Sooo, ich habe mich ein wenig durchgelesen und gehe mal davon aus, dass ichs bis hier hin richtig gemacht habe.
Logs:
MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.04.2014
Suchlauf-Zeit: 18:19:28
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.04.03.05
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Manuela
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 222395
Verstrichene Zeit: 16 Min, 53 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, 9068, Löschen bei Neustart, [af518f71cf3109f78e3967e7f30e9f61]
PUP.Optional.MindSpark, C:\Program Files\TelevisionFanatic\bar\1.bin\64brmon.exe, 2268, Löschen bei Neustart, [8977f20e20e038c80ddd5738c043649c]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 89
PUP.Optional.AudioToAudioToolBar.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TelevisionFanaticService, In Quarantäne, [a858738d57a952ae8131033219e7da26],
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, In Quarantäne, [af518f71cf3109f78e3967e7f30e9f61],
PUP.Optional.SaveSense.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\savesenselive, In Quarantäne, [01ff7987738d41bfa50e2e175da4e917],
PUP.Optional.SaveSense.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\savesenselivem, In Quarantäne, [01ff7987738d41bfa50e2e175da4e917],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SAVESENSELIVE.EXE, In Quarantäne, [01ff7987738d41bfa50e2e175da4e917],
PUP.Optional.SaveSence.A, HKLM\SOFTWARE\CLASSES\CLSID\{71e129ff-6c2a-4984-818c-7e2c998b8d99}, In Quarantäne, [57a923dde31d28d8a8c57dbf48bc05fb],
PUP.Optional.SaveSence.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{71E129FF-6C2A-4984-818C-7E2C998B8D99}, In Quarantäne, [57a923dde31d28d8a8c57dbf48bc05fb],
PUP.Optional.SaveSence.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{71E129FF-6C2A-4984-818C-7E2C998B8D99}, In Quarantäne, [57a923dde31d28d8a8c57dbf48bc05fb],
PUP.Optional.SaveSence.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{71E129FF-6C2A-4984-818C-7E2C998B8D99}, In Quarantäne, [57a923dde31d28d8a8c57dbf48bc05fb],
PUP.Optional.SaveSence.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{71E129FF-6C2A-4984-818C-7E2C998B8D99}, In Quarantäne, [57a923dde31d28d8a8c57dbf48bc05fb],
PUP.Optional.SaveSence.A, HKLM\SOFTWARE\CLASSES\CLSID\{71E129FF-6C2A-4984-818C-7E2C998B8D99}\INPROCSERVER32, In Quarantäne, [57a923dde31d28d8a8c57dbf48bc05fb],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\APPID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [e61a34ccd32d629ef696e12b59a98a76],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\CLSID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [e61a34ccd32d629ef696e12b59a98a76],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [e61a34ccd32d629ef696e12b59a98a76],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [e61a34ccd32d629ef696e12b59a98a76],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\CLSID\{33119133-0854-469d-807A-171568457991}, In Quarantäne, [9f61ac54dc24837d7e8e73cf4ab88c74],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\CLSID\{13119113-0854-469d-807A-171568457991}, In Quarantäne, [9f61ac54dc24837d7e8e73cf4ab88c74],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TelevisionFanatic.SkinLauncher.1, In Quarantäne, [9f61ac54dc24837d7e8e73cf4ab88c74],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TelevisionFanatic.SkinLauncher, In Quarantäne, [9f61ac54dc24837d7e8e73cf4ab88c74],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{03119103-0854-469d-807A-171568457991}, In Quarantäne, [9f61ac54dc24837d7e8e73cf4ab88c74],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{23119123-0854-469D-807A-171568457991}, In Quarantäne, [9f61ac54dc24837d7e8e73cf4ab88c74],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TelevisionFanatic.SkinLauncherSettings.1, In Quarantäne, [9f61ac54dc24837d7e8e73cf4ab88c74],
PUP.Optional.FunWebProducts.A, HKLM\SOFTWARE\CLASSES\TelevisionFanatic.SkinLauncherSettings, In Quarantäne, [9f61ac54dc24837d7e8e73cf4ab88c74],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, In Quarantäne, [3ec2827e5ea2f8085b64c779e61c639d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, In Quarantäne, [3ec2827e5ea2f8085b64c779e61c639d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc.1, In Quarantäne, [3ec2827e5ea2f8085b64c779e61c639d],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc, In Quarantäne, [3ec2827e5ea2f8085b64c779e61c639d],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3004627E-F8E9-4E8B-909D-316753CBA923}, In Quarantäne, [718f6d9346ba7d83086c7bc54cb620e0],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3004627E-F8E9-4E8B-909D-316753CBA923}, In Quarantäne, [718f6d9346ba7d83086c7bc54cb620e0],
PUP.Optional.PlurPush.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{82249076-D5C8-431D-982B-023779779587}, In Quarantäne, [3ec2a25e53ad2fd11d32241e26dc29d7],
PUP.Optional.PlurPush.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{82249076-D5C8-431D-982B-023779779587}, In Quarantäne, [3ec2a25e53ad2fd11d32241e26dc29d7],
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{828DC97A-2277-4E10-92A9-4907FA0922A9}, In Quarantäne, [32ce29d7a06077895c14e85b01014bb5],
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{828DC97A-2277-4E10-92A9-4907FA0922A9}, In Quarantäne, [32ce29d7a06077895c14e85b01014bb5],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, In Quarantäne, [1fe155ab3ec237c99fd4152b669cc63a],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}, In Quarantäne, [1fe155ab3ec237c99fd4152b669cc63a],
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}, In Quarantäne, [be4240c0a45ced135e110b38a85a6e92],
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}, In Quarantäne, [be4240c0a45ced135e110b38a85a6e92],
PUP.Optional.SupTab.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [1fe1c838748c18e85a6cca4142c058a8],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [1fe1c838748c18e85a6cca4142c058a8],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, In Quarantäne, [c33d50b058a8738d235dc32ee91a19e7],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [c33d50b058a8738d235dc32ee91a19e7],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\DealPlyLive, In Quarantäne, [7a86a35d48b8f9072a0ac1c36a99af51],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\SaveSenseLive, In Quarantäne, [b34d847c41bfac54d6fc454c4cb73fc1],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\sweet-pageSoftware, In Quarantäne, [b44c17e922ded42cf8b0475044bfb24e],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.OneClickCtrl.9, In Quarantäne, [a35d7d83f60a11ef4b8238595ba8f50b],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine, In Quarantäne, [748c9f611ae60df3ffced9b8897aac54],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine.1.0, In Quarantäne, [926ee21ea65a04fc804d781947bccc34],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.Update3WebControl.3, In Quarantäne, [28d859a77c84b64a8746167bba492cd4],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync, In Quarantäne, [56aab14fee123cc43499345d1ee5e818],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync.1.0, In Quarantäne, [748c3dc3c13f936de0ed5140b3506b95],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreClass, In Quarantäne, [936d19e74ab6cf311cb1474a966dc13f],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreClass.1, In Quarantäne, [78886b95738ddd23a62795fc63a03ec2],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass, In Quarantäne, [10f033cde41ce11f606dd6bbf112aa56],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass.1, In Quarantäne, [97699f6155ab718fe4e9177a3fc437c9],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine, In Quarantäne, [05fbce325da3ad53c00d048d57ac5ba5],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine.1.0, In Quarantäne, [13edc63a6f9151af9b3294fdb44fe21e],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine, In Quarantäne, [31cf8d7305fb23dd15b88a0715eea759],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [728ee8181ce4f709f2db3d5437cc2dd3],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [2ad6847c2ad65fa1f0dd6f2221e21be5],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [8977c23ed9276c94dbf2573a20e309f7],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher, In Quarantäne, [7c8439c7f9071ae6913c5c359f64ee12],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher.1.0, In Quarantäne, [ce32768ac937f60aad20236ef90a718f],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService, In Quarantäne, [ef1199677987758bae1f840daf5414ec],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [d42c29d714ec1be5ceffb2df897a916f],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine, In Quarantäne, [7b85c63a0000837d6c611b761be82cd4],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine.1.0, In Quarantäne, [33cd3fc1926e2cd4c10cb8d923e0f50b],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback, In Quarantäne, [5ca413ed30d0639de2eb286911f28779],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [d927a25ee91749b7eae36b2652b1857b],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc, In Quarantäne, [d62a2fd1de2279876766108150b34bb5],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [946ccf3113eda957834a97fa857ea858],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\APPID\SaveSenseLive.exe, In Quarantäne, [827e619f649c24dc4983c9c843c0748c],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [39c734ccff01b14f69398d01d52e13ed],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@tools.updaterss.com/SaveSenseLive Update;version=3, In Quarantäne, [956b53adbe42b34dd6faf39ecc3753ad],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@tools.updaterss.com/SaveSenseLive Update;version=9, In Quarantäne, [a45c916f37c943bdc20e5e336d96a759],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\mysearchdial.com, In Quarantäne, [de22738dae5216ea5184453ea063d030],
PUP.Optional.SaveSense.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SaveSense, In Quarantäne, [e61a936d51af7c84b5193b561ee51ee2],
PUP.Optional.SaveSense.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SaveSenseLive, In Quarantäne, [9b659d634fb1d12f11be345d778c9a66],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [6b952fd1976949b7bdd1a0cc29d9ef11],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [37c92cd459a717e909c793ef46bd6c94],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT, In Quarantäne, [c13fc9379769768a9c3992d90bf7a858],
PUP.Optional.SaveSense, HKLM\SOFTWARE\CLASSES\CLSID\{A18D16ED-27B2-4B83-B70C-15E73F099546}, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A18D16ED-27B2-4B83-B70C-15E73F099546}, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A18D16ED-27B2-4B83-B70C-15E73F099546}, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, HKLM\SOFTWARE\CLASSES\CLSID\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, HKLM\SOFTWARE\CLASSES\CLSID\{998745A3-2AE4-488D-8092-B98FB20A00C2}, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, HKLM\SOFTWARE\CLASSES\CLSID\{C1424421-D274-491E-9D47-11C8D8CB5F9A}, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SaveSense, In Quarantäne, [cd33d52b4fb1f10fdef4173d946ebf41],
Registrierungswerte: 8
Trojan.Ransom.Gend, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|wsrktula, regsvr32.exe "C:\ProgramData\wsrktula.dat", In Quarantäne, [d828fa06c838916f5225f013ad54b24e]
Trojan.Ransom.Gend, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|emhujry, regsvr32.exe "C:\ProgramData\emhujry.dat", In Quarantäne, [02fec43cf60a9f618fe85ba855ac56aa]
Trojan.Ransom.Gend, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|xxdory, regsvr32.exe "C:\ProgramData\xxdory.dat", In Quarantäne, [956bdb2552ae16ea4a2dba496b96d42c]
Trojan.Ransom.Gend, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mdyvov, regsvr32.exe "C:\ProgramData\mdyvov.dat", In Quarantäne, [11ef34cc14ec3dc3a5d24cb7639ec937]
PUP.Optional.MindSpark, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|TelevisionFanatic Search Scope Monitor, "C:\PROGRA~1\TELEVI~2\bar\1.bin\64srchmn.exe" /m=2 /w /h, In Quarantäne, [e11f2bd5f20e24dc79729bf407fc34cc]
PUP.Optional.MindSpark, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|TelevisionFanatic Browser Plugin Loader, C:\PROGRA~1\TELEVI~2\bar\1.bin\64brmon.exe, In Quarantäne, [8977f20e20e038c80ddd5738c043649c]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [37c92cd459a717e909c793ef46bd6c94]
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-56495341-11888579-1407618136-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT|Install, 1, In Quarantäne, [c13fc9379769768a9c3992d90bf7a858]
Registrierungsdaten: 2
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1396540027&from=cor&uid=ST9160827AS_5RG2ZDTRXXXX5RG2ZDTR&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1396540027&from=cor&uid=ST9160827AS_5RG2ZDTRXXXX5RG2ZDTR&q={searchTerms}),Ersetzt,[768a59a747b98977332f977c9d6739c7]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[1ee2dd23de222ad61adac25014f052ae]
Ordner: 27
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\mysearchdial, In Quarantäne, [58a81ae66f91ce3281cf91c256ac7e82],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\mysearchdial\icons_2.18.2.0, In Quarantäne, [58a81ae66f91ce3281cf91c256ac7e82],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\mysearchdial\UpdateProc, In Quarantäne, [58a81ae66f91ce3281cf91c256ac7e82],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\CrashReports, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\Download, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\Install, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\Offline, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\Offline\{8F4D9F90-D233-4D42-A7A7-A82ED9F67FF4}, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive, In Quarantäne, [6f91d927f10f7a860cc51d37e31f29d7],
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update, In Quarantäne, [6f91d927f10f7a860cc51d37e31f29d7],
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update\Log, In Quarantäne, [6f91d927f10f7a860cc51d37e31f29d7],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\SaveSense, In Quarantäne, [cd33d52b4fb1f10fdef4173d946ebf41],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\SaveSense\UpdateProc, In Quarantäne, [cd33d52b4fb1f10fdef4173d946ebf41],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense, In Quarantäne, [a75921df45bb629e9b3881d3bc46b34d],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSenseLive, In Quarantäne, [16ea99673ac644bc8a4cdf75ae5433cd],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSenseLive\CrashReports, In Quarantäne, [16ea99673ac644bc8a4cdf75ae5433cd],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, Löschen bei Neustart, [0ff1df21ff01a957161ac88efb070ff1],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [0ff1df21ff01a957161ac88efb070ff1],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}\content, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}\content\images, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}\defaults, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}\defaults\preferences, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSense, In Quarantäne, [2cd4eb1549b7eb151f0c035748ba59a7],
Dateien: 250
PUP.Optional.AudioToAudioToolBar.A, C:\Program Files\TelevisionFanatic\bar\1.bin\64barsvc.exe, Löschen bei Neustart, [a858738d57a952ae8131033219e7da26],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, Löschen bei Neustart, [af518f71cf3109f78e3967e7f30e9f61],
Trojan.Ransom.Gend, C:\ProgramData\wsrktula.dat, In Quarantäne, [d828fa06c838916f5225f013ad54b24e],
Trojan.Ransom.Gend, C:\ProgramData\emhujry.dat, In Quarantäne, [02fec43cf60a9f618fe85ba855ac56aa],
Trojan.Ransom.Gend, C:\ProgramData\xxdory.dat, In Quarantäne, [956bdb2552ae16ea4a2dba496b96d42c],
Trojan.Ransom.Gend, C:\ProgramData\mdyvov.dat, In Quarantäne, [11ef34cc14ec3dc3a5d24cb7639ec937],
PUP.Optional.SaveSense.A, C:\Program Files\SaveSenseLive\Update\SaveSenseLive.exe, In Quarantäne, [01ff7987738d41bfa50e2e175da4e917],
PUP.Optional.SaveSence.A, C:\Users\Manuela\AppData\Local\SaveSense\SaveSenseIE.dll, In Quarantäne, [57a923dde31d28d8a8c57dbf48bc05fb],
PUP.Optional.FunWebProducts.A, C:\Program Files\TelevisionFanatic\bar\1.bin\64sknlcr.dll, In Quarantäne, [9f61ac54dc24837d7e8e73cf4ab88c74],
PUP.Optional.MultiPlug.A, C:\ProgramData\topBuyer\GnVw.exe, In Quarantäne, [5aa640c08977c43c7f2b9fa3fe03d22e],
Spyware.Zbot.ED, C:\Users\Manuela\AppData\Roaming\Divaf\ottu.exe, In Quarantäne, [c33ddd2316ea709004bba7a4fc05fd03],
PUP.Optional.SupTab.A, C:\Users\Manuela\AppData\Roaming\SupTab\SupTab.dll, In Quarantäne, [8b758080e11f58a8be8d1a1b827eb44c],
Backdoor.Bot, C:\Users\Manuela\AppData\Local\Temp\112564.exe, In Quarantäne, [2bd59e628a76e91794f166e5d82919e7],
Trojan.Crypt.NKN, C:\Users\Manuela\AppData\Local\Temp\590193.exe, In Quarantäne, [2fd17090e31dfa069579a7b8669bd22e],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsb12B7.tmp, In Quarantäne, [a85822de2fd1c63a3cb91ad8887b1ae6],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsb6FF3.tmp, In Quarantäne, [df2135cb0000699726cf44aecc37f709],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsbB19.tmp, In Quarantäne, [44bc4bb5ae5203fd04f117dbd42f60a0],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsc96F4.tmp, In Quarantäne, [7b858a76d927ee125d9818da58ab7b85],
Trojan.Agent.ED, C:\Users\Manuela\AppData\Local\Temp\Arjr.dll, In Quarantäne, [2fd18a760ef237c9d8ab75ee2bd6f808],
PUP.Optional.NextLive.A, C:\Users\Manuela\AppData\Local\Temp\Mobogenie_INT.exe, In Quarantäne, [ed138d73d828728eb53fee5ed42d9b65],
PUP.Optional.Outbrowse, C:\Users\Manuela\AppData\Local\Temp\DM1394299820.exe, In Quarantäne, [c33d50b058a8738d235dc32ee91a19e7],
PUP.Optional.InstallCore, C:\Users\Manuela\AppData\Local\Temp\nsmF03A.tmp, In Quarantäne, [a25e1ae6827e5ca416a8e028aa5a718f],
PUP.Optional.SearchProtect.A, C:\Users\Manuela\AppData\Local\Temp\nso3C9A.exe, In Quarantäne, [2ad69a66867adf212a96a27f6d9430d0],
PUP.Optional.SearchProtect.A, C:\Users\Manuela\AppData\Local\Temp\nsy1846.exe, In Quarantäne, [e8186b95d32d5ea2e8d8df42de236997],
Backdoor.Bot, C:\Users\Manuela\AppData\Local\Temp\wgsdgsdgdsgsd.exe, In Quarantäne, [bf417a861fe1eb152d4eef177d839b65],
PUP.Optional.SearchProtect.A, C:\Users\Manuela\AppData\Local\Temp\nslD4B1.exe, In Quarantäne, [718f20e06799a15f3a865cc5ea1759a7],
PUP.Optional.InstallMonetizer.A, C:\Users\Manuela\AppData\Local\Temp\nsm71BB.tmp.exe, In Quarantäne, [7987f9072dd3af51bcd762bdef12d52b],
PUP.Optional.Conduit.A, C:\Users\Manuela\AppData\Local\Temp\SearchProtectINT.exe, In Quarantäne, [bc4405fb916f30d01fcd6da7b54c04fc],
PUP.Optional.InstallCore, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsgEB4A.tmp, In Quarantäne, [e21eeb15748c7090ab030ce6ba49c937],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nshD00D.tmp, In Quarantäne, [a45cf30d02fe0000ab4a0ae8b74c5ba5],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsm2186.tmp, In Quarantäne, [8080e11f2fd15ca481741cd655ae57a9],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsm231C.tmp, In Quarantäne, [f30deb153fc121df0ce991619a69e61a],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsm2F9A.tmp, In Quarantäne, [7c84aa560ff1be42be37926093706d93],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsm6318.tmp, In Quarantäne, [b64ad7296e92996737bec92924df37c9],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsmA7A6.tmp, In Quarantäne, [24dcda269d6325db9263bd351ce752ae],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsnBF4B.tmp, In Quarantäne, [5ba5b9470af6748c21d4b73bcd366799],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsr4645.tmp, In Quarantäne, [c13f956b3dc32cd4fef771811ce74ab6],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsr7437.tmp, In Quarantäne, [51afbe42b749e11f8372a94919ea738d],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsrA1FB.tmp, In Quarantäne, [936d0bf57e8222de65909a58f90af10f],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsw652A.tmp, In Quarantäne, [e917db25b24e02fe946126cc34cf9e62],
PUP.Optional.InstallCore, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsw7042.tmp, In Quarantäne, [e917b8482bd535cbf2bad919966db34d],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nswC746.tmp, In Quarantäne, [14ecfd03de22e91720d5eb077c87f808],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsxB463.tmp, In Quarantäne, [27d956aaaa56ce32668ffbf7c340857b],
PUP.Optional.InstallCore.A, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsxFBB.tmp, In Quarantäne, [d42c5ba560a03dc34fa650a2659ea759],
PUP.Optional.InstallCore, C:\Users\Manuela\AppData\Local\Temp\ICReinstall_nsyBFD8.tmp, In Quarantäne, [1ae68e7244bc38c8e6d84ebaa064d12f],
PUP.Optional.SkyTech.A, C:\Users\Manuela\AppData\Local\Temp\fullpackage_temp1396540017\alilog.dll, In Quarantäne, [27d9ba468d732cd4a56e34fe699702fe],
PUP.Optional.SkyTech.A, C:\Users\Manuela\AppData\Local\Temp\fullpackage_temp1396540017\package1.zip, In Quarantäne, [9b65ed13ec1420e07c97fd35768a6b95],
PUP.Optional.IePluginService.A, C:\Users\Manuela\AppData\Local\Temp\fullpackage_temp1396540017\tmp\SupTab.exe, In Quarantäne, [30d03bc5718f09f7e6e1dc72738e7b85],
PUP.Optional.WpManager, C:\Users\Manuela\AppData\Local\Temp\fullpackage_temp1396540017\tmp\wpm.exe, In Quarantäne, [1de3857b5da3ee12e5177eda9c65c53b],
PUP.Optional.Conduit.A, C:\Users\Manuela\AppData\Local\Temp\nstBD5A\SpSetup.exe, In Quarantäne, [3ac6817f4fb16d935858e333ea17ff01],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Local\Temp\is2352900\mysearchdial.dll, In Quarantäne, [5ba5b64af60a738d4820c685c0416a96],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\Temp\is45637729\1930646_stp\sas.exe, In Quarantäne, [5fa15ea2dd2350b0de07ed4d41c028d8],
PUP.Optional.ToolBarInstaller.A, C:\Users\Manuela\AppData\Local\Temp\is45637729\2653011_stp\BuenoSearchTB.exe, In Quarantäne, [45bb13ed857b60a0cee8c22a26dd4cb4],
PUP.Optional.SkyTech.A, C:\Users\Manuela\AppData\Local\Temp\is45637729\2212732_stp\25Marwww.sweet-page.exe, In Quarantäne, [52aeee127987f20e87205bf34ab7f60a],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\Temp\{91E8F69E-7B87-4D14-B359-263012BC5E0D}\o-update\SaveSenseLive.exe, In Quarantäne, [0bf5f808ab55f60a80effb69fb0622de],
PUP.OfferBundler.ST, C:\Users\Manuela\Downloads\SoftonicDownloader_fuer_malwarebytes-anti-malware.exe, In Quarantäne, [669a18e86a960df321e3f093877916ea],
PUP.OfferBundler.ST, C:\Users\Manuela\Desktop\Manuela\Downloads\SoftonicDownloader_fuer_malwarebytes-anti-malware.exe, In Quarantäne, [19e7ce32fe02b94717ed23607e82ee12],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{ad9a41d2-9a49-4fa6-a79e-71a0785364c8}.xpi, In Quarantäne, [4ab61ce4ac541be503f62737fd0507f9],
PUP.Optional.BuenoSearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\searchplugins\buenosearch.xml, In Quarantäne, [05fbe9178b75c9376cdd570a36cc3ec2],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\searchplugins\Mysearchdial.xml, In Quarantäne, [f0105fa12fd16f91f1e766fb3ec4d828],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\searchplugins\Mysearchdial.xml, In Quarantäne, [f907e41c4eb2fd035d7beb7605fde21e],
Trojan.Ransom.Gen, C:\Users\Manuela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk, In Quarantäne, [8f7112ee629eb34dc43c3b107f8429d7],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot.exe, In Quarantäne, [9868629e669ad52b9930cbb830d3f60a],
PUP.Optional.SaveSense, C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job, In Quarantäne, [17e94cb4c33d51af4b40efa247bca25e],
PUP.Optional.SaveSense, C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job, In Quarantäne, [768a629e8f71d42c0784e0b1887b40c0],
PUP.Optional.SweetPage.A, C:\Program Files\Mozilla Firefox\browser\searchplugins\sweet-page.xml, In Quarantäne, [cd3340c0cf31e719198e326530d3659b],
PUP.Optional.MindSpark, C:\Program Files\TelevisionFanatic\bar\1.bin\64SrchMn.exe, In Quarantäne, [e11f2bd5f20e24dc79729bf407fc34cc],
PUP.Optional.MindSpark, C:\Program Files\TelevisionFanatic\bar\1.bin\64brmon.exe, Löschen bei Neustart, [8977f20e20e038c80ddd5738c043649c],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\mysearchdial\UpdateProc\config.dat, In Quarantäne, [58a81ae66f91ce3281cf91c256ac7e82],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\mysearchdial\UpdateProc\info.dat, In Quarantäne, [58a81ae66f91ce3281cf91c256ac7e82],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\mysearchdial\UpdateProc\STTL.DAT, In Quarantäne, [58a81ae66f91ce3281cf91c256ac7e82],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\mysearchdial\UpdateProc\TTL.DAT, In Quarantäne, [58a81ae66f91ce3281cf91c256ac7e82],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_de.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_el.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_en-GB.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_en.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_es-419.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_es.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_et.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_fa.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_fi.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_fil.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_fr.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_gu.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_hi.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_hr.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_hu.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_id.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_it.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_iw.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ja.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_kn.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ko.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_lt.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_lv.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ml.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_mr.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ms.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_nl.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_no.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_pl.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_pt-BR.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_pt-PT.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ro.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdate.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_am.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ar.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_bg.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_bn.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ca.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_cs.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_sk.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_sl.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_sr.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_sv.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_sw.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ta.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_te.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_th.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_tr.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_uk.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ur.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_vi.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_zh-CN.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_zh-TW.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\psmachine.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\psuser.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHelper.msi, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_da.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_is.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\Program Files\SaveSenseLive\Update\1.3.23.0\goopdateres_ru.dll, In Quarantäne, [eb15728e4bb531cf67695202986abb45],
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update\Log\SaveSenseLive.log, In Quarantäne, [6f91d927f10f7a860cc51d37e31f29d7],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\SaveSense\UpdateProc\config.dat, In Quarantäne, [cd33d52b4fb1f10fdef4173d946ebf41],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\SaveSense\UpdateProc\info.dat, In Quarantäne, [cd33d52b4fb1f10fdef4173d946ebf41],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\SaveSense\UpdateProc\STTL.DAT, In Quarantäne, [cd33d52b4fb1f10fdef4173d946ebf41],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\SaveSense\UpdateProc\TTL.DAT, In Quarantäne, [cd33d52b4fb1f10fdef4173d946ebf41],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe, In Quarantäne, [cd33d52b4fb1f10fdef4173d946ebf41],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense\SaveSense Help.url, In Quarantäne, [a75921df45bb629e9b3881d3bc46b34d],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense\SaveSense.url, In Quarantäne, [a75921df45bb629e9b3881d3bc46b34d],
PUP.Optional.SaveSense, C:\Users\Manuela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense\Uninstall SaveSense.lnk, In Quarantäne, [a75921df45bb629e9b3881d3bc46b34d],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [0ff1df21ff01a957161ac88efb070ff1],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}\chrome.manifest, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}\install.rdf, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}\content\savesense.xul, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}\content\images\icon32.png, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\extensions\{2d7886a0-85bb-4bf2-b684-ba92b4b21d23}\defaults\preferences\defaults.js, In Quarantäne, [c63a5ea201fffc04d753fc5eb54dd828],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSense\icon.ico, In Quarantäne, [2cd4eb1549b7eb151f0c035748ba59a7],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSense\installer_icon.ico, In Quarantäne, [2cd4eb1549b7eb151f0c035748ba59a7],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSense\SaveSense.crx, In Quarantäne, [2cd4eb1549b7eb151f0c035748ba59a7],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSense\SaveSense.xpi, In Quarantäne, [2cd4eb1549b7eb151f0c035748ba59a7],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSense\SaveSenseIE64.dll, In Quarantäne, [2cd4eb1549b7eb151f0c035748ba59a7],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSense\SaveSenseUpdateVer.exe, In Quarantäne, [2cd4eb1549b7eb151f0c035748ba59a7],
PUP.Optional.SaveSense.A, C:\Users\Manuela\AppData\Local\SaveSense\uninst.exe, In Quarantäne, [2cd4eb1549b7eb151f0c035748ba59a7],
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.AL", 2);), Ersetzt,[19e72fd1e91707f94ddf41fcc3417d83]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.aflt", "cmi_14_10_FF");), Ersetzt,[d12f80800ff1f30d75b769d4f1134ab6]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");), Ersetzt,[7d83d22e5aa67b85f23aa49950b414ec]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q");), Ersetzt,[13ed4cb41be5d12fdd4f7dc02cd828d8]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cntry", "DE");), Entfernung fehlgeschlagen,[bd43a8587987768a4ddf64d94db7916f]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cr", "21098739");), Ersetzt,[9769e41cf01019e784a8231a61a37d83]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltLng", "");), Entfernung fehlgeschlagen,[19e7a759ca366d93a7858eaf18ec738d]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltSrch", true);), Ersetzt,[c93720e0eb15f010e448c479ec18c937]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dnsErr", true);), Ersetzt,[b44c4ab6817f748caf7d99a47b89d22e]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,1828564131,3396905322,2787570089,1850357963,3855095921,1516386922,3836221436,2015489896,270173904,3729539987,424611005,965674394,609003582,2041931190,3874294282,2774755777,931959409,398575749,3999997753,1104451911,1233863968,4280856088,1554076246,1949401179,1770772786,3253391265,3778438159,1649478750,2848156272,2476712966,3103989719,475488147,1715867073,3594694113,3774606882,4036647035,1593922001,4110151693,2941033654,3206511613");), Ersetzt,[857b02fec739a75946e60538cd378977]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.excTlbr", false);), Ersetzt,[10f05ba5718f32ce34f89da031d3bb45]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hdrMd5", "D700C8B343C8E4DEFD52558D8FB69ADF");), Ersetzt,[d729738dee1247b9dc50ce6fe81c37c9]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpg", true);), Ersetzt,[12ee50b057a9a65a9e8e7fbec2422ed2]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=");), Ersetzt,[58a80cf409f71fe19597083505ff966a]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.id", "001FE2E528848555");), Ersetzt,[f70908f8cb356d93fa32c07dd232639d]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlDay", "16138");), Ersetzt,[41bf639d3fc1a55b42eab08d42c26a96]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlRef", "140305_b");), Ersetzt,[17e9748c1fe1966a51db43fa20e404fc]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=");), Ersetzt,[2dd305fb966a718f5dcf77c62dd79c64]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.016:3:15");), Ersetzt,[29d7ed133ac6fd03959744f99d67bf41]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=");), Ersetzt,[1fe126da18e8d42c46e6a29b93718977]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"95\",\"lastVrsn\":\"95\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");), Ersetzt,[f60ad0309d63f709c56706377292b34d]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prdct", "mysearchdial");), Ersetzt,[1ae6f010f30d04fce14be25bdd2710f0]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");), Ersetzt,[a45cc23e1de3e11f80acb885c73dd62a]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.sg", "none");), Ersetzt,[7a865da3f40c42be7cb01d20e81c718f]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");), Ersetzt,[c63a956b3ac637c97bb1e35a996b0000]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrId", "base");), Ersetzt,[ed13b44c3dc38c74f03ccf6e61a3867a]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=&q=");), Ersetzt,[1ae631cf02fe6d93cd5f7dc014f06799]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsn", "1.8.29.0");), Ersetzt,[cc3452aef20e44bcb5773b025ea6ab55]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsni", "1.8.29.0");), Ersetzt,[d72939c77b8555ab2a028ab3df252cd4]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.newTab", false);), Ersetzt,[c33d2ed26799ca36d953da632cd89f61]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.smplGrp", "none");), Entfernung fehlgeschlagen,[b9475da304fc24dc1517d7669f65a957]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.016:3:15");), Ersetzt,[16ea2ed2c83813ede7450c31669e0df3]
PUP.Optional.MySearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.aflt", "cmi_14_10_FF");), Ersetzt,[d0300af6ed138f71ab79c9749c6829d7]
PUP.Optional.MySearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.instlRef", "140305_b");), Ersetzt,[97697888a25ef10f83a161dce51fb54b]
PUP.Optional.MySearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.cr", "21098739");), Ersetzt,[9c6445bb8b7523dd3ce8df5e679dce32]
PUP.Optional.MySearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q");), Ersetzt,[30d0c53b916f09f73aea102da26216ea]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpg", true);), Ersetzt,[5ea2ad53a25ea45c0f1e7dc038cc4fb1]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=");), Ersetzt,[f907de228977c13f8f9e182506fe13ed]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltSrch", true);), Ersetzt,[d52b3cc40bf53fc16cc10f2e31d3cd33]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");), Ersetzt,[20e002fe17e901ff16171d208480f709]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dnsErr", true);), Ersetzt,[c33d23dd2bd53dc354d95ae3d72db64a]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.newTab", false);), Ersetzt,[966a659bf0107e82ae7f2518bd47ee12]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=");), Ersetzt,[a55b55ab4eb2e31ddd5054e905ff2dd3]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=&q=");), Ersetzt,[5fa1e0200000b34d59d490ad8f75649c]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.id", "001FE2E528848555");), Ersetzt,[ec147f81d32dfd0387a63c0147bd50b0]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlDay", "16138");), Ersetzt,[1de3aa56b44caa56d5582d1063a1c43c]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsn", "1.8.29.0");), Ersetzt,[8d73dd2306faa957d8557bc2b1530af6]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsni", "1.8.29.0");), Ersetzt,[09f77b855da33dc3200d56e75ea6d32d]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.016:3:15");), Ersetzt,[04fc718fe31daf5170bdad90f90b50b0]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");), Ersetzt,[1fe19b6558a88779bd7066d79371718f]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prdct", "mysearchdial");), Ersetzt,[8e72ac543fc1ea16d7561924e222ba46]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.aflt", "cmi_14_10_FF");), Ersetzt,[6a9611ef8c74e31d49e471ccd3317f81]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.smplGrp", "none");), Ersetzt,[e11f857b24dcd828f538e35a53b1cc34]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrId", "base");), Ersetzt,[e21e57a9f30dd32de94481bc956f827e]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlRef", "140305_b");), Ersetzt,[9769738d7b85d62ab37a3d001ee6c13f]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltLng", "");), Ersetzt,[cc34ce3209f76d933af3c479f410d927]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");), Ersetzt,[a060b34d12eed12f7eaf112c43c18c74]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.excTlbr", false);), Ersetzt,[ad5340c0f80846baa38adc61e3214eb2]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cr", "21098739");), Ersetzt,[20e0d12f25db9967c16ccb72a2624fb1]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q");), Ersetzt,[ec1459a7a25ea35de34a2c112ed625db]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.AL", 2);), Ersetzt,[5ba57b8504fcf40cfa332a13768e5ea2]
PUP.Optional.BuenoSearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=7A5C001FE2E52884&affID=127690&tsp=5181");), Ersetzt,[3dc32fd1cd3346ba04346bd25ba922de]
PUP.Optional.BuenoSearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=7A5C001FE2E52884&affID=127690&tsp=5181");), Ersetzt,[fc0427d94db31ae695a382bbdd2741bf]
PUP.Optional.MySearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.aflt", "cmi_14_10_FF");), Ersetzt,[ee128b75649c7d8327fda39a7b897f81]
PUP.Optional.MySearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.instlRef", "140305_b");), Ersetzt,[99673bc58e724db335ef112c74902ad6]
PUP.Optional.MySearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.cr", "21098739");), Ersetzt,[8f71837d6898ac54081cb588f01424dc]
PUP.Optional.MySearch.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.irmysearch.cd", "2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q");), Ersetzt,[48b81be5639d7090e93b310c15ef728e]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpg", true);), Ersetzt,[cd33a25e20e08878cf5e7fbeb54f619f]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=");), Ersetzt,[f50b2ad6e61a11efa38a76c704007b85]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltSrch", true);), Ersetzt,[20e0b64ab848fa062b02e35aa1639769]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");), Ersetzt,[40c04eb2ed13f709c766ed5070947f81]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dnsErr", true);), Ersetzt,[af51de22ae52cc344be20b322ed60af6]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.newTab", false);), Ersetzt,[dc24b848af51817f36f7b687798b13ed]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=");), Ersetzt,[ae5255ab39c76d93082507365ba9cc34]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q&cr=21098739&ir=&q=");), Ersetzt,[dc24c33de51b12ee9697d16c16ee52ae]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.id", "001FE2E528848555");), Ersetzt,[3ac61de37a86847c0627320bc04424dc]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlDay", "16138");), Ersetzt,[cb35c040649c39c753dab78621e3bd43]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsn", "1.8.29.0");), Ersetzt,[4cb4f01040c0837dce5fc875ed17dd23]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.vrsni", "1.8.29.0");), Ersetzt,[be4229d79769629ebc7172cb4db7b24e]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.016:3:15");), Ersetzt,[55ab27d9d030b24e2a03c37a10f4649c]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");), Ersetzt,[d32db05030d038c8a588b984c73d3dc3]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.prdct", "mysearchdial");), Ersetzt,[e21e629e1fe1b44ceb42fd400bf99e62]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.aflt", "cmi_14_10_FF");), Ersetzt,[af5115eb8b758080f13c9f9ecc38ea16]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial_i.smplGrp", "none");), Ersetzt,[97691ae64bb5b34d71bc7fbe3bc942be]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.tlbrId", "base");), Ersetzt,[0000c63a59a7ca36a489d16ca064c63a]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.instlRef", "140305_b");), Ersetzt,[738d0df3f30d53adb677211cf70d34cc]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.dfltLng", "");), Ersetzt,[8b7530d04ab69c6472bb211cd03405fb]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");), Ersetzt,[659b738df010d12fe04db08dd72d1de3]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.excTlbr", false);), Ersetzt,[f20e2cd4d62a99674edf78c543c1da26]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cr", "21098739");), Ersetzt,[c53bba4637c9837dd55855e838cc817f]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.cd", "2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StC0CyDyEtAtD0B0EtG0EzyyB0DtG0A0EyC0BtGyD0EyEzytGyEzy0DtAyD0Ezy0CzyyD0AtA2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCzzyCtBtDyByDyBtGtDtD0EyBtG0Fzz0EzztGzzyD0AyCtGyB0EzytCzy0AtByDtC0BtDyB2Q");), Ersetzt,[4eb21be5f10f55abee3f2d106c98f907]
PUP.Optional.MySearchDial.A, C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js, Gut: (), Schlecht: (user_pref("extensions.mysearchdial.AL", 2);), Ersetzt,[0cf457a939c7916ffa3371cc7c88827e]
Physische Sektoren: 0
(No malicious items detected)
(end) ADWCLEANER Code:
# AdwCleaner v3.023 - Bericht erstellt am 03/04/2014 um 18:28:55
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : Manuela - MANUELA-PC
# Gestartet von : C:\Users\Manuela\Desktop\adwcleaner3023.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\Registry Helper
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Program Files\AnyProtectEx
Ordner Gelöscht : C:\Program Files\Optimizer Pro
Ordner Gelöscht : C:\Program Files\PC Speed Maximizer
Ordner Gelöscht : C:\Program Files\SupTab
Ordner Gelöscht : C:\Program Files\TelevisionFanatic
Ordner Gelöscht : C:\Users\Manuela\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Manuela\AppData\LocalLow\TelevisionFanatic
Ordner Gelöscht : C:\Users\Manuela\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Manuela\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Manuela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
Ordner Gelöscht : C:\Users\Manuela\Documents\Mobogenie
Ordner Gelöscht : C:\Users\Manuela\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\Manuela\Documents\PC Speed Maximizer
Ordner Gelöscht : C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\Extensions\64ffxtbr@TelevisionFanatic.com
Datei Gelöscht : C:\Users\Public\Desktop\iLivid.lnk
Datei Gelöscht : C:\Users\Manuela\Desktop\AnyProtect.lnk
Datei Gelöscht : C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\user.js
Datei Gelöscht : C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\user.js
Datei Gelöscht : C:\Windows\Tasks\SaveSense.job
Datei Gelöscht : C:\Windows\System32\Tasks\SaveSense
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [64ffxtbr@TelevisionFanatic.com]
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{384E9938-7E71-449D-B3D6-74D8FF8426DB}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{384E9938-7E71-449D-B3D6-74D8FF8426DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Registry Helper]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{04D2B915-19FF-41E9-994D-95DC898BEA43}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5D79F641-C168-40DF-A32F-BACEA7509E75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C98D5B61-B0EA-4D48-9839-1079D352D880}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F02C0832-C85C-4B93-8C6F-9DF20121A10D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5D79F641-C168-40DF-A32F-BACEA7509E75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04D2B915-19FF-41E9-994D-95DC898BEA43}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D79F641-C168-40DF-A32F-BACEA7509E75}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C98D5B61-B0EA-4D48-9839-1079D352D880}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F02C0832-C85C-4B93-8C6F-9DF20121A10D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D79F641-C168-40DF-A32F-BACEA7509E75}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C98D5B61-B0EA-4D48-9839-1079D352D880}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{04D2B915-19FF-41E9-994D-95DC898BEA43}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F02C0832-C85C-4B93-8C6F-9DF20121A10D}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{A5B9C0F5-5616-47CD-A95F-E43B488FACCF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{A5B9C0F5-5616-47CD-A95F-E43B488FACCF}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{C98D5B61-B0EA-4D48-9839-1079D352D880}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{C98D5B61-B0EA-4D48-9839-1079D352D880}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{0696F815-A3A9-490A-BB14-9EC3350B1276}]
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\TelevisionFanatic
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\Software\supTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\TelevisionFanatic
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TelevisionFanaticbar Uninstall
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v28.0 (en-US)
[ Datei : C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "sweet-page");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "sweet-page");
Zeile gelöscht : user_pref("extensions.buenosearch.lastB", "hxxp://start.mysearchdial.com/?f=1&a=cmi_14_10_FF&cd=2XzuyEtN2Y1L1QzutDtDtC0F0EtB0EyDtBzzzzyEzzyDyDyDtN0D0Tzu0SyBzyzytN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtA[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.cntry", "DE");
Zeile gelöscht : user_pref("extensions.mysearchdial.dfltLng", "");
Zeile gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.mzq2IoGobX.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.[...]
[ Datei : C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\uu4a4ocn.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [8590 octets] - [03/04/2014 18:28:10]
AdwCleaner[S0].txt - [8472 octets] - [03/04/2014 18:28:55]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8532 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x86
Ran by Manuela on 03.04.2014 at 18:32:29,78
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\backupstack_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\backupstack_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\taskhost_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\taskhost_RASMANCS
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Manuela\AppData\Roaming\mozilla\firefox\profiles\n2tbtnec.default\prefs.js
user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=7A5C001FE2E52884&affID=127690&tsp=5181");
user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=7A5C001FE2E52884&affID=127690&tsp=5181");
user_pref("extensions.mzq2IoGobX.scode", "(function(){try{var url=window.self.location.href;if(url.indexOf(\"acebook\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.index
Emptied folder: C:\Users\Manuela\AppData\Roaming\mozilla\firefox\profiles\n2tbtnec.default\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.04.2014 at 18:35:10,16
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST (1) ADDITION(2) Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Manuela (administrator) on MANUELA-PC on 03-04-2014 18:36:22
Running from C:\Users\Manuela\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe
(Red Bend Ltd.) C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe
(Microsoft Corporation) C:\Windows\system32\wbem\unsecapp.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\BtStackServer.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Microsoft Corporation) C:\Windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1725736 2010-04-23] (Synaptics Incorporated)
HKLM\...\Run: [] - [X]
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2012-02-20] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [421736 2012-03-06] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252296 2012-01-17] (Sun Microsystems, Inc.)
HKLM\...\Run: [AVSetupPending] - C:\Windows\TEMP\AVSETUP_5315615d\SetupPending.exe [422456 2014-03-04] (Avira Operations GmbH & Co. KG) <===== ATTENTION
HKU\S-1-5-21-56495341-11888579-1407618136-1000\...\Run: [renovator] - C:\Users\Manuela\AppData\Roaming\Sun\{B34B35F9-1D2E-4811-8A1C-55335C1F9BEB}\renovator.exe
AppInit_DLLs: c:\progra~1\suptab\search~1.dll => c:\progra~1\suptab\search~1.dll File Not Found
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xF5E9FE378BA7CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.google.de/
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - URL hxxp://search.conduit.com/Results.aspx?ctid=CT3323878&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SPBFAD1C0B-479C-45B1-B728-9E566BCC9132&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)
DPF: {816BE035-1450-40D0-8A3B-BA7825A83A77} hxxp://support.lenovo.com/Resources/Lenovo/AutoDetect/Lenovo_AutoDetect2.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.3.0.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.111.1
FireFox:
========
FF ProfilePath: C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default
FF Homepage: hxxp://www.google.de
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @java.com/DTPlugin,version=10.3.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.3.1 - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @TelevisionFanatic.com/Plugin - C:\Program Files\TelevisionFanatic\bar\1.bin\NP64Stub.dll No File
FF Extension: saverOn - C:\Users\Manuela\AppData\Roaming\Mozilla\Firefox\Profiles\n2tbtnec.default\Extensions\oeojvlx@oenp.net [2014-03-29]
========================== Services (Whitelisted) =================
R2 AMPPALR3; C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe [510464 2011-10-19] (Intel Corporation)
S2 AviraUpgradeService; C:\Windows\TEMP\AVSETUP_5315615d\setup.exe [1397840 2014-03-04] (Avira Operations GmbH & Co. KG)
R2 BTHSSecurityMgr; C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe [103184 2011-10-20] (Intel(R) Corporation)
U2 DMAgent; C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe [356352 2010-03-07] (Red Bend Ltd.)
R2 WiMAXAppSrv; C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe [1372160 2010-03-07] (Intel(R) Corporation)
==================== Drivers (Whitelisted) ====================
R3 AMPPAL; C:\Windows\System32\DRIVERS\AMPPAL.sys [140800 2011-10-19] (Windows (R) Win 7 DDK provider)
S3 AMPPALP; C:\Windows\System32\DRIVERS\amppal.sys [140800 2011-10-19] (Windows (R) Win 7 DDK provider)
R3 bpenum; C:\Windows\System32\DRIVERS\bpenum.sys [56832 2009-12-22] (Intel Corporation)
S3 cpudrv; C:\Program Files\SystemRequirementsLab\cpudrv.sys [11336 2011-06-02] ()
S3 lnvobus; C:\Windows\System32\DRIVERS\lnvobus.sys [302464 2008-08-01] (MCCI Corporation)
R3 NETwNs32; C:\Windows\System32\DRIVERS\NETwNs32.sys [7522304 2011-10-31] (Intel Corporation)
R1 wStLibG; C:\Windows\System32\drivers\wStLibG.sys [52920 2014-03-26] (StdLib)
S0 ddrbwlr; System32\drivers\yjnxcbc.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-03 18:36 - 2014-04-03 18:36 - 01145856 _____ (Farbar) C:\Users\Manuela\Desktop\FRST.exe
2014-04-03 18:36 - 2014-04-03 18:36 - 00008105 _____ () C:\Users\Manuela\Desktop\FRST.txt
2014-04-03 18:32 - 2014-04-03 18:32 - 00000000 ____D () C:\Windows\ERUNT
2014-04-03 18:32 - 2014-03-23 22:41 - 01038974 _____ (Thisisu) C:\Users\Manuela\Desktop\JRT_NEW.exe
2014-04-03 18:31 - 2014-04-03 18:31 - 01037734 _____ (Thisisu) C:\Users\Manuela\Desktop\JRT_6.1.2.exe
2014-04-03 18:28 - 2014-04-03 18:29 - 00000000 ____D () C:\AdwCleaner
2014-04-03 18:27 - 2014-04-03 18:27 - 01426178 _____ () C:\Users\Manuela\Desktop\adwcleaner3023.exe
2014-04-03 18:00 - 2014-04-03 18:02 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-03 18:00 - 2014-04-03 18:00 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-03 18:00 - 2014-04-03 18:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-03 18:00 - 2014-04-03 18:00 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-03 18:00 - 2014-03-05 09:26 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 18:00 - 2014-03-05 09:26 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 18:00 - 2014-03-05 09:26 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-03 17:59 - 2014-04-03 18:00 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Manuela\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-03 17:50 - 2014-04-03 18:36 - 00000000 ____D () C:\FRST
2014-04-03 17:50 - 2014-04-03 17:50 - 00000000 ____D () C:\Program Files\topBuyer
2014-04-03 17:47 - 2014-04-03 17:56 - 00000000 ____D () C:\Users\Manuela\AppData\Roaming\sweet-page
2014-03-29 15:18 - 2014-04-03 18:19 - 00000000 ____D () C:\ProgramData\topBuyer
2014-03-29 15:18 - 2014-04-03 17:50 - 00000000 ____D () C:\ProgramData\c1d0bd179be54cf7
2014-03-26 19:28 - 2014-03-26 19:28 - 00052920 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG.sys
2014-03-23 11:26 - 2014-03-23 11:26 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-23 10:05 - 2014-03-23 10:05 - 00000318 _____ () C:\Users\Manuela\AppData\Roaming\aps.uninstall.scan.results
2014-03-13 21:30 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-13 21:30 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-13 21:30 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-13 21:30 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-13 21:30 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-13 21:30 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-13 21:30 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-13 21:30 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-13 21:30 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-13 21:30 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-13 21:30 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-13 21:30 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-13 21:30 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-13 21:30 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-13 21:30 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-13 21:30 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-13 21:30 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-13 21:30 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-13 21:30 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-13 21:30 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-13 21:30 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-13 21:30 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-13 21:30 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-13 21:29 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-13 21:29 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-13 21:29 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-13 21:29 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-09 17:18 - 2014-04-03 18:19 - 00000000 ____D () C:\Users\Manuela\AppData\Roaming\Divaf
2014-03-09 17:18 - 2014-03-27 14:45 - 00000000 ____D () C:\Users\Manuela\AppData\Roaming\Upiwxe
2014-03-09 17:08 - 2014-04-03 17:54 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-09 17:07 - 2014-03-09 17:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-09 17:03 - 2014-03-29 10:16 - 00000108 _____ () C:\Users\Manuela\AppData\Roaming\WB.CFG
2014-03-09 10:24 - 2014-04-03 11:08 - 01176896 _____ (AnyProtect.com) C:\Users\Manuela\AppData\Local\AnyProtectScannerSetup.exe
2014-03-08 19:41 - 2014-03-28 17:47 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-08 19:41 - 2014-03-08 19:41 - 00001107 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-08 19:41 - 2014-03-08 19:41 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-08 19:40 - 2014-03-13 16:40 - 00000000 ____D () C:\Users\Manuela\AppData\Local\cache
2014-03-08 19:40 - 2014-03-08 19:40 - 00000000 ____D () C:\Users\Manuela\.android
2014-03-08 19:40 - 2014-03-08 19:40 - 00000000 _____ () C:\Users\Manuela\daemonprocess.txt
2014-03-05 19:06 - 2014-03-05 19:06 - 00089048 ____H () C:\Windows\system32\mlfcache.dat
==================== One Month Modified Files and Folders =======
2014-04-03 18:36 - 2014-04-03 18:36 - 01145856 _____ (Farbar) C:\Users\Manuela\Desktop\FRST.exe
2014-04-03 18:36 - 2014-04-03 18:36 - 00008105 _____ () C:\Users\Manuela\Desktop\FRST.txt
2014-04-03 18:36 - 2014-04-03 17:50 - 00000000 ____D () C:\FRST
2014-04-03 18:36 - 2010-11-20 23:01 - 01619700 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-03 18:35 - 2012-03-13 16:19 - 01201360 _____ () C:\Windows\WindowsUpdate.log
2014-04-03 18:32 - 2014-04-03 18:32 - 00000000 ____D () C:\Windows\ERUNT
2014-04-03 18:31 - 2014-04-03 18:31 - 01037734 _____ (Thisisu) C:\Users\Manuela\Desktop\JRT_6.1.2.exe
2014-04-03 18:30 - 2012-03-14 18:00 - 00000050 _____ () C:\Windows\system32\SupplicantTest.log
2014-04-03 18:30 - 2010-11-20 23:48 - 00265154 _____ () C:\Windows\PFRO.log
2014-04-03 18:30 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-03 18:30 - 2009-07-14 06:39 - 00050795 _____ () C:\Windows\setupact.log
2014-04-03 18:29 - 2014-04-03 18:28 - 00000000 ____D () C:\AdwCleaner
2014-04-03 18:29 - 2009-07-14 06:34 - 00028720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-03 18:29 - 2009-07-14 06:34 - 00028720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-03 18:27 - 2014-04-03 18:27 - 01426178 _____ () C:\Users\Manuela\Desktop\adwcleaner3023.exe
2014-04-03 18:19 - 2014-03-29 15:18 - 00000000 ____D () C:\ProgramData\topBuyer
2014-04-03 18:19 - 2014-03-09 17:18 - 00000000 ____D () C:\Users\Manuela\AppData\Roaming\Divaf
2014-04-03 18:02 - 2014-04-03 18:00 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-03 18:00 - 2014-04-03 18:00 - 00001062 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-03 18:00 - 2014-04-03 18:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-03 18:00 - 2014-04-03 18:00 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-04-03 18:00 - 2014-04-03 17:59 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Manuela\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-03 17:56 - 2014-04-03 17:47 - 00000000 ____D () C:\Users\Manuela\AppData\Roaming\sweet-page
2014-04-03 17:54 - 2014-03-09 17:08 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-03 17:50 - 2014-04-03 17:50 - 00000000 ____D () C:\Program Files\topBuyer
2014-04-03 17:50 - 2014-03-29 15:18 - 00000000 ____D () C:\ProgramData\c1d0bd179be54cf7
2014-04-03 17:49 - 2012-03-15 15:27 - 00000000 ____D () C:\Users\Manuela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2014-04-03 17:48 - 2012-03-15 15:54 - 00000000 ____D () C:\Program Files\VstPlugins
2014-04-03 17:47 - 2012-03-15 15:27 - 00000000 ____D () C:\Users\Manuela\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2014-04-03 11:08 - 2014-03-09 10:24 - 01176896 _____ (AnyProtect.com) C:\Users\Manuela\AppData\Local\AnyProtectScannerSetup.exe
2014-03-29 10:16 - 2014-03-09 17:03 - 00000108 _____ () C:\Users\Manuela\AppData\Roaming\WB.CFG
2014-03-28 17:47 - 2014-03-08 19:41 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-03-27 14:45 - 2014-03-09 17:18 - 00000000 ____D () C:\Users\Manuela\AppData\Roaming\Upiwxe
2014-03-26 19:28 - 2014-03-26 19:28 - 00052920 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG.sys
2014-03-23 22:41 - 2014-04-03 18:32 - 01038974 _____ (Thisisu) C:\Users\Manuela\Desktop\JRT_NEW.exe
2014-03-23 11:26 - 2014-03-23 11:26 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-03-23 10:05 - 2014-03-23 10:05 - 00000318 _____ () C:\Users\Manuela\AppData\Roaming\aps.uninstall.scan.results
2014-03-18 21:04 - 2014-02-15 20:35 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-18 21:02 - 2012-03-13 16:43 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-13 22:06 - 2009-07-14 06:33 - 00268272 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-13 22:05 - 2012-03-15 17:58 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-13 16:40 - 2014-03-08 19:40 - 00000000 ____D () C:\Users\Manuela\AppData\Local\cache
2014-03-09 17:07 - 2014-03-09 17:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-09 17:07 - 2012-03-15 15:06 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-09 10:21 - 2012-03-16 13:54 - 00000000 ____D () C:\Users\Manuela\AppData\Local\Mozilla
2014-03-08 19:41 - 2014-03-08 19:41 - 00001107 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-03-08 19:41 - 2014-03-08 19:41 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-08 19:40 - 2014-03-08 19:40 - 00000000 ____D () C:\Users\Manuela\.android
2014-03-08 19:40 - 2014-03-08 19:40 - 00000000 _____ () C:\Users\Manuela\daemonprocess.txt
2014-03-08 19:40 - 2012-03-13 16:26 - 00000000 ____D () C:\Users\Manuela
2014-03-08 12:52 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-05 19:06 - 2014-03-05 19:06 - 00089048 ____H () C:\Windows\system32\mlfcache.dat
2014-03-05 09:26 - 2014-04-03 18:00 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-04-03 18:00 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-04-03 18:00 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-04 07:06 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
Files to move or delete:
====================
C:\Windows\TEMP\AVSETUP_5315615d\SetupPending.exe
C:\ProgramData\23lldnur.pad
C:\ProgramData\ism_0_llatsni.pad
Some content of TEMP:
====================
C:\Users\Manuela\AppData\Local\Temp\6_Offer_15.exe
C:\Users\Manuela\AppData\Local\Temp\AskSLib.dll
C:\Users\Manuela\AppData\Local\Temp\BackupSetup.exe
C:\Users\Manuela\AppData\Local\Temp\jre-7u3-windows-i586-iftw.exe
C:\Users\Manuela\AppData\Local\Temp\nsh6569.tmp.exe
C:\Users\Manuela\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 18:14
==================== End Of Log ============================ Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014 01
Ran by Manuela at 2014-04-03 18:37:16
Running from C:\Users\Manuela\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe AIR (HKLM\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe AIR (Version: 3.1.0.4880 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 11 ActiveX (HKLM\...\{41042E28-CCA1-4147-869F-9E928B38F04C}) (Version: 11.9.900.170 - Adobe Systems Incorporated)
AnyProtect (HKLM\...\AnyProtect) (Version: 1.0.0.0 - CMI Limited)
Apple Application Support (HKLM\...\{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}) (Version: 2.1.7 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}) (Version: 5.1.1.4 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AT&T Service Activation (HKLM\...\{D81486A1-2371-4059-AC70-1AB894AC96E6}) (Version: 1.8.7.0 - AT&T)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Google Update Helper (Version: 1.3.23.0 - SaveSense) Hidden <==== ATTENTION
Intel PROSet Wireless (Version: - ) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2555 - Intel Corporation)
Intel(R) PROSet/Wireless WiFi-Software (HKLM\...\{D61E4101-9E15-4D0E-ABD1-1ABD36B43330}) (Version: 14.03.0000 - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
Intel® PROSet/Wireless WiMAX Software (HKLM\...\{6B58A964-29A5-467A-9CC4-EE1C4986214D}) (Version: 1.05.2000 - Intel Corporation)
iTunes (HKLM\...\{8B92D97D-DB3D-4926-A8F7-718FE7C5EE18}) (Version: 10.6.0.40 - Apple Inc.)
Java Auto Updater (Version: 2.1.6.0 - Sun Microsystems, Inc.) Hidden
Java(TM) 7 Update 3 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217003FF}) (Version: 7.0.30 - Oracle)
JavaFX 2.0.3 (HKLM\...\{1111706F-666A-4037-7777-203328764D10}) (Version: 2.0.3 - Oracle Corporation)
Malwarebytes Anti-Malware Version 2.00.0.1000 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.00.0.1000 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mobile Broadband Connect (HKLM\...\{91B7B957-0F45-4BDC-85BA-08F80D49B9BC}) (Version: 3.5.0011 - Lenovo)
Mozilla Firefox 28.0 (x86 en-US) (HKLM\...\Mozilla Firefox 28.0 (x86 en-US)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.9 - )
RICOH R5U8xx Media Driver ver.3.64.02 (HKLM\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.64.02 - RICOH)
System Requirements Lab for Intel (HKLM\...\{EFE3D683-903C-4B58-AB8F-C68C69F33758}) (Version: 4.5.3.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: - TeamSpeak Systems GmbH)
ThinkPad Bluetooth with Enhanced Data Rate Software (HKLM\...\{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}) (Version: 6.2.1.3100 - Broadcom Corporation)
ThinkPad UltraNav Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.18.0 - )
Verizon Wireless Mobile Broadband Self Activation (HKLM\...\{C64A877E-DF8D-4017-AA82-000A77C6D809}) (Version: 3.1.4 - Smith Micro Software, Inc.)
Windows Driver Package - Broadcom (BTHUSB) Bluetooth (04/08/2010 6.3.5.430) (HKLM\...\2004BB9EB6CEA02846881BEF1F51C11F7A90C9D6) (Version: 04/08/2010 6.3.5.430 - Broadcom)
Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) (HKLM\...\BF20603967CFDCB2BBF91950E8A56DFBC5C833FE) (Version: 07/28/2009 6.2.0.9800 - Broadcom)
==================== Restore Points =========================
07-03-2014 17:39:22 Windows Update
11-03-2014 12:19:49 Windows Update
13-03-2014 19:44:14 Windows Update
18-03-2014 14:28:48 Windows Update
18-03-2014 19:02:17 Windows Update
25-03-2014 14:20:34 Windows Update
28-03-2014 15:54:16 Windows Update
31-03-2014 16:58:25 Windows Defender Checkpoint
03-04-2014 15:48:18 Windows Update
03-04-2014 15:56:19 Removed Safari
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {7003339D-4E7A-4EC5-A36B-B37D3DBF893F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {F6409348-6801-4BD5-BBE2-5D3CBEA6CD0F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-09] (Adobe Systems Incorporated)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2012-02-20 22:29 - 2012-02-20 22:29 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2012-02-20 22:28 - 2012-02-20 22:28 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2011-01-24 13:35 - 2011-01-24 13:35 - 00132384 _____ () C:\Program Files\ThinkPad\Bluetooth Software\btkeyind.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
Name: Ericsson F3507g Mobile Broadband Minicard Composite Device
Description: Ericsson F3507g Mobile Broadband Minicard Composite Device
Class Guid: {36fc9e60-c465-11cf-8056-444553540000}
Manufacturer: Ericsson
Service: lnvobus
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 47%
Total physical RAM: 2013.3 MB
Available physical RAM: 1053.24 MB
Total Pagefile: 4026.6 MB
Available Pagefile: 3005.75 MB
Total Virtual: 2047.88 MB
Available Virtual: 1925.14 MB
==================== Drives ================================
Drive c: (System) (Fixed) (Total:137.82 GB) (Free:89.44 GB) NTFS
Drive d: (Lenovo) (Fixed) (Total:9.77 GB) (Free:3.16 GB) NTFS
Drive e: (Order CD) (CDROM) (Total:0.03 GB) (Free:0 GB) CDFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: F1157780)
Partition: GPT Partition Type.
==================== End Of Log ============================ |