Chrisss007 | 20.10.2014 19:13 | Addition Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-10-2014
Ran by Mein at 2014-10-19 22:52:33
Running from C:\Users\Mein\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
888poker (HKLM-x32\...\888poker) (Version: - )
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.104 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.5 - Google Inc.) Hidden
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games )
League of Legends (x32 Version: 3.0.1 - Riot Games ) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{D285FC5F-3021-32E9-9C59-24CA325BDC5C}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{86CE1746-9EFF-3C9C-8755-81EA8903AC34}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 33.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 33.0 (x86 de)) (Version: 33.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0 - Mozilla)
NVIDIA 3D Vision Controller-Treiber 344.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 344.11 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 344.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.11 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.5 - NVIDIA Corporation)
NVIDIA Grafiktreiber 344.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.11 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.162.1274 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.14.0702 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.12.6514 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 344.11 (Version: 344.11 - NVIDIA Corporation) Hidden
Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden
Ralink RT2870 Wireless LAN Card (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 1.5.31.0 - Ralink)
Resident Evil 4 HD (HKLM-x32\...\{AF0D370A-ACD8-4961-BCD4-9676EEC0F364}_is1) (Version: v1.1.0 - RAF)
TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
15-10-2014 16:52:44 Configured NVIDIA ForceWare Network Access Manager
15-10-2014 16:59:04 Installiert Ralink Wireless LAN
15-10-2014 17:01:31 Installiert USB Video Device
15-10-2014 17:05:02 Installed Platform
15-10-2014 17:15:58 Entfernt USB Video Device
19-10-2014 18:23:15 Gerätetreiber-Paketinstallation: DT Soft Ltd Systemgeräte
19-10-2014 18:46:33 DirectX wurde installiert
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {52EACB50-089B-4B31-8923-2033282FD26E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-14] (Adobe Systems Incorporated)
Task: {6848E3A9-1941-497D-A38D-5B615556BFBE} - System32\Tasks\DriverEasy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: {976C27FB-68AC-44DA-AF23-B68AE16091F4} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-14] (Google Inc.)
Task: {B6CF3D0E-F056-47E9-A745-E22C2936A9E8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-14] (Google Inc.)
Task: {B7425514-92D4-45DB-859F-D8244C65AE8A} - System32\Tasks\Installer_iwebar => C:\Users\Mein\AppData\Local\Installer\Installiwebar_21011\delay.exe [2014-10-19] () <==== ATTENTION
Task: {DF875AF5-FB5F-4E47-84A2-8A4A463370C2} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-10-14] (AVAST Software)
Task: {E2B38826-1E7D-4CBD-88A3-2F720399DD6E} - System32\Tasks\Installer_sense => C:\Users\Mein\AppData\Local\Installer\Installsense_31729\delay.exe [2014-10-19] () <==== ATTENTION
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DriverEasy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2014-10-14 21:41 - 2014-09-13 23:53 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-10-15 19:06 - 2012-11-14 15:22 - 00078456 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\QsApoApi64.dll
2014-10-15 19:06 - 2012-11-14 15:22 - 00386168 ____R () C:\Program Files (x86)\VIA\VIAudioi\VDeck\Dts2ApoApi64.dll
2014-10-19 20:29 - 2014-10-19 20:29 - 01151376 _____ () C:\Users\Mein\AppData\Local\Installer\Installiwebar_21011\delay.exe
2014-10-14 22:08 - 2014-10-14 22:08 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-10-19 20:25 - 2014-10-19 20:25 - 02896384 _____ () C:\Program Files\AVAST Software\Avast\defs\14101901\algo.dll
2014-10-14 22:08 - 2014-10-14 22:08 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-10-14 22:10 - 2014-10-10 04:03 - 01042760 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libglesv2.dll
2014-10-14 22:10 - 2014-10-10 04:03 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libegl.dll
2014-10-14 22:10 - 2014-10-10 04:04 - 08910664 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll
2014-10-14 22:10 - 2014-10-10 04:03 - 01681224 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:56E2E879
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) =============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== MSCONFIG/TASK MANAGER disabled items =========
(Currently there is no automatic fix for this section.)
========================= Accounts: ==========================
Administrator (S-1-5-21-573921585-283970995-535547236-500 - Administrator - Disabled)
Gast (S-1-5-21-573921585-283970995-535547236-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-573921585-283970995-535547236-1002 - Limited - Enabled)
Mein (S-1-5-21-573921585-283970995-535547236-1000 - Administrator - Enabled) => C:\Users\Mein
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (10/19/2014 10:05:17 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: Mein-PC)
Description: Die Anwendung oder der Dienst "linmsl" konnte nicht heruntergefahren werden.
Error: (10/19/2014 10:03:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: jsdrv.exe, Version: 1.37.0.1375, Zeitstempel: 0x5443f0b6
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7601.18409, Zeitstempel: 0x53159a86
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000d1c8
ID des fehlerhaften Prozesses: 0x150c
Startzeit der fehlerhaften Anwendung: 0xjsdrv.exe0
Pfad der fehlerhaften Anwendung: jsdrv.exe1
Pfad des fehlerhaften Moduls: jsdrv.exe2
Berichtskennung: jsdrv.exe3
Error: (10/19/2014 09:23:02 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm UNWISE.EXE, Version 0.0.0.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1898
Startzeit: 01cfebd1b1bd1f4c
Endzeit: 5
Anwendungspfad: C:\PROGRA~2\YOUTUB~1\UNWISE.EXE
Berichts-ID: 5418814e-57c5-11e4-834f-9896649dc303
Error: (10/14/2014 10:41:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary oczbqaxf.
System Error:
Das System kann die angegebene Datei nicht finden.
.
Error: (10/14/2014 10:19:53 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm ts3client_win64.exe, Version 3.0.16.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1290
Startzeit: 01cfe7ec1f8bd613
Endzeit: 11
Anwendungspfad: C:\Users\Mein\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe
Berichts-ID: 730e1b2b-53df-11e4-a0a8-e383b77beeea
Error: (10/14/2014 10:19:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm ts3client_win64.exe, Version 3.0.16.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 10ac
Startzeit: 01cfe7ebcef01cb7
Endzeit: 15
Anwendungspfad: C:\Users\Mein\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe
Berichts-ID: 58b459b8-53df-11e4-a0a8-e383b77beeea
Error: (10/14/2014 10:07:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary oczbqaxf.
System Error:
Das System kann die angegebene Datei nicht finden.
.
Error: (10/14/2014 07:43:51 PM) (Source: MsiInstaller) (EventID: 11935) (User: Mein-PC)
Description: Produkt: MSXML 4.0 SP3 Parser (KB2758694) -- Fehler 1935. Während der Installation der Assemblierungskomponente {74910135-7980-398A-A06B-D6B9ABF34537} ist ein Fehler aufgetreten. HRESULT: 0x80070BC9. Assemblierungsschnittstelle: IAssemblyCacheItem, Funktion: Commit, Assemblierungsname: Microsoft.MSXML2,type="win32",version="4.30.2117.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"
System errors:
=============
Error: (10/19/2014 08:31:53 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Der Dienst "YouTubeAcceleratorService" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren.
Error: (10/19/2014 07:59:21 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (10/19/2014 02:14:14 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (10/18/2014 00:31:44 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (10/18/2014 00:59:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR2 gefunden.
Error: (10/17/2014 09:41:33 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "AN_TOSHIBA",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{80C256BC-DC79-4DE8-9A35-5E9DA2D94D6A}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.
Error: (10/15/2014 03:32:26 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}
Error: (10/15/2014 00:21:50 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT-AUTORITÄT)
Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80242016 fehlgeschlagen: Update für Windows 7 für x64-basierte Systeme (KB2952664)
Error: (10/15/2014 00:14:44 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows Modules Installer" wurde mit folgendem Fehler beendet:
%%16405
Error: (10/15/2014 00:09:44 AM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Der Dienst Windows Modules Installer konnte nach dem Empfang eines Preshutdown-Steuerelements nicht richtig heruntergefahren werden.
Microsoft Office Sessions:
=========================
Error: (10/19/2014 10:05:17 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10006) (User: Mein-PC)
Description: 1C:\Program Files (x86)\LPT\linmsl.exelinmsl0511710320
Error: (10/19/2014 10:03:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: jsdrv.exe1.37.0.13755443f0b6KERNELBASE.dll6.1.7601.1840953159a86c00000050000d1c8150c01cfebd7c09219deC:\Program Files (x86)\ShopperPro\JSDriver\1.37.0.1375\jsdrv.exeC:\Windows\syswow64\KERNELBASE.dll005015e9-57cb-11e4-83a3-0025224eb0ea
Error: (10/19/2014 09:23:02 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: UNWISE.EXE0.0.0.0189801cfebd1b1bd1f4c5C:\PROGRA~2\YOUTUB~1\UNWISE.EXE5418814e-57c5-11e4-834f-9896649dc303
Error: (10/14/2014 10:41:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary oczbqaxf.
System Error:
Das System kann die angegebene Datei nicht finden.
Error: (10/14/2014 10:19:53 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ts3client_win64.exe3.0.16.0129001cfe7ec1f8bd61311C:\Users\Mein\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe730e1b2b-53df-11e4-a0a8-e383b77beeea
Error: (10/14/2014 10:19:11 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ts3client_win64.exe3.0.16.010ac01cfe7ebcef01cb715C:\Users\Mein\AppData\Local\TeamSpeak 3 Client\ts3client_win64.exe58b459b8-53df-11e4-a0a8-e383b77beeea
Error: (10/14/2014 10:07:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary oczbqaxf.
System Error:
Das System kann die angegebene Datei nicht finden.
Error: (10/14/2014 07:43:51 PM) (Source: MsiInstaller) (EventID: 11935) (User: Mein-PC)
Description: Produkt: MSXML 4.0 SP3 Parser (KB2758694) -- Fehler 1935. Während der Installation der Assemblierungskomponente {74910135-7980-398A-A06B-D6B9ABF34537} ist ein Fehler aufgetreten. HRESULT: 0x80070BC9. Assemblierungsschnittstelle: IAssemblyCacheItem, Funktion: Commit, Assemblierungsname: Microsoft.MSXML2,type="win32",version="4.30.2117.0",publicKeyToken="6bd6b9abf345378f",processorArchitecture="x86"(NULL)(NULL)(NULL)(NULL)(NULL)
==================== Memory info ===========================
Processor: AMD Athlon(tm) II X3 440 Processor
Percentage of memory in use: 40%
Total physical RAM: 4095.18 MB
Available physical RAM: 2428.2 MB
Total Pagefile: 8188.54 MB
Available Pagefile: 6124.48 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:149.05 GB) (Free:101.27 GB) NTFS
Drive d: (Volume) (Fixed) (Total:232.54 GB) (Free:229.03 GB) NTFS
Drive e: (Alex's Externe) (Fixed) (Total:931.51 GB) (Free:497.82 GB) NTFS
Drive f: (raf-re4_hd) (CDROM) (Total:5.98 GB) (Free:0 GB) UDF
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: FE77F5F9)
Partition 1: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 41BF41BE)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=232.5 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: F9FC775A)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-10-19 23:06:24
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 Maxtor_6G160P0 rev.KA201V00 149,05GB
Running: Gmer-19357.exe; Driver: C:\Users\Mein\AppData\Local\Temp\kxldypog.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002ff0000 46 bytes [73, 6D, D5, F7, 01, 00, 31, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 692 fffff80002ff00a4 27 bytes [0B, 49, 1D, AE, A4, E1, 9F, ...]
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\wininit.exe[540] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Windows\system32\services.exe[620] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Windows\system32\winlogon.exe[660] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Windows\system32\nvvsvc.exe[868] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe[892] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007582a2fd 1 byte [62]
.text C:\Windows\System32\svchost.exe[304] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Windows\system32\svchost.exe[472] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1248] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Windows\system32\nvvsvc.exe[1256] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Windows\system32\taskhost.exe[1940] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Windows\Explorer.EXE[2236] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Windows\System32\rundll32.exe[2280] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000075808791 8 bytes [31, C0, C2, 04, 00, 90, 90, ...]
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007582a2fd 1 byte [62]
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExW + 17 0000000075501401 2 bytes JMP 7582b21b C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!EnumProcessModules + 17 0000000075501419 2 bytes JMP 7582b346 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 17 0000000075501431 2 bytes JMP 758a8ea9 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 42 000000007550144a 2 bytes CALL 758048ad C:\Windows\syswow64\kernel32.dll
.text ... * 9
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!EnumDeviceDrivers + 17 00000000755014dd 2 bytes JMP 758a87a2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameA + 17 00000000755014f5 2 bytes JMP 758a8978 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSetEx + 17 000000007550150d 2 bytes JMP 758a8698 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetDeviceDriverBaseNameW + 17 0000000075501525 2 bytes JMP 758a8a62 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameW + 17 000000007550153d 2 bytes JMP 7581fca8 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!EnumProcesses + 17 0000000075501555 2 bytes JMP 758268ef C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetProcessMemoryInfo + 17 000000007550156d 2 bytes JMP 758a8f61 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetPerformanceInfo + 17 0000000075501585 2 bytes JMP 758a8ac2 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!QueryWorkingSet + 17 000000007550159d 2 bytes JMP 758a865c C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetModuleBaseNameA + 17 00000000755015b5 2 bytes JMP 7581fd41 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetModuleFileNameExA + 17 00000000755015cd 2 bytes JMP 7582b2dc C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 20 00000000755016b2 2 bytes JMP 758a8e24 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\AVAST Software\Avast\avastui.exe[2532] C:\Windows\syswow64\PSAPI.DLL!GetProcessImageFileNameW + 31 00000000755016bd 2 bytes JMP 758a85f1 C:\Windows\syswow64\kernel32.dll
.text C:\Program Files\Windows Media Player\wmpnetwk.exe[2648] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007772ef8d 1 byte [62]
.text C:\Users\Mein\AppData\Local\Installer\Installiwebar_21011\delay.exe[2472] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007582a2fd 1 byte [62]
.text C:\Users\Mein\Downloads\Gmer-19357.exe[1268] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 000000007582a2fd 1 byte [62]
---- EOF - GMER 2.1 ---- habe schonmal malwarebyte runtergeladen und einen scan durchgeführt.danke schonmal für deine bereitschagt.
LG Chrisss
Hier die log Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 20.10.2014
Scan Time: 19:56:17
Logfile: MALWAReBytes.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.10.20.06
Rootkit Database: v2014.10.17.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Mein
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 299907
Time Elapsed: 12 min, 47 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c-6.exe, 3816, , [84728f87dca078be155aa88f49b8e21e]
Modules: 1
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\395ccca4-5f59-4758-877d-a773eb952655.dll, , [fbfb3cda4339280e671b1061be460df3],
Registry Keys: 51
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611511123}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{11111111-1111-1111-1111-110611511123}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644514423}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655515523}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666516623}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655515523}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666516623}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644514423}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\68671f62832e4803b34065d441f9a2210065123.BHO.1, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611511123}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611511123}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\68671f62832e4803b34065d441f9a2210065123.BHO, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\68671f62832e4803b34065d441f9a2210065123.BHO, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\68671f62832e4803b34065d441f9a2210065123.BHO.1, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{22222222-2222-2222-2222-220622512223}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\68671f62832e4803b34065d441f9a2210065123.Sandbox.1, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\68671f62832e4803b34065d441f9a2210065123.Sandbox, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\68671f62832e4803b34065d441f9a2210065123.Sandbox, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\68671f62832e4803b34065d441f9a2210065123.Sandbox.1, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622512223}, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611511123}\INPROCSERVER32, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, , [37bf69ad0e6ebb7bf7d7d607ca3841bf],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, , [37bf69ad0e6ebb7bf7d7d607ca3841bf],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\iWebar, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, , [ed09ec2a7b0112241d1b86c1c93abb45],
PUP.Optional.iWebar.A, HKLM\SOFTWARE\WOW6432NODE\iWebar, , [8a6ccb4b304cca6c176df57cb054db25],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, , [bf37090d81fb6ccaa68cd15bc142b947],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21836, , [589e38de106ce452c47422257291af51],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, , [b145ae68205c85b102c9ee9ee024847c],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, , [8a6c3adc5e1e2412cdff8903c63e27d9],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [6195e72f463678be55ac6c12e51fa759],
PUP.Optional.iWebar.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\iWebar, , [c333cf474537de58d6099eb026dd30d0],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21836, , [9e58ea2c33497eb85e92958ac340ea16],
PUP.Optional.iWebar.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\iWebar, , [52a46aacd3a9d95df05d4f0110f306fa],
PUP.Optional.Linkury.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, , [3db96bab7408c0760f9439ec5fa4eb15],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.Update3WebControl.4, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, , [42b48f87ccb044f23c66ad5a01020ef2],
Registry Values: 4
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, , [ae48ba5cd8a446f0067e8c9631d2d22e]
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, , [bf37090d81fb6ccaa68cd15bc142b947]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, , [e51180962557d165949fc46837cc5ba5]
PUP.Optional.Linkury.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, YahooSM, , [3db96bab7408c0760f9439ec5fa4eb15]
Registry Data: 7
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmCcKg8AficzW2DXkTfig,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmCcKg8AficzW2DXkTfig,,&q={searchTerms}),,[4bab93833c403df984bc809c2dd80cf4]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}),,[17dfbd59e795ca6caf9433e964a1d12f]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1EcruhpFiO6QZdQeF1kLsfxivJE2gcVtZlrVeF0Nyx1zngi__hOpCYxkGEYDfYbr0dV_BDwsn3VieIEwx9RT-Ywke7FgHSef-sag,,, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1EcruhpFiO6QZdQeF1kLsfxivJE2gcVtZlrVeF0Nyx1zngi__hOpCYxkGEYDfYbr0dV_BDwsn3VieIEwx9RT-Ywke7FgHSef-sag,,),,[a94d9086d5a7b28451f32bf1a95cf20e]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}),,[e3139f778eee9c9ade64948855b0d12f]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}),,[f0067d99205c9e9873d2a87481847090]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}),,[20d69f77d7a5c0762b1be03c10f5a15f]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-573921585-283970995-535547236-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q={searchTerms}),,[07ef9185f884c86ea39ed547d3328b75]
Folders: 21
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{3465D6A0-F7C2-4E23-8911-BAC988626743}, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\defaults, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\defaults\preferences, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\userCode, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\locale, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\locale\en-US, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin, , [7680eb2b75070c2a6ea6bd5aab58ed13],
Files: 192
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c-6.exe, , [84728f87dca078be155aa88f49b8e21e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bho64.dll, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bho.dll, , [5b9b160003791d193b3458dfb948ef11],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c-11.exe, , [1adcd93d2557b77f006f4dea2cd54bb5],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c-2.exe, , [2ec89e785d1f9a9cea85f047fc057c84],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c-4.exe, , [b73f36e00a7265d11659b681b74a12ee],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c-5.exe, , [1dd9e33392ea1a1caec142f547ba7d83],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c-64.exe, , [50a661b585f7aa8c016eee49c140f40c],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c-7.exe, , [e4129383b5c7c0766c036ec9eb16728e],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-bg.exe, , [4ea8ad693a423ef8a1cee45355ac03fd],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil.exe, , [21d5ce48fd7fb2846c031f18dd246e92],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil64.exe, , [2dc9cd49f389a591c4ab3ef907fa0000],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-codedownloader.exe, , [d81ed541ed8f0d2989e6d562d928936d],
PUP.Optional.CrossRider.A, C:\Program Files (x86)\iWebar\utils.exe, , [ce28898d23593402d23af366f709b749],
PUP.Optional.Somoto, C:\Users\Mein\AppData\Local\Temp\bitool.dll, , [bf3769adfb81e74f80cf145b54aebb45],
PUP.Optional.Somoto, C:\Users\Mein\AppData\Local\Temp\nsmBE9A.tmp, , [817519fdde9ea78f763d941bf908c23e],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_1485\trz3029.tmp, , [5f977c9a6e0eb581064ed3fcbf42936d],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_15100\trzCAB0.tmp, , [32c448ce63193cfa0b498f40fa0717e9],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_15661\trzE954.tmp, , [787ea670ccb08caab99b448ba25f966a],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_16071\trzF3D8.tmp, , [24d2bc5a255758de97bdce011fe2c13f],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_18973\trz2605.tmp, , [c432c45257252313e17326a9768b38c8],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_19351\trz86E.tmp, , [fef8f620e9935fd72c28c8078978e917],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_20755\iwebar.exe, , [8b6b03133e3e3bfb3e16527d39c8d729],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_2270\trz4E.tmp, , [33c32aecbcc0a1950a4a547bee135aa6],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_23873\trz2048.tmp, , [2fc732e4512b84b25301606f7e83a15f],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_31067\trzB30C.tmp, , [05f162b445370a2cda7a38974ab7718f],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_7084\trzDEAB.tmp, , [46b0d93d0f6d1224eb69fcd3b24f0df3],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_7341\trzEC0E.tmp, , [f4021df9cbb15ed83a1a6f60e21f1ae6],
PUP.Optional.CrossRider, C:\Users\Mein\AppData\Local\Temp\Install_7799\trz595C.tmp, , [f4028a8c3d3f989eaea65877ab5611ef],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-1, , [00f6e72fe39968ceb07d44e8bd4603fd],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-11, , [c234fa1c96e6fe38fa3309236c9750b0],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-2, , [81750115621a89ad42ebf438aa59629e],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-4, , [f204d5412f4d40f62904c3692bd87f81],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-5, , [20d61cfa5d1f96a0c26b36f6d033669a],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-5_user, , [0fe7a3731b61fd3977b687a59370867a],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-6, , [b244df370775e65064c92c00d62d4eb2],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-7, , [eb0b1cfa4e2e59ddc16cb17bfe05dc24],
PUP.Optional.WebSearch.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\searchplugins\Web Search.xml, , [40b639dd710bd46251629eab838019e7],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\background.html, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c.xpi, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\1293297481.mxaddon, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\395ccca4-5f59-4758-877d-a773eb952655.dll, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\406137b1-659d-4dd9-a778-b66698d6cfd0.crx, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\5be75e71-a6a5-44d9-b864-257cb52fe59c.crx, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\61ea3dd9-03b5-405d-a593-d34c8be40766.dll, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\bgNova.html, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil.dll, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar-buttonutil64.dll, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\iWebar.ico, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.iWebar.A, C:\Program Files (x86)\iWebar\Uninstall.exe, , [fbfb3cda4339280e671b1061be460df3],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-1.job, , [a74fb1650478b87ec59c6a2032d242be],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-11.job, , [718533e31a62d85e5f0214760ef6e61a],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-2.job, , [bc3a8a8c57251a1c2e33a6e4fe06b14f],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-4.job, , [36c0b75fb9c3191d10518703ff0508f8],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-5.job, , [ee088591f28a60d68ed3fc8e3ec6c937],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-5_user.job, , [e115bd590c70b87eb5ac8406b1535fa1],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-6.job, , [eb0bc3530e6ebb7b08594c3e8c78a858],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\5be75e71-a6a5-44d9-b864-257cb52fe59c-7.job, , [03f323f32854cb6b95cc6b1f8b79d62a],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, , [787ee630a8d475c191e6d9b1b84c35cb],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, , [73837e982f4d152133451b6ffd07ad53],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, , [975fec2a5d1f340287f2d8b2b54fb14f],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, , [b44274a27705aa8c5e1cd7b3e51f59a7],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, , [42b48f87ccb044f23c66ad5a01020ef2],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\GoogleCrashHandler.exe, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\GoogleUpdate.exe, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\GoogleUpdateBroker.exe, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\GoogleUpdateHelper.msi, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\GoogleUpdateOnDemand.exe, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\goopdate.dll, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\goopdateres_en.dll, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\npGoogleUpdate4.dll, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\psmachine.dll, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.GlobalUpdate.A, C:\Users\Mein\AppData\Local\Temp\comh.155406\psuser.dll, , [bc3aed29bbc17abc883609fe857e847c],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome.manifest, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\install.rdf, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\0ed3d2cca43fa6c8ea08589489c29c42.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\38e41db2627f76740979163a06804712.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\7d74de6a82d32c613fc327152c8e22eb.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\9849bac407069329c85c8636aa0594b2.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\background.html, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\browser.xul, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\c59f308e18195c24f77c1be77bfd3782.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\dialog.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\eae0dceaa81ee1bf7d9e89edc9708deb.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\ffCoreFilesIndex.txt, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\options.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\options.xul, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\search_dialog.xul, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\0f6bec7696efafa9059971298d2ab6f2.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\2e5fb02556492f87d8430b930bd18865.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\3065d804d22eca35af691bee64019b44.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\3e022c55126ebe5ccbfe58f4aa4d7741.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\45a02a96ad409870808783b54761530b.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\5cb06b5285509331128d3d6bbab1faee.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\730b2dffbd78879256bf7626bd00da28.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\af00a98a2946705a221cf316ea089b6d.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\b2a9b138e6ea4d0d7605638d4b4370d8.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\d046a0ba3ef28c47974e6bf95d864c13.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\d7c5789803abae7742183d6c1ddac10d.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\d93c567549a5eb648c2a539b5b48e775.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\d9c81c2f2bcd574c8e8a60743bb92d44.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\e4c7cf0325860ad34975cd7fe433e1b2.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\e887ed1d759b7056f05f743a69b4f9ab.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\api\ea77c1cf7c90f1f5b643f8d350d3515a.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\1c2677d113702e3aef62e29fd727d38c.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\1d69bc2d1273866ab66c8a0c2c709fc7.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\267086b5afc5e77492f641f65bbf720c.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\29ca78965b7e37a83af3dfcfa36bfa78.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\322254e4368596453ee5272ffbd0c1fd.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\33ea63abb6d243259ac73f4f4df88098.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\57276ca8a2be1b1ca8c2514d2a635352.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\6774db2158a33c56bb63758b46a4598f.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\6815181c94a5a7b023ba14121e84cb71.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\7ebaac0bff1214c2cca54e52c7310b18.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\a4a1902a3a21c26ff19909a3d9b3e19d.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\b19db36f3c060cc146fd423f2c236248.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\b3f52b70fe09957f1e9a4c6c43671477.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\c0ef00c3549e40593c0171f2eabb784c.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\d088ba8e1800f36f532aafee3e357cc0.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\d769ca4ac23221f77391080ab1467335.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\e1713e22b713521e3c6df39f039a0c9f.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\e89283e63f1d93ed91b60afcf04465d7.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\efb8b2e2f1b7c50e2aa24cbf92a02a5d.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\fc5639d737d25e40ceed3c7d62be596a.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\chrome\content\core\installer.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\defaults\preferences\prefs.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\manifest.xml, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins.json, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\1.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\102.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\104.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\13.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\14.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\16.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\17.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\177.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\180.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\182.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\183.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\184.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\195.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\200.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\207.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\21.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\22.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\220.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\223.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\242.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\246.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\268.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\275.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\28.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\286.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\301.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\4.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\47.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\64.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\7.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\72.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\78.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\9.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\91.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\93.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\plugins\98.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\userCode\background.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\extensionData\userCode\extension.js, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\locale\en-US\translations.dtd, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\button1.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\button2.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\button3.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\button4.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\button5.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\crossrider_statusbar.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\icon128.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\icon16.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\icon24.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\icon48.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\panelarrow-up.png, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\popup.html, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\skin.css, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.CrossRider.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\extensions\ROUAILDE73397174@UXGZI17268980.com\skin\update.css, , [7680eb2b75070c2a6ea6bd5aab58ed13],
PUP.Optional.HelperBar.A, C:\Users\Mein\AppData\Roaming\Mozilla\Firefox\Profiles\juovxf1k.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StLKYZZHUxozG7WbG8M4ZbpPFmdMdnxsM5TEzN82KkLNcu2v2bOF6pL29mxXvYfYRXhQpOHpCmNFN5pWW8TLO-nyvmpKDR-xGA90U7yy1I0rtm1UV0KOOSrnazbfHgQqr7Ogbh3OhbRk4szSKY7jxIPzdTNPZZDkeZRiXrt1Sr5pGC4iqW6yRn4wmFFQgdfYhiJAPHMdzo4g,,&q=");), ,[f7ffd541d8a440f6305e4b0f26df639d]
Physical Sectors: 0
(No malicious items detected)
(end) |