![]() |
Auswertung OTL Ergebnis Folgende Symptome hat mein Rechner: Immer laut am Arbeiten, obwohl nur ein Leerlaufprozess im Task Manager angezeigt wird (allerdings bei 30% bei einem 2,6 GH Quadcore). Ich bitte um eine Auswertung meines OTL-Files. Vielen Dank!OTL Logfile: OTL Logfile: Code: OTL logfile created on: 17.11.2014 11:32:09 - Run 1 --- --- --- |
hi, OTL ist outdated. Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-11-2014 --- --- --- --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-11-2014 Danke Herr Schrauber !!! |
Naja, Comodo Rundum Rechner-Lahmleg-Paket, inklusive aktiver Reste von Panda und Sau-Alarm (ZoneAlarm), da schwitzt jeder Rechner ;) Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Danke :-) zunächst mal das Adware Programm:AdwCleaner Logfile: Code: # AdwCleaner v4.102 - Bericht erstellt am 25/11/2014 um 17:14:02 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.3.9 (11.15.2014:2) OS: Windows 7 Professional x64 Ran by Olav Kittel on 25.11.2014 at 17:19:10,33 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\privdogservice ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\adtrustmedia" Successfully deleted: [Folder] "C:\ProgramData\pcdr" Successfully deleted: [Folder] "C:\Users\Olav Kittel\AppData\Roaming\pcdr" Successfully deleted: [Folder] "C:\Program Files (x86)\adtrustmedia" Successfully deleted: [Empty Folder] C:\Users\Olav Kittel\appdata\local\{59777A80-1A7D-489C-98F7-543B45C29ADB} Successfully deleted: [Empty Folder] C:\Users\Olav Kittel\appdata\local\{AD83B17D-2D18-45FC-9952-0C70D628556B} ~~~ FireFox Successfully deleted: [File] C:\user.js Successfully deleted the following from C:\Users\Olav Kittel\AppData\Roaming\mozilla\firefox\profiles\u9tra0dx.default-1362061992689\prefs.js user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=69&CUI=&SSPV=&Lay=1&UM user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=55&CUI=&UM=6&UP= user_pref("extensions.trusted-ads.ExLst", "{\"u\":{\"v\":\"1.70\",\"d\":\"032414\"},\"h\":{\"pogo.com\":{\"p\":[{\"e\":\"/.*/\",\"r\":[\"/connect\\\\.facebook\\\\.net\\\\/en_U user_pref("extensions.trusted-ads.TrustAd", "{\"r\":[{\"t\":\"FQDN\",\"r\":\"trustedads.adtrustmedia.com\",\"c\":[{\"i\":\"1\",\"s\":[\"display.clickpoint.com\",\"www.africawi user_pref("extensions.trusted-ads.list_api", "{\"r\":[\"hxxp://24x7homesecurity.com/\",\"hxxp://a1supplements.com/\",\"hxxp://aactionair.net/\",\"hxxp://abcnews.go.com/\",\"ht user_pref("extensions.trusted-ads.serpInject", "{\"u\":{\"v\":\"2.72\",\"d\":\"061714\"},\"l\":\"hxxp://search.adtrustmedia.com/search_safecontent.php\",\"e\":[{\"u\":\"hxxp:/ user_pref("extensions.trusted-ads.serp_mywebsearch", "\"%2F*!%20serp-mywebsearch%20-%20v0.1.10%20-%202014-04-07%2018%3A21%3A58%20*%2F%0D%0Avar%20u%20%3D%20%7B%7D%3B%0A%0Avar%2 Emptied folder: C:\Users\Olav Kittel\AppData\Roaming\mozilla\firefox\profiles\u9tra0dx.default-1362061992689\minidumps [296 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 25.11.2014 at 17:22:16,01 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 25.11.2014 Suchlauf-Zeit: 16:53:06 Logdatei: mbam.txt Administrator: Ja Version: 2.00.3.1025 Malware Datenbank: v2014.11.25.06 Rootkit Datenbank: v2014.11.22.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Olav Kittel Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 348108 Verstrichene Zeit: 18 Min, 57 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, 2648, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709] Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 17 PUP.Optional.Babylon.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [a555a09fc5b741f53e85a41b47bb49b7], PUP.Optional.SearchProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SearchProtect, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\IB Updater, In Quarantäne, [15e5cc73ea92072f868d99d09b68f709], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [45b50e31b6c667cf25edabbef310926e], PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, In Quarantäne, [b7436dd23f3d072f267e6d4854b0f50b], PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [8872b986e09c81b5f1b2288d3dc7b050], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\IB Updater, In Quarantäne, [0bef5ce3423af0464dc64d1cb94a05fb], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [b149d7686e0e67cf8cafd1ab6d966c94], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [bc3e1b24c7b5c076e42e2643cd36af51], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\jbpkiefagocgkmemidfngdkamloieekf, In Quarantäne, [8e6c93ac6913a6904bd7d5823ac9c937], PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, In Quarantäne, [b64487b85a2289ad8da23e1aee15768a], PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, In Quarantäne, [31c9a996a7d5a88e73f3e8aad92b8f71], PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD, In Quarantäne, [8f6b162919632313d1b6d879b1524db3], PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, In Quarantäne, [2bcfd669e29ad1659637bfd39470c63a], PUP.Optional.Babylon.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, In Quarantäne, [2dcde55afd7f9f976cf1642e976d0cf4], PUP.Optional.SweetIM.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, In Quarantäne, [79815ce3e19b3cfa1d48b5dd55afa060], Registrierungswerte: 8 PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [4ab0c778344871c5f175ad1235cd3ec2], PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\IB Updater\Firefox, In Quarantäne, [4ab0c778344871c5f175ad1235cd3ec2] PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\IB Updater\Firefox, In Quarantäne, [4ab0c778344871c5f175ad1235cd3ec2] PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [49b1d26ddf9d96a04a1c516ea35ff20e], PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, In Quarantäne, [b64487b85a2289ad8da23e1aee15768a] PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, 11111111, In Quarantäne, [31c9a996a7d5a88e73f3e8aad92b8f71] PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD|ImagePath, \??\C:\Windows\system32\drivers\SPPD.sys, In Quarantäne, [8f6b162919632313d1b6d879b1524db3] PUP.Optional.SweetIM.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, 11111111, In Quarantäne, [79815ce3e19b3cfa1d48b5dd55afa060] Registrierungsdaten: 3 PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll),Ersetzt,[c238e25d86f603334f17975507fa9e62] PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll),Ersetzt,[4ab0350a1f5d7eb847377328a55ff709] PUP.Optional.Trovi.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=55&CUI=&UM=6&UP=SP1EB8EB35-729A-42D7-A673-6043DE058F44&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=55&CUI=&UM=6&UP=SP1EB8EB35-729A-42D7-A673-6043DE058F44&SSPV=),Ersetzt,[6c8e0f30ec90b1854965c6847491ee12] Ordner: 30 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.OpenCandy, C:\Users\Olav Kittel\AppData\Roaming\OpenCandy, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\Olav Kittel\AppData\Roaming\OpenCandy\277E0050A9444F889345A9CCDE6C794B, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\Olav Kittel\AppData\Roaming\OpenCandy\2B5A75CC4F7D46A8A8C3E42888EAF3B5, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\Olav Kittel\AppData\Roaming\OpenCandy\43B399D44DA441DF86B8F7494CB6A4FB, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\Olav Kittel\AppData\Roaming\OpenCandy\7FF7AB5C577E4837BE8084BDD5FC7626, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.SearchProtect.A, C:\Users\Olav Kittel\AppData\Local\SearchProtect, Löschen bei Neustart, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\Olav Kittel\AppData\Local\SearchProtect\SearchProtect, Löschen bei Neustart, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\Olav Kittel\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\Olav Kittel\AppData\Local\SearchProtect\SearchProtect\STG, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\Olav Kittel\AppData\Local\SearchProtect\UI, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\Olav Kittel\AppData\Local\SearchProtect\UI\rep, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.TornTV.A, C:\Users\Olav Kittel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com, In Quarantäne, [f9013c03b6c670c629594fe628db4fb1], Dateien: 107 PUP.Optional.SearchProtect, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll, In Quarantäne, [c238e25d86f603334f17975507fa9e62], PUP.Optional.PCFixSpeed.A, C:\Users\Olav Kittel\AppData\Roaming\OpenCandy\43B399D44DA441DF86B8F7494CB6A4FB\SearchGolTB.exe, In Quarantäne, [04f6a09f2f4dc2741e2dd8e9f1136b95], PUP.Optional.OpenCandy, C:\$Recycle.Bin\S-1-5-21-1530557571-3670826322-1770252739-1000\$RXMINJB.exe, In Quarantäne, [bb3f99a683f9c175ec5bcf2a728f4eb2], Adware.Linkular, C:\Users\Olav Kittel\AppData\Local\Temp\EVO4YxvT.exe.part, In Quarantäne, [0eece35c7804261037dd6c11b451629e], Trojan.Fakealert.ED, C:\Users\Olav Kittel\AppData\Local\Temp\JpST98MR.zip.part, In Quarantäne, [5e9cb28dd1ab6dc9938814ef8a7bdc24], PUP.Optional.Yontoo.A, C:\Users\Olav Kittel\AppData\Local\Temp\YontooSetup-S.exe, In Quarantäne, [5b9ffe417c00ef471e9c0cd40cf537c9], Adware.DomaIQ, C:\Users\Olav Kittel\AppData\Local\Temp\6apY4288.exe.part, In Quarantäne, [17e379c69ddfca6cd44279ff778e847c], Adware.DomaIQ, C:\Users\Olav Kittel\AppData\Local\Temp\eJqIR5Ae.exe.part, In Quarantäne, [fbff7fc085f747efc155b1c7c4412dd3], PUP.Optional.Babylon.A, C:\Users\Olav Kittel\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\BExternal.dll, In Quarantäne, [e01aa897ed8ffa3c7ab88a99ad53b44c], PUP.Optional.Conduit.A, C:\Users\Olav Kittel\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\ccp.exe, In Quarantäne, [6b8f66d944384aecd120d46719e8c13f], PUP.Optional.Babylon.A, C:\Users\Olav Kittel\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\CrxInstaller.dll, In Quarantäne, [1cdebd82522a0f276ab05fd5f60b4db3], PUP.Optional.Babylon.A, C:\Users\Olav Kittel\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\MntrDLLInstall.dll, In Quarantäne, [28d2b28d4a32be78a97254e0e31e3ac6], PUP.Optional.SearchGolTB.A, C:\Users\Olav Kittel\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\MySgolTB.exe, In Quarantäne, [1cde97a8403c52e4de15c279de2322de], PUP.Optional.Babylon.A, C:\Users\Olav Kittel\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\Setup.exe, In Quarantäne, [ea1095aaea92a690b42479a88b75cf31], PUP.Optional.SmileysWeLove.A, C:\Users\Olav Kittel\AppData\Local\Temp\bhfiles\IEOpenServiceHelper.exe, In Quarantäne, [a258d46b2b510f27187f92126899718f], PUP.Adware.RKN, C:\Users\Olav Kittel\Downloads\MediaProSoftFreeYouTubetoFLVConverter292.exe, In Quarantäne, [0af05be482facb6b26f4f5ac6c94a65a], PUP.Optional.SearchProtect, C:\Windows\AppPatch\AppPatch64\VCLdr64.dll, In Quarantäne, [2ccec8775725c6701c4a05e760a17f81], PUP.Optional.Trovi.A, C:\Users\Olav Kittel\AppData\Roaming\Mozilla\Firefox\Profiles\u9tra0dx.default-1362061992689\searchplugins\trovi-search.xml, In Quarantäne, [05f50c33a8d46dc9d0b5441fd330d42c], PUP.Optional.SearchGol.A, C:\Users\Olav Kittel\AppData\Roaming\Mozilla\Firefox\Profiles\u9tra0dx.default-1362061992689\searchplugins\searchgol.xml, In Quarantäne, [9169cc739fdde3531c390170b0538a76], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPtool.dll, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPtool64.exe, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32.dll, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64.dll, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def-grey.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-dia.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Icon.ico, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\SP_DialogBG.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\DialogAPI.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [f9017bc407753cfa396edfd63aca649c], PUP.Optional.OpenCandy, C:\Users\Olav Kittel\AppData\Roaming\OpenCandy\2B5A75CC4F7D46A8A8C3E42888EAF3B5\qms.exe, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\Olav Kittel\AppData\Roaming\OpenCandy\7FF7AB5C577E4837BE8084BDD5FC7626\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.SearchProtect.A, C:\Users\Olav Kittel\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\Olav Kittel\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\Olav Kittel\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.TornTV.A, C:\Users\Olav Kittel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com\TornTV.lnk, In Quarantäne, [f9013c03b6c670c629594fe628db4fb1], PUP.Optional.TornTV.A, C:\Users\Olav Kittel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com\Uninstall.lnk, In Quarantäne, [f9013c03b6c670c629594fe628db4fb1], PUP.Optional.Trovi.A, C:\Users\Olav Kittel\AppData\Roaming\Mozilla\Firefox\Profiles\u9tra0dx.default-1362061992689\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=55&CUI=&UM=6&UP=SP1EB8EB35-729A-42D7-A673-6043DE058F44&SSPV=");), Ersetzt,[30cae8572854e254f460325a15f0bd43] PUP.Optional.Trovi.A, C:\Users\Olav Kittel\AppData\Roaming\Mozilla\Firefox\Profiles\u9tra0dx.default-1362061992689\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=69&CUI=&SSPV=&Lay=1&UM=6&UP=SP1EB8EB35-729A-42D7-A673-6043DE058F44");), Ersetzt,[ba4086b945373cfaff56028a7d889070] Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 25.11.2014 Suchlauf-Zeit: 16:53:06 Logdatei: mbam.txt Administrator: Ja Version: 2.00.3.1025 Malware Datenbank: v2014.11.25.06 Rootkit Datenbank: v2014.11.22.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: XXX Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 348108 Verstrichene Zeit: 18 Min, 57 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, 2648, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709] Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 17 PUP.Optional.Babylon.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [a555a09fc5b741f53e85a41b47bb49b7], PUP.Optional.SearchProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SearchProtect, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\IB Updater, In Quarantäne, [15e5cc73ea92072f868d99d09b68f709], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [45b50e31b6c667cf25edabbef310926e], PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, In Quarantäne, [b7436dd23f3d072f267e6d4854b0f50b], PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [8872b986e09c81b5f1b2288d3dc7b050], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\IB Updater, In Quarantäne, [0bef5ce3423af0464dc64d1cb94a05fb], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [b149d7686e0e67cf8cafd1ab6d966c94], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [bc3e1b24c7b5c076e42e2643cd36af51], PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\jbpkiefagocgkmemidfngdkamloieekf, In Quarantäne, [8e6c93ac6913a6904bd7d5823ac9c937], PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, In Quarantäne, [b64487b85a2289ad8da23e1aee15768a], PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, In Quarantäne, [31c9a996a7d5a88e73f3e8aad92b8f71], PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD, In Quarantäne, [8f6b162919632313d1b6d879b1524db3], PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, In Quarantäne, [2bcfd669e29ad1659637bfd39470c63a], PUP.Optional.Babylon.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, In Quarantäne, [2dcde55afd7f9f976cf1642e976d0cf4], PUP.Optional.SweetIM.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, In Quarantäne, [79815ce3e19b3cfa1d48b5dd55afa060], Registrierungswerte: 8 PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [4ab0c778344871c5f175ad1235cd3ec2], PUP.Optional.StartPage.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\IB Updater\Firefox, In Quarantäne, [4ab0c778344871c5f175ad1235cd3ec2] PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\IB Updater\Firefox, In Quarantäne, [4ab0c778344871c5f175ad1235cd3ec2] PUP.Optional.StartPage.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [49b1d26ddf9d96a04a1c516ea35ff20e], PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, In Quarantäne, [b64487b85a2289ad8da23e1aee15768a] PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, 11111111, In Quarantäne, [31c9a996a7d5a88e73f3e8aad92b8f71] PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD|ImagePath, \??\C:\Windows\system32\drivers\SPPD.sys, In Quarantäne, [8f6b162919632313d1b6d879b1524db3] PUP.Optional.SweetIM.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, 11111111, In Quarantäne, [79815ce3e19b3cfa1d48b5dd55afa060] Registrierungsdaten: 3 PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll),Ersetzt,[c238e25d86f603334f17975507fa9e62] PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll),Ersetzt,[4ab0350a1f5d7eb847377328a55ff709] PUP.Optional.Trovi.A, HKU\S-1-5-21-1530557571-3670826322-1770252739-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=55&CUI=&UM=6&UP=SP1EB8EB35-729A-42D7-A673-6043DE058F44&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=55&CUI=&UM=6&UP=SP1EB8EB35-729A-42D7-A673-6043DE058F44&SSPV=),Ersetzt,[6c8e0f30ec90b1854965c6847491ee12] Ordner: 30 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.OpenCandy, C:\Users\XXX\AppData\Roaming\OpenCandy, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\XXX\AppData\Roaming\OpenCandy\277E0050A9444F889345A9CCDE6C794B, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\XXX\AppData\Roaming\OpenCandy\2B5A75CC4F7D46A8A8C3E42888EAF3B5, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\XXX\AppData\Roaming\OpenCandy\43B399D44DA441DF86B8F7494CB6A4FB, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\XXX\AppData\Roaming\OpenCandy\7FF7AB5C577E4837BE8084BDD5FC7626, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.SearchProtect.A, C:\Users\XXX\AppData\Local\SearchProtect, Löschen bei Neustart, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\XXX\AppData\Local\SearchProtect\SearchProtect, Löschen bei Neustart, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\XXX\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\XXX\AppData\Local\SearchProtect\SearchProtect\STG, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\XXX\AppData\Local\SearchProtect\UI, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\XXX\AppData\Local\SearchProtect\UI\rep, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.TornTV.A, C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com, In Quarantäne, [f9013c03b6c670c629594fe628db4fb1], Dateien: 107 PUP.Optional.SearchProtect, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll, In Quarantäne, [c238e25d86f603334f17975507fa9e62], PUP.Optional.PCFixSpeed.A, C:\Users\XXX\AppData\Roaming\OpenCandy\43B399D44DA441DF86B8F7494CB6A4FB\SearchGolTB.exe, In Quarantäne, [04f6a09f2f4dc2741e2dd8e9f1136b95], PUP.Optional.OpenCandy, C:\$Recycle.Bin\S-1-5-21-1530557571-3670826322-1770252739-1000\$RXMINJB.exe, In Quarantäne, [bb3f99a683f9c175ec5bcf2a728f4eb2], Adware.Linkular, C:\Users\XXX\AppData\Local\Temp\EVO4YxvT.exe.part, In Quarantäne, [0eece35c7804261037dd6c11b451629e], Trojan.Fakealert.ED, C:\Users\XXX\AppData\Local\Temp\JpST98MR.zip.part, In Quarantäne, [5e9cb28dd1ab6dc9938814ef8a7bdc24], PUP.Optional.Yontoo.A, C:\Users\XXX\AppData\Local\Temp\YontooSetup-S.exe, In Quarantäne, [5b9ffe417c00ef471e9c0cd40cf537c9], Adware.DomaIQ, C:\Users\XXX\AppData\Local\Temp\6apY4288.exe.part, In Quarantäne, [17e379c69ddfca6cd44279ff778e847c], Adware.DomaIQ, C:\Users\XXX\AppData\Local\Temp\eJqIR5Ae.exe.part, In Quarantäne, [fbff7fc085f747efc155b1c7c4412dd3], PUP.Optional.Babylon.A, C:\Users\XXX\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\BExternal.dll, In Quarantäne, [e01aa897ed8ffa3c7ab88a99ad53b44c], PUP.Optional.Conduit.A, C:\Users\XXX\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\ccp.exe, In Quarantäne, [6b8f66d944384aecd120d46719e8c13f], PUP.Optional.Babylon.A, C:\Users\XXX\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\CrxInstaller.dll, In Quarantäne, [1cdebd82522a0f276ab05fd5f60b4db3], PUP.Optional.Babylon.A, C:\Users\XXX\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\MntrDLLInstall.dll, In Quarantäne, [28d2b28d4a32be78a97254e0e31e3ac6], PUP.Optional.SearchGolTB.A, C:\Users\XXX\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\MySgolTB.exe, In Quarantäne, [1cde97a8403c52e4de15c279de2322de], PUP.Optional.Babylon.A, C:\Users\XXX\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\Setup.exe, In Quarantäne, [ea1095aaea92a690b42479a88b75cf31], PUP.Optional.SmileysWeLove.A, C:\Users\XXX\AppData\Local\Temp\bhfiles\IEOpenServiceHelper.exe, In Quarantäne, [a258d46b2b510f27187f92126899718f], PUP.Adware.RKN, C:\Users\XXX\Downloads\MediaProSoftFreeYouTubetoFLVConverter292.exe, In Quarantäne, [0af05be482facb6b26f4f5ac6c94a65a], PUP.Optional.SearchProtect, C:\Windows\AppPatch\AppPatch64\VCLdr64.dll, In Quarantäne, [2ccec8775725c6701c4a05e760a17f81], PUP.Optional.Trovi.A, C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\u9tra0dx.default-1362061992689\searchplugins\trovi-search.xml, In Quarantäne, [05f50c33a8d46dc9d0b5441fd330d42c], PUP.Optional.SearchGol.A, C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\u9tra0dx.default-1362061992689\searchplugins\searchgol.xml, In Quarantäne, [9169cc739fdde3531c390170b0538a76], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPtool.dll, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPtool64.exe, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32.dll, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64.dll, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, Löschen bei Neustart, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def-grey.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-dia.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Icon.ico, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\SP_DialogBG.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\DialogAPI.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js, In Quarantäne, [4ab0350a1f5d7eb847377328a55ff709], PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [f9017bc407753cfa396edfd63aca649c], PUP.Optional.OpenCandy, C:\Users\XXX\AppData\Roaming\OpenCandy\2B5A75CC4F7D46A8A8C3E42888EAF3B5\qms.exe, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.OpenCandy, C:\Users\XXX\AppData\Roaming\OpenCandy\7FF7AB5C577E4837BE8084BDD5FC7626\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, In Quarantäne, [18e2112eef8d290d31baba522ed5ef11], PUP.Optional.SearchProtect.A, C:\Users\XXX\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\XXX\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.SearchProtect.A, C:\Users\XXX\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, In Quarantäne, [98620c33295352e43a2f0e1420e3f10f], PUP.Optional.TornTV.A, C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com\TornTV.lnk, In Quarantäne, [f9013c03b6c670c629594fe628db4fb1], PUP.Optional.TornTV.A, C:\Users\XXX\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TornTV.com\Uninstall.lnk, In Quarantäne, [f9013c03b6c670c629594fe628db4fb1], PUP.Optional.Trovi.A, C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\u9tra0dx.default-1362061992689\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=55&CUI=&UM=6&UP=SP1EB8EB35-729A-42D7-A673-6043DE058F44&SSPV=");), Ersetzt,[30cae8572854e254f460325a15f0bd43] PUP.Optional.Trovi.A, C:\Users\XXX\AppData\Roaming\Mozilla\Firefox\Profiles\u9tra0dx.default-1362061992689\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3331398&octid=EB_ORIGINAL_CTID&ISID=M33C4B6D1-E6DE-4D6C-A476-95209E9884F7&SearchSource=69&CUI=&SSPV=&Lay=1&UM=6&UP=SP1EB8EB35-729A-42D7-A673-6043DE058F44");), Ersetzt,[ba4086b945373cfaff56028a7d889070] Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-11-2014 01 Sorry, falls ich das 2 Mal gepostet habe, aber das hatte ich beim Nachschauen eben nicht entdeckt...FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-11-2014 01 schon einmal meinen Herzlichen Zwischendank, mein Rechner läuft bereits scheinbar etwas ruhiger... allerdings scheint das Internet nun etwas langsamer... |
Zitat:
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
Security Check Log Results of screen317's Security Check version 0.99.90 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Microsoft Security Essentials Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java(TM) 7 Update 1 Java version out of Date! Adobe Flash Player 15.0.0.239 Mozilla Firefox (33.1) ````````Process Check: objlist.exe by Laurent```````` Microsoft Security Essentials MSMpEng.exe Microsoft Security Essentials msseces.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` C:\AdwCleaner\Quarantine\C\Users\Olav Kittel\AppData\Roaming\RHEng\277E0050A9444F889345A9CCDE6C794B\zafwSetupWeb_131_211_000.exe.vir Win32/Toolbar.Conduit evtl. unerwünschte Anwendung C:\Program Files (x86)\Panda Security\Panda Security Toolbar\dtuser.exe Variante von Win32/Toolbar.Visicom.C evtl. unerwünschte Anwendung C:\Program Files (x86)\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll Variante von Win32/Toolbar.Visicom.B evtl. unerwünschte Anwendung C:\Program Files (x86)\Panda Security\Panda Security Toolbar\PandaSecurityTb.dll Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung C:\Users\Olav Kittel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2H3VX1S2\IncredibarToolbar[1].7z Win32/Toolbar.Montiera.I evtl. unerwünschte Anwendung C:\Users\Olav Kittel\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CJ97UTZZ\sg[1].exe Variante von Win32/Toolbar.Perion.G evtl. unerwünschte Anwendung C:\Users\Olav Kittel\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\BabMaint.exe Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung C:\Users\Olav Kittel\AppData\Local\Temp\A11F9512-BAB0-7891-B591-4D3EACEB82CE\Latest\IEHelper.dll Win32/Toolbar.Babylon.E evtl. unerwünschte Anwendung C:\Users\Olav Kittel\AppData\Local\Temp\bhfiles\BrowserHelper.exe MSIL/Toolbar.SmileysLove.B evtl. unerwünschte Anwendung C:\Users\Olav Kittel\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2\5fb6d982-4da14857 Mehrere Bedrohungen C:\Users\Olav Kittel\Downloads\Cloud152Antivirus.exe Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung C:\Users\Olav Kittel\Downloads\VideoConverterSetup.exe Variante von Win32/InstallCore.AF evtl. unerwünschte Anwendung C:\Windows\Temp\NAV6D15.tmp Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung C:\Windows\Temp\NAVEFCD.tmp Variante von Win32/Toolbar.Visicom.A evtl. unerwünschte Anwendung FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-11-2014 01 --- --- --- --- --- --- Lieber Herr Schrauber, der PC läuft weiterhin ruhiger, das "Internet" läuft nun auch wieder schneller. Ich nehme an es lag daran, dass ich zwischendurch den PC per W-lan verbunden hatte und nicht wie gewohnt wie per Kabel. Könnte das sein? Ich bin weiterhin gespannt, wie es weitergeht. Und ich freue mich schon darauf zu spenden, auch wenn es bei meinen Einkünften ein bescheidener Beitrag wird. Vielen herzlichen Dank Dudeness |
Das kann daran liegen, klar. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKU\S-1-5-18\...\RunOnce: [panda2_0dn] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda2_0dn" /f Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
|
Fixlog Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 01-12-2014 Ran by xxx at 2014-12-02 16:51:26 Run:1 Running from C:\Users\xxx\Documents\Compi Clean Loaded Profile: xxx (Available profiles: xxx) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\S-1-5-18\...\RunOnce: [panda2_0dn] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda2_0dn" /f HKU\S-1-5-18\...\RunOnce: [panda2_0dn_XP] => reg.exe delete "HKCU\Software\panda2_0dn" /f HKU\S-1-5-18\...\RunOnce: [panda4_0dn] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda4_0dn" /f HKU\S-1-5-18\...\RunOnce: [panda4_0dn_XP] => reg.exe delete "HKCU\Software\panda4_0dn" /f HKU\S-1-5-18\...\RunOnce: [panda4_1dn] => reg.exe delete "HKCU\Software\AppDataLow\Software\panda4_1dn" /f HKU\S-1-5-18\...\RunOnce: [panda4_1dn_XP] => reg.exe delete "HKCU\Software\panda4_1dn" /f Emptytemp: ***************** HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda2_0dn => value deleted successfully. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda2_0dn_XP => value deleted successfully. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda4_0dn => value deleted successfully. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda4_0dn_XP => value deleted successfully. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda4_1dn => value deleted successfully. HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\panda4_1dn_XP => value deleted successfully. EmptyTemp: => Removed 2.9 GB temporary data. The system needed a reboot. ==== End of Fixlog ==== erstaunlicherweise lief der Rechner aktuell wieder lauter. Allerdings nur heute vor dem FRST fix run und dabei. Nun wieder leiser, aber nicht mehr so leise wie nach den ersten Schritten... Wieder einmal meinen Dank und Gruß, Dudeness |
Lüfter oder eher Festplattengeräusch? |
Danke und Spende unterwegs OK, vielen Dank noch einmal. Ich werde Ihnen und Ihrem Projekt 20€ senden, mehr ist leider nicht drin. Ich nehme an, das mein Rechner nun aus Ihrer Perspektive sauber ist? Dann werde ich mich einmal mit einem technisch verständigen Freund an die Hardware machen. Beste Grüße |
Dann müssen wir noch aufräumen. Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 06:11 Uhr. |
Copyright ©2000-2025, Trojaner-Board