sunny123 | 25.04.2014 17:11 | Hallo, hier kommen meine neuen Dateien.
1. Schritt: Malwarebytes Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 25/04/2014
Suchlauf-Zeit: 17:08:30
Logdatei: MBAM.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.25.06
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Basti
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 275773
Verstrichene Zeit: 1 Std, 4 Min, 13 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 13
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [07f9a858827e9a660c82a9a6ea18dd23],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [07f9a858827e9a660c82a9a6ea18dd23],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [916fda2639c7d82857df7aa14bb729d7],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [916fda2639c7d82857df7aa14bb729d7],
PUP.Optional.DigitalSites.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DSite, Löschen bei Neustart, [d12fcd33966aaa561b5775b8dc25619f],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\DEALPLY, In Quarantäne, [857b738dfe028a76b392198352b1a25e],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, In Quarantäne, [758bd52bdb2549b7e5eb801b699ae719],
PUP.Optional.SmartBar, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SmartbarLog, Löschen bei Neustart, [0ff1718f30d0966a72044e65e81b58a8],
PUP.Optional.DealPly.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DEALPLY, Löschen bei Neustart, [6c94cc3452aefe0203465f3dd62d13ed],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [2bd5eb15bf4125db01e169316e95c937],
PUP.Optional.BProtector.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, Löschen bei Neustart, [d82855ab58a83ec258c0ccd28b78d22e],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, Löschen bei Neustart, [fc04be42c63a2dd3c30c029937cc956b],
PUP.Optional.DealPly.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\DealPly, Löschen bei Neustart, [0af6eb157c84f8080842bea46f93b24e],
Registrierungswerte: 7
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\DEALPLY|ChromeCrxPath, C:\Program Files (x86)\DealPly\DealPly.crx, In Quarantäne, [857b738dfe028a76b392198352b1a25e]
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, 1590556140525584383, In Quarantäne, [758bd52bdb2549b7e5eb801b699ae719]
PUP.Optional.DealPly.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DEALPLY|Partner, iron, Löschen bei Neustart, [6c94cc3452aefe0203465f3dd62d13ed]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0L1N1H2O1S, Löschen bei Neustart, [2bd5eb15bf4125db01e169316e95c937]
PUP.BProtector, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, hxxp://www.delta-search.com/?affID=119357&tt=gc_&babsrc=HP_ss&mntrId=B20700FF50C95005, Löschen bei Neustart, [c04022de2bd5eb15f0cc7d1d8e75e11f]
PUP.BProtector, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Löschen bei Neustart, [6799c33d25dbb74977466f2b7f8403fd]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, 1590556140525584383, Löschen bei Neustart, [fc04be42c63a2dd3c30c029937cc956b]
Registrierungsdaten: 9
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000),Löschen bei Neustart,[916f28d8c53b50b033b640e5b0547d83]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000),Löschen bei Neustart,[0cf419e7ca36e7196b698ba4ab59cc34]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000),Löschen bei Neustart,[5ca42cd451afae5203e52ff67d87936d]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000),Löschen bei Neustart,[3bc505fb25dbab5515bef03f3ec643bd]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000),Löschen bei Neustart,[b94733cd7888b848a44733f2758ffe02]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000),Löschen bei Neustart,[57a9de2270907f817561f73862a2ce32]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000),Löschen bei Neustart,[ee126f9110f008f8d21ab86d18eca25e]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000),Löschen bei Neustart,[58a8f50bfa061ee2f3e4cc632dd7926e]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2040692901-543291816-533557636-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOCCH&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=ds&q={searchTerms}&fr=linkury-tb&installDate={installDate}&barcodeid={barcodeID}&um={UM}&type=hp1000),Löschen bei Neustart,[e21ef40cb24e2bd5ecfb8a9be2228878]
Ordner: 29
PUP.Optional.SmartBar.A, C:\Users\Basti\AppData\Local\Temp\smartbar, In Quarantäne, [699733cdb54bd12f327487ffd42ea55b],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.DealPly.A, C:\Users\Basti\AppData\Roaming\DealPly, In Quarantäne, [0af6eb157c84f8080842bea46f93b24e],
PUP.Optional.DealPly.A, C:\Users\Basti\AppData\Roaming\DealPly\UpdateProc, In Quarantäne, [0af6eb157c84f8080842bea46f93b24e],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\0112907235A9428B90E2593F311DCA9B, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\08FDF9B0B8044ACCA5CA1FB5A09B4271, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\5C0D5C73EDCE40DC89445EF9845B5D50, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\6C76C951A0904B68BAEC2E8BEF33D5F3, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\7457A55C8A0B4FB3A8B71CDA7A1AA118, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.FileScout.A, C:\Users\Basti\AppData\Roaming\File Scout, In Quarantäne, [10f08f71e21e40c0d0c98cd62ad86f91],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\CSS, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
Dateien: 134
PUP.Optional.FileScout.A, C:\Users\Basti\AppData\Roaming\File Scout\filescout.exe, In Quarantäne, [6b9538c8d92701ff9a00d72ce02141bf],
PUP.Optional.DigitalSites.A, C:\Users\Basti\AppData\Roaming\DSite\UpdateProc\UpdateTask.exe, In Quarantäne, [d12fcd33966aaa561b5775b8dc25619f],
PUP.Optional.OpenCandy.A, C:\Users\Basti\AppData\Roaming\OpenCandy\0112907235A9428B90E2593F311DCA9B\LatestDLMgr.exe, In Quarantäne, [5da3fc0450b008f8e643d8304cb5d42c],
PUP.Optional.Linkury.A, C:\Users\Basti\AppData\Roaming\OpenCandy\6C76C951A0904B68BAEC2E8BEF33D5F3\Installer.exe, In Quarantäne, [d32d30d0d030cc34b0dfc63ae61ead53],
PUP.Optional.SmartBar.A, C:\Users\Basti\AppData\Local\Temp\smartbar\Installer.msi, In Quarantäne, [3cc411ef18e820e0e0f56abd689853ad],
PUP.Optional.Conduit.A, C:\Users\Basti\Downloads\ArcSoft_Panorama_Maker_6_TSV31GCBA.exe, In Quarantäne, [16eaa95759a797692b11e5615fa2f30d],
PUP.Optional.OpenCandy, C:\Users\Basti\Downloads\winamp563_full_emusic-7plus_de-de.exe, In Quarantäne, [a55b31cfba46d52b88bdd182877dde22],
PUP.Optional.OpenCandy, C:\Users\Basti\Downloads\winamp565_full_emusic-7plus_de-de.exe, In Quarantäne, [a45caa56837d5aa632137dd69e66f20e],
PUP.Optional.BundleInstaller.A, C:\Users\Basti\Downloads\Player_Setup(1).exe, In Quarantäne, [f80851af12ee1fe1ac730efbbb491be5],
PUP.Optional.BundleInstaller.A, C:\Users\Basti\Downloads\Player_Setup(2).exe, In Quarantäne, [f50b45bbbd4328d8c05f8d7c8480718f],
PUP.Optional.BundleInstaller.A, C:\Users\Basti\Downloads\Player_Setup.exe, In Quarantäne, [69976b95b14f06fa23fc7594d72d847c],
PUP.Optional.BProtector.A, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\z8ehhuuq.default\bProtector_extensions.sqlite, In Quarantäne, [5da38e72de22b44c1852aacf1ae855ab],
PUP.Optional.BProtector.A, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\z8ehhuuq.default\bprotector_prefs.js, In Quarantäne, [bc443cc4000058a80764caaf43bf8d73],
PUP.Optional.WebSearch.A, C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\z8ehhuuq.default\searchplugins\Web Search.xml, In Quarantäne, [6f9151afae5203fd2b499ae0b949d828],
PUP.Optional.SmartBar.A, C:\Users\Basti\AppData\Local\Temp\smartbar\GuidCreator.dll, In Quarantäne, [699733cdb54bd12f327487ffd42ea55b],
PUP.Optional.SmartBar.A, C:\Users\Basti\AppData\Local\Temp\smartbar\Installer.exe.config, In Quarantäne, [699733cdb54bd12f327487ffd42ea55b],
PUP.Optional.SmartBar.A, C:\Users\Basti\AppData\Local\Temp\smartbar\sqlite3.dll, In Quarantäne, [699733cdb54bd12f327487ffd42ea55b],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, In Quarantäne, [11efbe422bd5ca3613ff327343c0d828],
PUP.Optional.DealPly.A, C:\Users\Basti\AppData\Roaming\DealPly\UpdateProc\config.dat, In Quarantäne, [0af6eb157c84f8080842bea46f93b24e],
PUP.Optional.DealPly.A, C:\Users\Basti\AppData\Roaming\DealPly\UpdateProc\info.dat, In Quarantäne, [0af6eb157c84f8080842bea46f93b24e],
PUP.Optional.DealPly.A, C:\Users\Basti\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe, In Quarantäne, [0af6eb157c84f8080842bea46f93b24e],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\0112907235A9428B90E2593F311DCA9B\3209.ico, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\0112907235A9428B90E2593F311DCA9B\speedupmypcDE.exe, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\08FDF9B0B8044ACCA5CA1FB5A09B4271\Installer.exe, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\5C0D5C73EDCE40DC89445EF9845B5D50\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.OpenCandy, C:\Users\Basti\AppData\Roaming\OpenCandy\7457A55C8A0B4FB3A8B71CDA7A1AA118\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, In Quarantäne, [9b6528d80000a65ac8b9075bd131b34d],
PUP.Optional.FileScout.A, C:\Users\Basti\AppData\Roaming\File Scout\uninst.exe, In Quarantäne, [10f08f71e21e40c0d0c98cd62ad86f91],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\bg.html, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\bg.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\manifest.json, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\options.htm, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\options.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\popup.html, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\popup.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\redirect.html, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\redirect.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\CSS\border.css, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-1.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-2.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-3.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\fb.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\fblike.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\gmail.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\google.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\googleplus.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-1.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-2.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-3.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\left.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-1.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-2.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-3.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\mgsplusvideo.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-1.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-2.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-3.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\pinit.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\right.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\searchBox.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-1.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-2.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-3.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\twitter.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-1.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-2.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-3.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\BackPageRemove.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\defaultBlockList.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\documentEvents.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\externalJS.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\FBImagePreview.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\InternalJS.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\jquery-1.9.0.min.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\PluginWrapper.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\publisherDefinitions.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\tabReload.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\TopFrameJS.js, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\homePage.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\Linkury.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\Linkury128.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\Linkury16.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.SnapDo.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\Linkury48.png, In Quarantäne, [45bb867a08f8fe02d0ff90d522e011ef],
PUP.Optional.HelperBar.A, C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&userid=2306573a-b7aa-f554-6fe8-72f54a2d5af1&searchtype=hp&fr=linkury-tb&installDate=10/01/2014&type=hp1000",), Ersetzt,[40c0cb35718f8779961d4c0fdf25a957]
Physische Sektoren: 0
(No malicious items detected)
(end) 2. Schritt: adwCleaner Code:
# AdwCleaner v3.202 - Bericht erstellt am 25/04/2014 um 17:28:21
# Aktualisiert 23/04/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Basti - SEBASTIAN
# Gestartet von : C:\Users\Basti\Desktop\Trojanerboard\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Websteroids
Ordner Gelöscht : C:\ProgramData\WOWCoupoen
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\Program Files (x86)\sweetpacks bundle uninstaller
Ordner Gelöscht : C:\Program Files (x86)\Uniblue
Ordner Gelöscht : C:\Users\Basti\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\DigitalSites
Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\DSite
Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Uniblue
Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitGuard
Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly
Ordner Gelöscht : C:\Users\Basti\AppData\Local\Software
Ordner Gelöscht : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\z8ehhuuq.default\Extensions\p7i@ctvv-ccrd.org
Ordner Gelöscht : C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifhmhkhhcmceninamcfbengebffgkjfb
Datei Gelöscht : C:\Users\Basti\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
Datei Gelöscht : C:\WINDOWS\System32\Tasks\Dealply
Datei Gelöscht : C:\WINDOWS\System32\Tasks\DealPlyUpdate
Datei Gelöscht : C:\WINDOWS\Tasks\DSite.job
Datei Gelöscht : C:\WINDOWS\System32\Tasks\DSite
Datei Gelöscht : C:\WINDOWS\Tasks\SpeedUpMyPC.job
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Optimizer Pro]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\*\shell\filescout
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKCU\Software\94dedee73eb844
Schlüssel Gelöscht : HKLM\SOFTWARE\94dedee73eb844
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF7BD87A-8024-11E2-F316-F3E56188709B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\filescout
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DynConIE
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\DealPly
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Optimizer Pro_is1
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\271769~1.27\{c16c1~1\loader.dll
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Mozilla Firefox v28.0 (en-US)
[ Datei : C:\Users\Basti\AppData\Roaming\Mozilla\Firefox\Profiles\z8ehhuuq.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.VkmgFrz8eG.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"immediate-support.com\")>-1||url.indexOf(\"txtlnkusaolp0000080[...]
Zeile gelöscht : user_pref("extensions.uAtrcSfe.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"immediate-support.com\")>-1||url.indexOf(\"txtlnkusaolp00000800\[...]
-\\ Google Chrome v31.0.1650.63
[ Datei : C:\Users\Basti\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Extension] : amfclgbdpgndipgoegfpkkgobahigbcl
Gelöscht [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo
Gelöscht [Extension] : eooncjejnppfjjklapaamhcdmjbilmde
Gelöscht [Extension] : hphibigbodkkohoglgfkddblldpfohjl
Gelöscht [Extension] : ifhmhkhhcmceninamcfbengebffgkjfb
Gelöscht [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Gelöscht [Extension] : kincjchfokkeneeofpeefomkikfkiedl
Gelöscht [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc
*************************
AdwCleaner[R0].txt - [7640 octets] - [25/04/2014 17:24:37]
AdwCleaner[S0].txt - [6803 octets] - [25/04/2014 17:28:21]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6863 octets] ########## 3. Schritt: JRT - Junkware Removal Tool Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Basti on 25/04/2014 at 17:42:06.02
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2040692901-543291816-533557636-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
~~~ Files
Successfully deleted: [File] "C:\Users\Basti\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"
Successfully deleted: [File] "C:\Users\Basti\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\speedupmypc.lnk"
Successfully deleted: [File] "C:\Users\Basti\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\user pinned\taskbar\startfenster.lnk"
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Basti\music\qtrax media library"
~~~ FireFox
Successfully deleted the following from C:\Users\Basti\AppData\Roaming\mozilla\firefox\profiles\z8ehhuuq.default\prefs.js
user_pref("extensions.uAtrcSfe.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"immediate-support.com\")>-1||url.indexO
Emptied folder: C:\Users\Basti\AppData\Roaming\mozilla\firefox\profiles\z8ehhuuq.default\minidumps [57 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25/04/2014 at 17:58:36.34
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |