homepage
Gefunden : icon_url
Gefunden : search_url
Gefunden : keyword
[ Datei : C:\Users\Konstantin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gefunden : homepage
Gefunden : icon_url
Gefunden : search_url
Gefunden : keyword
[ Datei : C:\Users\Jakob\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gefunden : homepage
Gefunden : icon_url
Gefunden : search_url
Gefunden : keyword
*************************
AdwCleaner[R0].txt - [5135 octets] - [26/03/2014 12:32:45]
########## EOF - \AdwCleaner\AdwCleaner[R0].txt - [5195 octets] ########## So, ich hoffe, du hast nun alles, was du brauchst!
Liebe Grüße
Barbara |