Hallo,
Sorry war die letzten Tage unterwegs:
Hier die weiteren Logs:
AdwCleaner:
AdwCleaner Logfile: Code:
# AdwCleaner v5.003 - Bericht erstellt 26/08/2015 um 11:12:04
# Aktualisiert 20/08/2015 von Xplode
# Datenbank : 2015-08-20.1 [Lokal]
# Betriebssystem : Windows 8 (x64)
# Benutzername : Tobi - TOBIAS
# Gestarted von : C:\Users\Tobias\Desktop\AdwCleaner_5.003.exe
# Option : Löschen
***** [ Dienste ] *****
[-] Dienst Gelöscht : ServiceEverything
***** [ Ordner ] *****
[-] Ordner Gelöscht : C:\Program Files (x86)\WinZipper
[-] Ordner Gelöscht : C:\Program Files (x86)\miuitab
[-] Ordner Gelöscht : C:\Users\Tobi\AppData\Roaming\WinZipper
***** [ Dateien ] *****
[-] Datei Gelöscht : C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\user.js
***** [ Verknüpfungen ] *****
[-] Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[-] Verknüpfung Desinfiziert : C:\Users\Tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[-] Verknüpfung Desinfiziert : C:\Users\Tobi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Verknüpfung Desinfiziert : C:\Users\Tobi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Geplante Tasks ] *****
***** [ Registrierungsdatenbank ] *****
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7D86A08B-0A8F-4BE0-B693-F05E6947E780}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[-] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}]
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
[-] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
[-] Schlüssel Gelöscht : HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Schlüssel Gelöscht : HKCU\Software\Myfree Codec
[-] Schlüssel Gelöscht : HKCU\Software\OCS
[-] Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\hdcode
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\Myfree Codec
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\SupDp
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\SupTab
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\V9
[-] Schlüssel Gelöscht : HKLM\SOFTWARE\winzipersvc
[!] Schlüssel Nicht Gelöscht : [x64] HKCU\Software\Myfree Codec
[!] Schlüssel Nicht Gelöscht : [x64] HKCU\Software\OCS
[-] Daten Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs]
[-] Daten Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs]
***** [ Internetbrowser ] *****
[-] [C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.defaultenginename", "delta-homes");
[-] [C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.searchengine.alias", "delta-homes");
[-] [C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.searchengine.iconURL", "hxxp://search.delta-homes.com/favicon.ico");
[-] [C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.searchengine.name", "delta-homes");
[-] [C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.searchengine.url", "hxxp://search.delta-homes.com/web/?type=ds&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q[...]
[-] [C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js] [Preference] Gelöscht : user_pref("browser.search.selectedEngine", "delta-homes");
[-] [C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js] [Preference] Gelöscht : user_pref("extensions.quick_start.enable_search1", false);
[-] [C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js] [Preference] Gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
*************************
:: Proxy Einstellungen zurückgesetzt
:: Winsock Einstellungen zurückgesetzt
########## EOF - \AdwCleaner\AdwCleaner[C1].txt - [5299 Bytes] ########## --- --- ---
mbam erster Durchgang: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 26.08.2015
Suchlaufzeit: 09:00
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.1.8.1057
Malware-Datenbank: v2015.06.03.03
Rootkit-Datenbank: v2015.06.02.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Tobi
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 723667
Abgelaufene Zeit: 51 Min., 28 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 3
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1244, Löschen bei Neustart, [a3ace6d04f3b30065e8ce2dcff028977]
PUP.Optional.XTab.A, C:\Program Files (x86)\MiuiTab\ProtectService.exe, 1856, Löschen bei Neustart, [f35c3c7a5d2d3402fe9321f651b1a15f]
PUP.Optional.LuckyTab.A, C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe, 4228, Löschen bei Neustart, [2e2160563852b77f3fe1f568e122e818]
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 37
PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [a3ace6d04f3b30065e8ce2dcff028977],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsMangerProtect, In Quarantäne, [a3ace6d04f3b30065e8ce2dcff028977],
PUP.Optional.XTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, In Quarantäne, [f35c3c7a5d2d3402fe9321f651b1a15f],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{7D3C47ED-E0BE-4940-9DDA-A7A097AEBD88}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{7D3C47ED-E0BE-4940-9DDA-A7A097AEBD88}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{7D3C47ED-E0BE-4940-9DDA-A7A097AEBD88}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{51D26BB4-4D2C-4AE4-9873-5FF41B6DED1F}, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\GamesAppIntegrationService, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [96b96452b7d3330323c9fe692fd4926e],
PUP.Optional.MultiPlug.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Native Instruments Kontakt Factory Library, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.MultiPlug.Gen, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1244CC88-97DF-4694-A720-6F073845DEE2}, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\delta-homesSoftware, In Quarantäne, [4e01c1f5b1d993a3f1ddad61e22257a9],
PUP.Optional.FFPluginHp.A, HKLM\SOFTWARE\WOW6432NODE\FFPluginHp, In Quarantäne, [c68915a16822280e266402e33bc89d63],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, In Quarantäne, [66e9b8fe9eec71c55af343b3c83b28d8],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [9ab5a4121377a294f9e5293f2bdaaa56],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, In Quarantäne, [d37c991db5d59c9a1f0a67a3a262ba46],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [afa0199d8dfd61d568ba7de14cb9c739],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [b59a2294602af046b078f812bc48748c],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [3c13fbbbcfbb88ae8faca35d63a1d030],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [3b148036b4d61d19f04c01ffcd37c937],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [cf80feb8573371c54ace91a3d133f20e],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\INSTALLCORE, In Quarantäne, [0a45714517739f9702d77ccd4abb0ff1],
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [c38c298d0d7d77bf818d37b14bb8b050],
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}, In Quarantäne, [5cf372440f7b270f729caa3e778c04fc],
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{710EB415-0FEB-4072-A071-2EBF67913B6D}, In Quarantäne, [311ed3e3404a76c06ba3de0a1ae98e72],
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{83500C12-F30C-4853-B3FC-855714F941F1}, In Quarantäne, [430c2f875f2b181e888614d4689bb34d],
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9F24448A-79C7-4C35-9C15-B0E17ED97E93}, In Quarantäne, [98b7a90de5a550e60806df097f848b75],
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}, In Quarantäne, [c58a75415436b482a36b10d8e221847c],
PUP.Optional.QuickSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [034c44720c7e9e98594c85611be8659b],
PUP.Optional.OptimizerPro.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\OPTIMIZER PRO, In Quarantäne, [430c6d49d1b930061078413f1ce9ba46],
Registrierungswerte: 13
PUP.Optional.QuickSearch.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_searchff@gmail.com, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com, In Quarantäne, [1b34b7ff7119211591ec1cca37cc40c0]
PUP.Optional.SweetSearch.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|sweetsearch@gmail.com, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com, In Quarantäne, [ee61ccea830745f108761fc71be8ba46]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cor, In Quarantäne, [b59a2294602af046b078f812bc48748c]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [0a45714517739f9702d77ccd4abb0ff1]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [c38c298d0d7d77bf818d37b14bb8b050]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [5cf372440f7b270f729caa3e778c04fc]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|FaviconURL, hxxp://do-search.com//favicon.ico, In Quarantäne, [aca364524b3f33031af440a86a99ea16]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{710EB415-0FEB-4072-A071-2EBF67913B6D}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [311ed3e3404a76c06ba3de0a1ae98e72]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{83500C12-F30C-4853-B3FC-855714F941F1}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [430c2f875f2b181e888614d4689bb34d]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9F24448A-79C7-4C35-9C15-B0E17ED97E93}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [98b7a90de5a550e60806df097f848b75]
PUP.Optional.DoSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}|URL, hxxp://do-search.com/web/?utm_source=b&utm_medium=&utm_campaign=install_ie&utm_content=ds&from=&uid=ST500DM002-1BC142_W2A27G6AXXXXW2A27G6A&ts=1420373293&type=default&q={searchTerms}, In Quarantäne, [c58a75415436b482a36b10d8e221847c]
PUP.Optional.QuickSearch.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MOZILLA\EXTENDS|appid, quick_searchff@gmail.com, In Quarantäne, [034c44720c7e9e98594c85611be8659b]
PUP.Optional.OptimizerPro.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\OPTIMIZER PRO|AdsBuyNowURL, hxxp://www.safeshopgate.com/r?s=121000600&g=0B81BED8-0BE9-229D-B6CA-934C528A0174, In Quarantäne, [430c6d49d1b930061078413f1ce9ba46]
Registrierungsdaten: 21
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://www.delta-homes.com/?type=sc&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT, Gut: (firefox.exe), Schlecht: ("C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://www.delta-homes.com/?type=sc&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT),Ersetzt,[e06f74420684a5913d4a85af24e2ac54]
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.delta-homes.com/?type=sc&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.delta-homes.com/?type=sc&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT),Ersetzt,[e56a7d39b1d959dd3751ab8945c1c63a]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[1f30a90dabdfcc6a23de6bc9fe08a35d]
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT),Ersetzt,[1d32bbfb7e0cd1657a099c987b8bf808]
PUP.Optional.Delta.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT),Ersetzt,[96b9d9dd0387b77fbfc4082c21e52fd1]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[f55af8be800a0f27996843f13ec840c0]
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://www.delta-homes.com/?type=sc&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT, Gut: (firefox.exe), Schlecht: ("C:\Program Files (x86)\Mozilla Firefox\firefox.exe" hxxp://www.delta-homes.com/?type=sc&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT),Ersetzt,[63ec308678121323c3c4092b5fa7a858]
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.delta-homes.com/?type=sc&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.delta-homes.com/?type=sc&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT),Ersetzt,[3b148a2c2a6077bfe0a821136f9734cc]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[0946486ee9a11323926fbd77ad59669a]
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT),Ersetzt,[74dbaa0c7317979f4340f2426c9af50b]
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT),Ersetzt,[56f97145b2d8999d5231dd570df920e0]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[c788e0d6ed9d53e3738e5fd5fd0931cf]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[1e31c3f3fb8f251137c7d2617b8b29d7]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[cd82d0e65a30e94d9569b77cfa0cb14f]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[62edf1c5e2a8db5b728cc76c16f0ab55]
PUP.Optional.Delta.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT, Gut: (www.google.com), Schlecht: (hxxp://www.delta-homes.com/?type=hp&ts=1434146431&z=0b88b9627c9d27937d4b259g8z8c4z2g8z7q9z2c0c&from=ient06120&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT),Ersetzt,[b39c7343c8c2082e2c58072d0bfb16ea]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1002\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[004fe0d6b2d8b482f707f63d1ee829d7]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[84cbe2d40882ff37a55950e315f1e917]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[78d701b55832ec4a619d8ea5887ee020]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1005\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[9db274429eec58de906ebb781ee82dd3]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-3842866729-4066958523-73093308-1011\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1404758087&from=cor&uid=TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT&q={searchTerms}),Ersetzt,[bc932f87e4a6f44201fd8ea5f31321df]
Ordner: 47
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{868E5822-04F1-4FBB-98CD-DC08EB82D497}, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.OptimizerPro.A, C:\Users\Tobi\Documents\Optimizer Pro, In Quarantäne, [e7684e68e0aaf640e6a0b2ce41c4b050],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [6ee18d298dfd350191bdb70c778cc23e],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [6ee18d298dfd350191bdb70c778cc23e],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [fb54783e9dede4525ac0b90c4eb52ad6],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [fb54783e9dede4525ac0b90c4eb52ad6],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [fb54783e9dede4525ac0b90c4eb52ad6],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [a3acbef894f69d996d28596f80838b75],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, In Quarantäne, [d27d5165cebc46f0e6a7d604d72c06fa],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, In Quarantäne, [d27d5165cebc46f0e6a7d604d72c06fa],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\include, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\include\tools, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\lib, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\module, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\pack, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\en, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\en-US, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\es, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\es-419, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr-BE, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr-CA, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr-CH, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr-LU, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\it, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\it-CH, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\pl, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\pt-BR, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\ru, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\ru-MO, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\tr, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\vi, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\zh-CN, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\zh-TW, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\defaults, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\defaults\preferences, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com, In Quarantäne, [aca3496da2e8e25412e7ae3338cbed13],
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com\chrome, In Quarantäne, [aca3496da2e8e25412e7ae3338cbed13],
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com\chrome\content, In Quarantäne, [aca3496da2e8e25412e7ae3338cbed13],
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com\chrome\skin, In Quarantäne, [aca3496da2e8e25412e7ae3338cbed13],
Dateien: 98
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [a3ace6d04f3b30065e8ce2dcff028977],
PUP.Optional.XTab.A, C:\Program Files (x86)\MiuiTab\ProtectService.exe, Löschen bei Neustart, [f35c3c7a5d2d3402fe9321f651b1a15f],
PUP.Optional.LuckyTab.A, C:\Program Files (x86)\MiuiTab\SupTab.dll, In Quarantäne, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.LuckyTab.A, C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe, Löschen bei Neustart, [2e2160563852b77f3fe1f568e122e818],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, In Quarantäne, [80cfd2e41f6be74f350c7b40669b25db],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [bf903c7a2763b086ff9dd85fb0504ab6],
PUP.Optional.Browserwatch, C:\Program Files (x86)\MiuiTab\BrowerWatchCH.dll, In Quarantäne, [4a051b9b87035bdbfde6a47e4cbab54b],
PUP.Optional.Browserwatch, C:\Program Files (x86)\MiuiTab\BrowerWatchFF.dll, In Quarantäne, [e26dffb7fd8d1422dd061b0733d3c23e],
PUP.Optional.SearchProtect, C:\Program Files (x86)\MiuiTab\BrowserAction.dll, In Quarantäne, [cd8252648dfd88ae578c212662a0eb15],
PUP.Optional.Giner, C:\Program Files (x86)\MiuiTab\CmdShell.exe, In Quarantäne, [92bd54620d7d75c1c106dc934db904fc],
PUP.Optional.Giner, C:\Program Files (x86)\MiuiTab\HPNotify.exe, In Quarantäne, [c788694d800ae74fd9ee78f70105629e],
PUP.Optional.Giner, C:\Program Files (x86)\MiuiTab\IeWatchDog.dll, In Quarantäne, [5af5c4f21971a78fab1c353a19ed768a],
PUP.Optional.SkyTech.A, C:\Users\Tobi\AppData\Local\Temp\SupIeTemp\D17AB79826034081A81CE635E71F1C60\QQBrowserFrame.dll, In Quarantäne, [a8a7c1f50387bc7ad535a66440c2768a],
PUP.Optional.Giner, C:\Users\Tobi\AppData\Local\Temp\SupIeTemp\D17AB79826034081A81CE635E71F1C60\XTab.exe, In Quarantäne, [97b8c3f390fa7abc10b7b4bba95d7e82],
PUP.Optional.Giga, C:\Users\Tobias\Downloads\CPU-Z-lnstall.exe, In Quarantäne, [56f9dfd797f3a88ed5ac0e01ee189769],
PUP.Optional.Delta.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\searchplugins\delta-homes.xml, In Quarantäne, [d27d2f878cfe91a52f3d9c7b61a3c13f],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{868E5822-04F1-4FBB-98CD-DC08EB82D497}\Kontakt Factory Library Setup PC.dat, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{868E5822-04F1-4FBB-98CD-DC08EB82D497}\instance.dat, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{868E5822-04F1-4FBB-98CD-DC08EB82D497}\Kontakt Factory Library Setup PC.exe, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{868E5822-04F1-4FBB-98CD-DC08EB82D497}\Kontakt Factory Library Setup PC.msi, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{868E5822-04F1-4FBB-98CD-DC08EB82D497}\Kontakt Factory Library Setup PC.par, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{868E5822-04F1-4FBB-98CD-DC08EB82D497}\Kontakt Factory Library Setup PC.res, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\{868E5822-04F1-4FBB-98CD-DC08EB82D497}\mia.lib, In Quarantäne, [ed62882ea9e13ef8e67f99e724e1a25e],
PUP.Optional.OptimizerPro.A, C:\Users\Tobi\Documents\Optimizer Pro\CookiesException.txt, In Quarantäne, [e7684e68e0aaf640e6a0b2ce41c4b050],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [6ee18d298dfd350191bdb70c778cc23e],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\PluginUpdate.exe, In Quarantäne, [6ee18d298dfd350191bdb70c778cc23e],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-07-07[20-35-43-372].log, In Quarantäne, [fb54783e9dede4525ac0b90c4eb52ad6],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\update.exe, In Quarantäne, [fb54783e9dede4525ac0b90c4eb52ad6],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome.manifest, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\install.rdf, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\awesome.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\awesome.xul, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\index.html, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\quick_start.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\quick_start.xul, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\include\speed_dial.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\include\tools\about_blank_hook.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\include\tools\misc.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\include\tools\popup_image_helper.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\include\tools\urlrequestor.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\js.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\lib\doT.min.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\lib\jquery-2.1.0.min.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\lib\jquery.autocomplete.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\module\hotSearch.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\module\mostgrid.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\module\search.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\module\stat.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\pack\common.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\pack\ga.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\content\js\pack\xagainit.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\en\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\en-US\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\es\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\es-419\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr-BE\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr-CA\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr-CH\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\fr-LU\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\it\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\it-CH\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\pl\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\pt-BR\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\ru\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\ru-MO\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\tr\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\vi\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\zh-CN\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\locale\zh-TW\locale.properties, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\default_logo.png, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\googlelogo.png, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\google_trends.png, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\icon.png, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\loading.gif, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\logo.png, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\luck.png, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\newtab.ico, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\simple.css, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\chrome\skin\style.css, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\defaults\preferences\fvd.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\defaults\preferences\preferences.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\addonmanager.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\aes.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\config.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\dialogs.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\last_tab.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\misc.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\properties.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\remoterequest.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\restoreprefs.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\quick_searchff@gmail.com\modules\settings.js, In Quarantäne, [c28d34821e6cac8a9365cf1213f09f61],
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com\chrome.manifest, In Quarantäne, [aca3496da2e8e25412e7ae3338cbed13],
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com\install.rdf, In Quarantäne, [aca3496da2e8e25412e7ae3338cbed13],
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com\chrome\content\toolbar.js, In Quarantäne, [aca3496da2e8e25412e7ae3338cbed13],
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com\chrome\content\toolbar.xul, In Quarantäne, [aca3496da2e8e25412e7ae3338cbed13],
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\extensions\sweetsearch@gmail.com\chrome\skin\icon.png, In Quarantäne, [aca3496da2e8e25412e7ae3338cbed13],
PUP.Optional.QuickStart.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), Ersetzt,[38175f57c8c276c016102a4953b3bf41]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) mbam zweiter Durchgang: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 26.08.2015
Suchlaufzeit: 13:11
Protokolldatei: mbam2.txt
Administrator: Nein
Version: 2.1.8.1057
Malware-Datenbank: v2015.08.26.05
Rootkit-Datenbank: v2015.08.16.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Tobias
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 532411
Abgelaufene Zeit: 19 Min., 50 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 3
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\net_search, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
Dateien: 40
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Local\Temp\SupIeTemp\D17AB79826034081A81CE635E71F1C60\everything.exe, In Quarantäne, [81ec6ba2a2e9cb6b1a0fae034bb60bf5],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\config.ini, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\everything.dll, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\everything.exe, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\helper.dll, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\Patch.dll, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\SearchBase.db, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\SearchBase.exe, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\SearchHand.dll, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\ServiceEverything.exe, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\SFKEX.dll, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\SFKEX.exe, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\SFKEX64.dll, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\SFKEX64.exe, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\uninst.exe, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\update.exe, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\net_search\bing.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\net_search\google.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\net_search\search_config.ini, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\net_search\SFK.ini, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\net_search\SFKEX.ini, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\net_search\yahoo.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\bing.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\caret.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\FileListItem.xml, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\FileListItem_bing.xml, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\FileListItem_google.xml, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\frame.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\frame2.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\google.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\guide.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\icon_search.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\mainpanel.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\MainPannel.xml, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\panel_base.xml, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\search_content_list.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\WndMask.xml, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.Everything.A, C:\Users\Tobi\AppData\Everything\skin\yahoo.png, In Quarantäne, [95d84ac35c2f7db96aa4bc67729116ea],
PUP.Optional.QuickSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js, Gut: (), Schlecht: (quick_searchff@gmail.com), Ersetzt,[a0cd64a97318af87e4210f8a32d3d32d]
PUP.Optional.SweetSearch.A, C:\Users\Tobi\AppData\Roaming\Mozilla\Firefox\Profiles\a53njth5.default\prefs.js, Gut: (), Schlecht: (sweetsearch@gmail.com), Ersetzt,[8edfc845c9c29c9a5cac1386d33228d8]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) JRT
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.5.7 (08.18.2015:1)
OS: Windows 8 x64
Ran by Tobi on 26.08.2015 at 11:20:50,52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] C:\Program Files (x86)\myfree codec
~~~ FireFox
Successfully deleted the following from C:\Users\Tobi\AppData\Roaming\mozilla\firefox\profiles\a53njth5.default\prefs.js
user_pref(browser.search.searchengine.desc, this is my first firefox searchEngine);
user_pref(browser.search.searchengine.ptid, ient06120);
user_pref(browser.search.searchengine.uid, TOSHIBAXMQ01ABF050_23Q9C0FLTXX23Q9C0FLT);
user_pref(extensions.xpiState, {\app-profile\:{\quick_searchff@gmail.com\:{\d\:\C:\\\\Users\\\\Tobi\\\\AppData\\\\Roaming\\\\Mozilla\\\\Firefox\\\\Profiles\\\\a53njt
~~~ Chrome
[C:\Users\Tobi\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\Tobi\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
[C:\Users\Tobi\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\Tobi\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26.08.2015 at 11:25:03,50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-06-2015
Ran by Tobias (ATTENTION: The logged in user is not administrator) on TOBIAS on 26-08-2015 11:45:10
Running from C:\Users\Tobi\Desktop
Loaded Profiles: Tobi & Tobias (Available Profiles: UpdatusUser & Tobi & Tobias & Polina & Andere & Musik)
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> winlogon.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> dwm.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> WUDFHost.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> LMS.exe
Failed to access process -> WmiPrvSE.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
Failed to access process -> svchost.exe
Failed to access process -> HeciServer.exe
Failed to access process -> VESMgr.exe
Failed to access process -> VESMgrSub.exe
Failed to access process -> VESMgrSub.exe
Failed to access process -> dllhost.exe
Failed to access process -> SUSSoundProxy.exe
Failed to access process -> vmware-usbarbitrator64.exe
Failed to access process -> wmpnetwk.exe
Failed to access process -> AppleMobileDeviceService.exe
Failed to access process -> btwdins.exe
Failed to access process -> RIconMan.exe
Failed to access process -> VCService.exe
Failed to access process -> VCAgent.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
Failed to access process -> dllhost.exe
Failed to access process -> VUAgent.exe
Failed to access process -> WmiPrvSE.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\WLTRAY.exe [10590208 2013-03-14] (Broadcom Corporation)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1381744 2014-02-11] (Realtek Semiconductor)
HKLM\...\Run: [Bluetooth] => C:\Program Files\WIDCOMM\Bluetooth Software\bttray.exe [533208 2013-04-02] (Broadcom Corporation.)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3928264 2015-05-27] (Synaptics Incorporated)
HKLM\...\Run: [tvncontrol] => "C:\Program Files\TightVNC\tvnserver.exe" -controlservice -slave
HKLM-x32\...\Run: [mcui_exe] => "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Intel AppUp(R) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [156000 2013-02-19] (Intel Corporation)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-03-20] (Apple Inc.)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-07-25] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [54072 2015-06-18] (Malwarebytes Corporation)
Winlogon\Notify\igfxcui: c:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3842866729-4066958523-73093308-1003\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1562264 2014-07-25] (Samsung)
AppInit_DLLs: C:\PROGRA~2\SupTab\SEARCH~2.DLL => C:\PROGRA~2\SupTab\SEARCH~2.DLL File not found
AppInit_DLLs: , C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [184048 2013-10-31] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\vpngui.exe.lnk [2013-10-14]
ShortcutTarget: vpngui.exe.lnk -> C:\Windows\Installer\{467D5E81-8349-4892-9E81-C3674ED8E451}\Icon09DB8A851.exe ()
Startup: C:\Users\Tobias\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk [2014-11-06]
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-03-05] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Tobias\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll [2015-03-05] (Dropbox, Inc.)
BootExecute: autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3842866729-4066958523-73093308-1002\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
HKU\S-1-5-21-3842866729-4066958523-73093308-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://vaioportal.sony.eu
HKU\S-1-5-21-3842866729-4066958523-73093308-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKU\S-1-5-21-3842866729-4066958523-73093308-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony13.msn.com
HKU\S-1-5-21-3842866729-4066958523-73093308-1003\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://vaioportal.sony.eu
URLSearchHook: [S-1-5-21-3842866729-4066958523-73093308-1002] ATTENTION ==> Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3842866729-4066958523-73093308-1003 -> {9F24448A-79C7-4C35-9C15-B0E17ED97E93} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-&_nkw={searchTerms}
SearchScopes: HKU\S-1-5-21-3842866729-4066958523-73093308-1003 -> {A400D7DF-CA39-4F01-8FD1-348B993DFBF5} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-&_nkw={searchTerms}
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-05-24] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-05-24] (Oracle Corporation)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\ya9i3cr5.default
FF NetworkProxy: "type", 0
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-01-23] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-01-23] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.13.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2013-05-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.13.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-05-24] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\Sony\MSS\3.8.130\npMcAfeeMss.dll No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @vmware.com/vmrc,version=5.5.0.00000 -> C:\Program Files (x86)\Common Files\VMware\VMware Remote Console Plug-in 5.5\Firefox\np-vmware-vmrc.dll [2013-08-17] (VMware, Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [2015-05-25] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: Ghostery - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\ya9i3cr5.default\Extensions\firefox@ghostery.com.xpi [2014-04-11]
FF Extension: Adblock Plus - C:\Users\Tobias\AppData\Roaming\Mozilla\Firefox\Profiles\ya9i3cr5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-11]
StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR Profile: C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-16]
CHR Extension: (Google Drive) - C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-16]
CHR Extension: (YouTube) - C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-16]
CHR Extension: (Google Search) - C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-16]
CHR Extension: (Google Wallet) - C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-16]
CHR Extension: (Gmail) - C:\Users\Tobias\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-16]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2228440 2013-05-16] (Broadcom Corporation.)
S2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-19] (Intel Corporation)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129824 2013-01-23] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166688 2013-01-23] (Intel Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [23040 2012-09-20] (Microsoft Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
S3 McComponentHostServiceSony; C:\Program Files (x86)\Sony\MSS\3.8.130\McCHSvc.exe [235216 2013-10-16] (McAfee, Inc.)
S3 NetworkSupport; C:\Program Files (x86)\Sony\VAIO Control Center\NetworkSetting\NetworkSupport.exe [629336 2013-09-05] (Sony Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [23040 2012-09-20] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [23040 2012-09-20] (Microsoft Corporation)
S2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [266168 2013-11-19] (Intel Corporation)
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [377768 2013-11-19] (Intel Corporation)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [972000 2013-01-06] (Sony Corporation)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1642544 2014-02-28] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2015-07-06] (Microsoft Corporation)
S2 wltrysvc; C:\Program Files\Broadcom\Broadcom 802.11 Network Adapter\bcmwltry.exe [6070272 2013-03-14] (Broadcom Corporation) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170200 2013-05-16] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8469680 2015-04-17] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 BTWPANFL; C:\Windows\system32\drivers\btwpanfl.sys [44912 2013-05-16] (Broadcom Corporation.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 CVPNDRVA; C:\Windows\system32\Drivers\CVPNDRVA.sys [304784 2010-03-23] ()
S3 ffusb2audio; C:\Windows\system32\DRIVERS\ffusb2audio.sys [127280 2014-03-17] (Focusrite Audio Engineering Limited.)
S3 MADFULEGACYKEYBOARD; C:\Windows\System32\drivers\MAudioLegacyKeyboard_DFU.sys [28680 2010-02-09] (M-Audio)
S3 MAUSBLEGACYKEYBOARD; C:\Windows\system32\DRIVERS\MAudioLegacyKeyboard.sys [196616 2010-02-09] (M-Audio)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-08-26] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
S3 ptun0901; C:\Windows\system32\DRIVERS\ptun0901.sys [27136 2015-01-26] (The OpenVPN Project)
R3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2015-03-15] ()
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-05-27] (Synaptics Incorporated)
S3 vmci; \SystemRoot\System32\drivers\vmci.sys [X]
S3 VMnetAdapter; \SystemRoot\system32\DRIVERS\vmnetadapter.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-26 11:45 - 2015-08-26 11:45 - 00018593 _____ C:\Users\Tobi\Desktop\FRST.txt
2015-08-26 11:43 - 2015-08-26 11:43 - 00001780 _____ C:\Users\Tobias\Desktop\JRT.txt
2015-08-26 11:25 - 2015-08-26 11:25 - 00001780 _____ C:\Users\Tobi\Desktop\JRT.txt
2015-08-26 11:16 - 2015-08-26 11:16 - 00005396 _____ C:\Users\Tobias\Desktop\AdwCleaner[C1].txt
2015-08-26 10:55 - 2015-08-26 11:18 - 00000000 ____D C:\AdwCleaner
2015-08-26 10:48 - 2015-08-26 10:48 - 00049926 _____ C:\Users\Tobias\Desktop\mbam.txt
2015-08-26 09:57 - 2015-08-26 09:57 - 00319377 _____ C:\Users\Tobias\Desktop\Windows 8 DirektPay Trojaner; nur abgesichter Modus.htm
2015-08-26 09:57 - 2015-08-26 09:57 - 00000000 ____D C:\Users\Tobias\Desktop\Windows 8 DirektPay Trojaner; nur abgesichter Modus-Dateien
2015-08-26 08:58 - 2015-08-26 08:58 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-26 08:58 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-26 08:58 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-26 08:32 - 2015-08-26 08:32 - 01798576 _____ (Malwarebytes Corporation) C:\Users\Tobias\Desktop\JRT.exe
2015-08-26 08:31 - 2015-08-26 08:32 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Tobias\Desktop\mbam-setup-2.1.8.1057.exe
2015-08-22 19:39 - 2015-07-13 23:05 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-22 19:39 - 2015-07-13 23:05 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-22 19:39 - 2015-07-01 15:00 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-22 19:39 - 2015-07-01 14:58 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-22 19:39 - 2015-07-01 13:42 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-08-22 19:39 - 2015-07-01 13:41 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-08-22 19:39 - 2015-06-27 15:46 - 01314816 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-22 19:39 - 2015-06-27 15:23 - 00694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-22 19:39 - 2015-04-30 15:44 - 00478296 _____ C:\Windows\SysWOW64\locale.nls
2015-08-22 19:39 - 2015-04-30 15:44 - 00478296 _____ C:\Windows\system32\locale.nls
2015-08-22 19:38 - 2015-07-30 15:11 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-22 19:38 - 2015-07-30 15:10 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-22 19:38 - 2015-07-28 18:25 - 00025776 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-22 19:38 - 2015-07-28 16:13 - 01116160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-22 19:38 - 2015-07-28 16:13 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-22 19:38 - 2015-07-28 16:13 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-22 19:38 - 2015-07-28 16:13 - 00437248 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-22 19:38 - 2015-07-28 16:13 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-22 19:38 - 2015-07-28 15:12 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-22 19:38 - 2015-07-16 22:31 - 19291648 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-22 19:38 - 2015-07-16 22:31 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-22 19:38 - 2015-07-16 21:06 - 14383616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-22 19:38 - 2015-07-16 21:06 - 02865664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-22 19:38 - 2015-07-09 23:46 - 05982208 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-22 19:38 - 2015-07-09 23:44 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
2015-08-22 19:38 - 2015-07-09 22:17 - 05095424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-08-22 19:38 - 2015-07-09 22:16 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2015-08-22 19:38 - 2015-07-06 18:16 - 00044560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2015-08-22 19:38 - 2015-07-06 16:32 - 00281944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2015-08-22 19:38 - 2015-06-29 15:27 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-08-22 19:37 - 2015-07-29 16:45 - 01412608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-08-22 19:37 - 2015-07-29 16:45 - 00035328 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-22 19:37 - 2015-07-29 15:52 - 01840640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-22 19:37 - 2015-07-29 15:52 - 01280000 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-22 19:37 - 2015-07-29 15:52 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-22 19:37 - 2015-07-28 00:42 - 00304128 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-22 19:37 - 2015-07-28 00:40 - 04064768 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-08-22 19:37 - 2015-07-28 00:40 - 00366592 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-22 19:37 - 2015-07-16 22:32 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-22 19:37 - 2015-07-16 22:32 - 01409024 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-22 19:37 - 2015-07-16 22:32 - 00601600 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-22 19:37 - 2015-07-16 22:31 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-22 19:37 - 2015-07-16 22:31 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-22 19:37 - 2015-07-16 22:30 - 15416320 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-22 19:37 - 2015-07-16 22:30 - 02657280 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-22 19:37 - 2015-07-16 22:30 - 00949760 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-08-22 19:37 - 2015-07-16 21:07 - 01763328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-22 19:37 - 2015-07-16 21:07 - 01181696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-22 19:37 - 2015-07-16 21:07 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-08-22 19:37 - 2015-07-16 21:06 - 13774848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-22 19:37 - 2015-07-16 21:06 - 02056704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-22 19:37 - 2015-07-16 21:06 - 00737280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-08-22 19:37 - 2015-07-16 21:06 - 00690176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-08-22 19:37 - 2015-07-16 21:06 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-08-22 19:37 - 2015-07-16 21:06 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-08-22 19:37 - 2015-07-16 21:06 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-08-22 19:37 - 2015-07-13 23:23 - 01744384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-08-22 19:37 - 2015-07-13 23:23 - 01422336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-08-22 19:37 - 2015-07-13 23:05 - 02340864 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-08-22 19:37 - 2015-07-13 23:05 - 01850880 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-08-22 19:37 - 2015-06-17 16:13 - 01150264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2015-08-22 19:37 - 2015-06-17 15:44 - 01567560 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2015-08-22 19:37 - 2015-06-15 17:22 - 08858112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2015-08-22 19:37 - 2015-06-15 17:22 - 02416640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-08-22 19:37 - 2015-06-15 17:22 - 02037760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-08-22 19:37 - 2015-06-15 17:22 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-08-22 19:37 - 2015-06-15 17:22 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-08-22 19:37 - 2015-06-15 17:22 - 00062976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-08-22 19:37 - 2015-06-15 17:21 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-08-22 19:37 - 2015-06-15 17:20 - 10116608 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2015-08-22 19:37 - 2015-06-15 17:20 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-08-22 19:37 - 2015-06-15 17:20 - 00255488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-22 19:37 - 2015-06-15 17:20 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-22 19:37 - 2015-06-15 17:19 - 02307072 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-08-22 19:37 - 2015-06-15 17:19 - 01509376 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-22 19:37 - 2015-06-15 17:19 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-22 19:37 - 2015-06-11 22:29 - 01302528 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-08-22 19:37 - 2015-06-11 18:27 - 01024000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-08-22 19:37 - 2015-06-09 15:57 - 03248640 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-08-22 19:37 - 2015-06-09 15:09 - 00411133 _____ C:\Windows\system32\ApnDatabase.xml
2015-08-22 19:37 - 2015-04-21 15:53 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2015-08-22 19:36 - 2015-07-15 18:09 - 06969688 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-22 19:36 - 2015-07-15 18:09 - 00095064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-22 19:36 - 2015-07-15 18:06 - 01824296 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-22 19:36 - 2015-07-15 15:49 - 01410000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-22 19:36 - 2015-07-15 15:29 - 01333248 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-22 19:36 - 2015-07-09 23:47 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-22 19:36 - 2015-07-09 23:47 - 00243712 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-22 19:36 - 2015-07-09 22:18 - 00233984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-22 19:36 - 2015-06-27 18:36 - 00171352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-08-22 19:36 - 2015-06-27 15:56 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2015-08-22 19:36 - 2015-06-27 15:55 - 00668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-08-22 19:36 - 2015-06-27 15:55 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-08-22 19:36 - 2015-06-27 15:46 - 00829952 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-08-22 19:36 - 2015-06-27 15:46 - 00588800 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2015-08-22 19:36 - 2015-06-27 15:46 - 00318464 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-08-22 19:36 - 2015-06-25 20:29 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2015-08-22 19:36 - 2015-06-25 20:27 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2015-08-22 19:36 - 2015-01-07 06:25 - 00403456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2015-08-22 19:26 - 2015-08-22 19:26 - 04404952 _____ (Kaspersky Lab ZAO) C:\Users\Tobias\Desktop\tdsskiller.exe
2015-08-22 12:21 - 2015-08-26 08:58 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-22 12:20 - 2015-08-26 08:58 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-22 12:20 - 2015-08-22 19:19 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-08-22 12:19 - 2015-08-22 19:37 - 00000000 ____D C:\Users\Tobias\Desktop\mbar
2015-08-22 12:19 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-22 12:18 - 2015-08-22 12:18 - 16563304 _____ (Malwarebytes Corp.) C:\Users\Tobias\Desktop\mbar-1.09.2.1008.exe
2015-08-22 11:20 - 2015-08-22 11:20 - 00000000 ____D C:\Users\Tobi\workspace
2015-08-22 11:01 - 2015-08-22 11:01 - 00000491 _____ C:\Users\Tobias\Desktop\gmer.log
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-26 11:45 - 2015-06-13 14:01 - 00000000 ____D C:\FRST
2015-08-26 11:14 - 2013-09-30 13:47 - 00000614 _____ C:\Windows\Tasks\MATLAB R2012a Startup Accelerator.job
2015-08-26 11:13 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-26 11:12 - 2014-04-10 10:50 - 00001061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-08-26 11:12 - 2013-09-09 12:53 - 00001009 _____ C:\Users\Tobi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-26 11:11 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2015-08-26 10:51 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF
2015-08-26 10:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru
2015-08-26 09:58 - 2012-08-03 04:22 - 00122850 _____ C:\Windows\PFRO.log
2015-08-26 08:25 - 2015-03-19 20:22 - 00443416 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-26 08:23 - 2013-10-20 19:41 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-08-26 08:23 - 2013-10-20 19:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-08-26 08:21 - 2015-04-19 10:31 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-26 08:21 - 2015-04-19 10:31 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-26 08:21 - 2012-07-26 10:12 - 00000000 ___RD C:\Windows\ToastData
2015-08-26 08:21 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-26 08:21 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-26 08:21 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Defender
2015-08-26 08:21 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-08-26 08:20 - 2013-05-24 01:59 - 01936238 _____ C:\Windows\WindowsUpdate.log
2015-08-22 20:19 - 2013-10-20 19:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-08-22 20:18 - 2013-09-10 11:24 - 00000000 ____D C:\Windows\system32\MRT
2015-08-22 19:54 - 2013-09-09 17:38 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-22 19:46 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-22 19:46 - 2012-07-26 10:12 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-22 19:46 - 2012-07-26 09:59 - 00000000 ____D C:\Windows\CbsTemp
2015-08-22 19:46 - 2012-07-26 07:26 - 00000199 _____ C:\Windows\win.ini
2015-08-22 19:39 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2015-08-22 11:20 - 2013-09-09 12:51 - 00000000 ____D C:\Users\Tobi
2015-08-22 11:19 - 2014-12-24 17:42 - 00000000 ____D C:\eclipse
2015-08-22 10:56 - 2015-06-13 14:08 - 00060056 _____ C:\Users\Tobias\Desktop\Addition.txt
2015-08-22 10:56 - 2015-06-13 14:08 - 00022815 _____ C:\Users\Tobias\Desktop\FRST.txt
2015-08-22 10:17 - 2015-06-13 00:01 - 00000000 ____D C:\Users\Tobi\AppData\Everything
2015-08-08 04:27 - 2014-11-15 10:39 - 00793544 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-08 04:27 - 2014-11-15 10:39 - 00177632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-28 10:59 - 2013-09-10 11:24 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Files in the root of some directories =======
2014-12-19 18:09 - 2015-06-02 17:20 - 0000600 _____ () C:\Users\Tobias\AppData\Roaming\winscp.rnd
2014-10-15 15:23 - 2015-06-02 18:00 - 0000600 _____ () C:\Users\Tobias\AppData\Local\PUTTY.RND
2013-11-13 23:40 - 2013-11-13 23:40 - 0002762 _____ () C:\Users\Tobias\AppData\Local\recently-used.xbel
2015-03-15 22:13 - 2015-03-15 22:13 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-04-18 17:06 - 2012-10-24 21:44 - 0656048 _____ (WildTangent, Inc.) C:\ProgramData\uninstall404190.exe
Files to move or delete:
====================
C:\ProgramData\uninstall404190.exe
C:\Users\Public\Supercharger 1.1.0 Setup PC.exe
Some files in TEMP:
====================
C:\Users\Tobi\AppData\Local\Temp\xmlUpdater.exe
C:\Users\Tobias\AppData\Local\Temp\Ableton Swapper.exe
C:\Users\Tobias\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmprgbgyg.dll
C:\Users\Tobias\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\Tobias\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\Tobias\AppData\Local\Temp\ICReinstall_FileZilla_3.8.1_win32-setup.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
==================== End of log ============================ --- --- ---
Gruß,
Tobias |