![]() |
Mein Laptop legt Verknüpfungen am USB Stick an Hallo zusammen, mein Laptop legt Selbsständig verknüpfungen auf dem USB Stick an. Auf dem einem Stick sind Sensible daten drauf. Kann mir da jemand helfen. Der Rechner hat Windows 7 drauf. |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01 --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-04-2014 01 |
Stick anklemmen, nicht mehr abklemmen. Panda USB Vaccine - Download - Filepony Das laufen lassen zum Absichern des Sticks. Scan mit Combofix
|
Combofix Logfile: Code: ComboFix 14-04-17.01 - Marcus Vogelgsang 19.04.2014 14:49:44.1.8 - x64 |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
mbam.txt lässt sich nicht speichern. Programm bendet sich immer 2014/04/20 09:03:40 +0200 m.Xml yes 2.00.1.1004 v2014.04.20.03 v2014.03.27.01 trial enabled enabled disabled Windows 7 Service Pack 1 x64 Marcus Vogelgsang NTFS threat completed 273138 615 1 1 99 4 9 19 113 0 enabled enabled enabled enabled disabled disabled enabled enabled enabled C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exePUP.Optional.PriceMeter.Adelete-on-reboot22085f340e1e9fdce452b22410612ad803fd C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdate.dllPUP.Optional.PriceMeter.Adelete-on-reboot1d762705ef8c211555e33c2a689a30d0 HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}PUP.Optional.Delta.Asuccess662d60cc611ae74f79b4ce7ed32f9769 HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}PUP.Optional.Delta.Asuccess662d60cc611ae74f79b4ce7ed32f9769 HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}PUP.Optional.Wajam.Asuccessdab963c9c0bb0333f215da73dd25d42c HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}PUP.Optional.Wajam.Asuccessdab963c9c0bb0333f215da73dd25d42c HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}PUP.Optional.Iminent.Asuccessc6cdd05c2e4d2c0acba8a6a66f93e51b HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}PUP.Optional.Iminent.Asuccessc0d32dff1a6168cec6ae123a9969669a HKLM\SOFTWARE\CLASSES\CrossriderApp0039030.BHOPUP.Optional.CrossRider.Asuccess543f48e4374479bde49250469e65ec14 HKLM\SOFTWARE\CLASSES\CrossriderApp0039030.BHO.1PUP.Optional.CrossRider.Asuccess880b34f845364ee8314597ff867d9868 HKLM\SOFTWARE\CLASSES\CrossriderApp0039030.SandboxPUP.Optional.CrossRider.Asuccessd6bd9a92314ac175c1b5623407fcaf51 HKLM\SOFTWARE\CLASSES\CrossriderApp0039030.Sandbox.1PUP.Optional.CrossRider.Asuccessfd96ce5edf9c1a1c3244544233d06f91 HKLM\SOFTWARE\CLASSES\iMeshIEHelper.DNSGuardPUP.Optional.iMeshMusicBoxTB.Asuccess484b3cf01269ce68ca5aef93cb37c63a HKLM\SOFTWARE\CLASSES\iMeshIEHelper.DNSGuard.1PUP.Optional.iMeshMusicBoxTB.Asuccessf1a2ce5ec1ba47ef9d87c4be13ef6e92 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickCtrl.9PUP.Optional.PriceMeter.Asuccessc9ca76b699e275c17168a0d1857d629e HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachinePUP.Optional.PriceMeter.Asuccess395a88a4a6d51323d009b8b924def40c HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0PUP.Optional.PriceMeter.Asuccess385b6fbddaa1043210c98be6877b619f HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.Update3WebControl.3PUP.Optional.PriceMeter.Asuccess920170bc136873c3eeea4928a161a55b HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsyncPUP.Optional.PriceMeter.Asuccess98fb62ca19626dc9e4f588e9649e9967 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0PUP.Optional.PriceMeter.Asuccess0f848ca00972ab8b8c4d353c91711ae6 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClassPUP.Optional.PriceMeter.Asuccessa1f2e349bbc08caad207db961ee4ad53 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass.1PUP.Optional.PriceMeter.Asuccesseda6d5579edd3afc2bae056c1be7f20e HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClassPUP.Optional.PriceMeter.Asuccess147fbd6fec8fab8bdefba8c9c24038c8 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass.1PUP.Optional.PriceMeter.Asuccesse6ad65c7b4c70b2b54851f5227dbb050 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachinePUP.Optional.PriceMeter.Asuccessa6edf4383d3eb87eb92094ddba48768a HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0PUP.Optional.PriceMeter.Asuccess365d220a196223138b4e036e659d06fa HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachinePUP.Optional.PriceMeter.Asuccessc0d353d97cff2e087366c4ad04fe7f81 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0PUP.Optional.PriceMeter.Asuccess2073a28ab7c44ceaf6e3c6ab0ef47c84 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallbackPUP.Optional.PriceMeter.Asuccesse3b00923fd7e142203d6a1d0887a8e72 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0PUP.Optional.PriceMeter.Asuccessdeb5042832497eb89d3cff72f50d9070 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvcPUP.Optional.PriceMeter.Asuccess276c0c201a6145f1895028498a7818e8 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0PUP.Optional.PriceMeter.Asuccessb5dec16b4a3156e0f4e5e889ce347d83 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncherPUP.Optional.PriceMeter.Asuccesseba86ebe96e5d75fdefb83eeef1324dc HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0PUP.Optional.PriceMeter.Asuccess2c672408d9a265d1f6e31e5350b2d030 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassServicePUP.Optional.PriceMeter.Asuccesse8ab58d4accf6accd801521f2ad81be5 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0PUP.Optional.PriceMeter.Asuccess2370b874d0ab122411c88fe2f60c659b HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachinePUP.Optional.PriceMeter.Asuccessd0c38f9d0477a98d8257b8b98082ce32 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0PUP.Optional.PriceMeter.Asuccess0c876cc086f5d6607c5ddb9641c1e719 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallbackPUP.Optional.PriceMeter.Asuccessc8cb4fdd0576a98ddefb165b986ad729 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0PUP.Optional.PriceMeter.Asuccess474c6dbfb7c40a2c01d89ed326dc7f81 HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvcPUP.Optional.PriceMeter.Asuccess355e1913ea9160d6f0e93839659df30d HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0PUP.Optional.PriceMeter.Asuccessc8cb17150873999d2eabd79add251be5 HKLM\SOFTWARE\WOW6432NODE\DealPlyLivePUP.Optional.DealPly.Asuccess850e7cb093e88aac4fa1a8eea1623ac6 HKLM\SOFTWARE\WOW6432NODE\IminentPUP.Optional.Iminent.Asuccess8f04d65697e4a591f26020607191c739 HKLM\SOFTWARE\WOW6432NODE\Plus-HD-3.8PUP.Optional.PlusHD.Asuccess1281c369daa142f465c25230a85a847c HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0039030.BHOPUP.Optional.CrossRider.Asuccessace7a7858bf0b77f2551672f8a790ef2 HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0039030.BHO.1PUP.Optional.CrossRider.Asuccessf79cb87489f268ce05716432768d6799 HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0039030.SandboxPUP.Optional.CrossRider.Asuccessace7012bc9b243f3b3c31c7a42c1748c HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0039030.Sandbox.1PUP.Optional.CrossRider.Asuccess167d1715cfac41f580f697ffe41f19e7 HKLM\SOFTWARE\WOW6432NODE\CLASSES\iMeshIEHelper.DNSGuardPUP.Optional.iMeshMusicBoxTB.Asuccess3063c66693e879bd47dd87fb44be0ff1 HKLM\SOFTWARE\WOW6432NODE\CLASSES\iMeshIEHelper.DNSGuard.1PUP.Optional.iMeshMusicBoxTB.Asuccessf0a3f83407749b9b3de7641efd058080 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickCtrl.9PUP.Optional.PriceMeter.Asuccess4251cc60116a04325683c7aa946e827e HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachinePUP.Optional.PriceMeter.Asuccessf79cca62601b48ee1cbdd89908fab848 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0PUP.Optional.PriceMeter.Asuccess147f1616502b46f08d4c3d340af83 7c9 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.Update3WebControl.3PUP.Optional.PriceMeter.Asuccess603332fab2c9fc3a03d5125f43bf14ec HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsyncPUP.Optional.PriceMeter.Asuccesse2b1b6760e6d0f27cc0d9ad78181bc44 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0PUP.Optional.PriceMeter.Asuccess7e1514185b20f34307d23b36768c5aa6 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClassPUP.Optional.PriceMeter.Asuccess058e9f8db7c457dfd405de93b74b768a HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass.1PUP.Optional.PriceMeter.Asuccessdeb5919bb1ca0e28e1f896dbef137a86 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClassPUP.Optional.PriceMeter.Asuccess880b85a77cffd95d56832a474bb7da26 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass.1PUP.Optional.PriceMeter.Asuccessa8eb0725413af73fb128d899ee14cf31 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachinePUP.Optional.PriceMeter.Asuccess43509b91235841f5cb0ec0b15aa8e020 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0PUP.Optional.PriceMeter.Asuccess31623af2423963d39544fc75936f34 cc HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachinePUP.Optional.PriceMeter.Asuccess41524ce05922df574f8a4031f70b50b0 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0PUP.Optional.PriceMeter.Asuccessd8bb37f57b00ca6c4693ff72738f53 ad HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallbackPUP.Optional.PriceMeter.Asuccess890a61cb0972bd798752caa731 d16f91 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0PUP.Optional.PriceMeter.Asuccess0093c369b6c5a98db128f9 788d75a25e HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvcPUP.Optional.PriceMeter.Asuccess751e71bb02798fa7f3e6502130d2c53b HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0PUP.Optional.PriceMeter.Asuccess3b58b379d2a91c1a8e4b0c65c9396e92 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncherPUP.Optional.PriceMeter.Asuccess266d939998e3f83e5d7cbab71ee433cd HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0PUP.Optional.PriceMeter.Asuccess3b581418aad1b77fa6330c65c83a02fe HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassServicePUP.Optional.PriceMeter.Asuccess00931d0f87f44cea439611600cf646ba HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0PUP.Optional.PriceMeter.Asuccess296ad557235835019346f1803fc3cb3 5 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachinePUP.Optional.PriceMeter.Asuccessb8db0b21433804328455403104fe1ce4 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0PUP.Optional.PriceMeter.Asuccessc6cd44e8a6d53006c811541d34cef60a HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallbackPUP.Optional.PriceMeter.Asuccess454ed25ae695082ed2076b06e61c768a HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0PUP.Optional.PriceMeter.Asuccess930086a604777abc9049f27fa55d 3bc5 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvcPUP.Optional.PriceMeter.Asuccess524178b490eb67cf6970e28fdb27f010 HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0PUP.Optional.PriceMeter.Asuccess6231bd6fd0ab65d1ae2b74fd1de523dd HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pricemeterliveUpdatePUP.Optional.PriceMeter.Asuccess5f340e1e9fdce452b22410612ad803fd HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pricemeterliveUpdatemPUP.Optional.PriceMeter.Asuccess5f340e1e9fdce452b22410612ad803fd HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_ToolbarPUP.Optional.DataMngr.Asuccessafe4a686e39883b3cd97b1e48e756997 HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\IminentPUP.Optional.Iminent.Asuccessc7ccb27af289af87a3b01e6245bd35cb HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-3.8PUP.Optional.PlusHD.Asuccessf59eb27afc7f68ce1ff98ae8d32faf51 HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGongPUP.Optional.PriceGong.Asuccess444f77b5bfbc72c44d51ee8b21e1a55b HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\ValueAppsPUP.Optional.ValueApps.Asuccess761d0a220576db5bc0100c7311f157a9 HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DISTROMATIC\ToolbarsPUP.Optional.AlexaTB.Asuccess593a83a9b6c531050b1794088b78be42 HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1SPUP.Optional.InstallCore.Asuccess227153d9ef8c49edc6934f30917102fe HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCOREPUP.Optional.InstallCore.Asuccess4c475ece8eed37ffe3a9dfb6788b16ea HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Plus HDPUP.Optional.PlusHD.Asuccess3a59d35973082115a574b4be52b06997 HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINTPUP.Optional.SearchProtect.Asuccessc6cd5ad2cead61d5554bfd8110f2c43c HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal DownloaderPUP.Optional.Softonic.Asuccess355e17158bf06ccab8cb76f70cf6a45c HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Plus-HD-3.8PUP.Optional.PlusHD.Asuccess2e651d0f007b270f8f9d6105d1310af6 HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{89449F37-4AB2-46ED-A566-BB3A7797701B}PUP.Optional.PriceMeter.Asuccess1d762705ef8c211555e33c2a689a30d0 HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89449F37-4AB2-46ED-A566-BB3A7797701B}PUP.Optional.PriceMeter.Asuccess1d762705ef8c211555e33c2a689a30d0 HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{89449F37-4AB2-46ED-A566-BB3A7797701B}PUP.Optional.PriceMeter.Asuccess1d762705ef8c211555e33c2a689a30d0 HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F509ADC2-B40E-470F-A7B7-45191486B5CB}PUP.Optional.PriceMeter.Asuccess1d762705ef8c211555e33c2a689a30d0 HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F509ADC2-B40E-470F-A7B7-45191486B5CB}PUP.Optional.PriceMeter.Asuccess1d762705ef8c211555e33c2a689a30d0 HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{F509ADC2-B40E-470F-A7B7-45191486B5CB}PUP.Optional.PriceMeter.Asuccess1d762705ef8c211555e33c2a689a30d0 HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4211E851-747F-4470-923D-6EF683EE79CA}PUP.Optional.PriceMeter.Asuccess1d762705ef8c211555e33c2a689a30d0 HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{74930D00-2198-46FE-B6BC-FEEC60C666C9}PUP.Optional.PriceMeter.Asuccess1d762705ef8c211555e33c2a689a30d0 HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}PUP.Optional.InboxToolBar.Asuccess662d48e4cfaca5915619eb62c93921df HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER{D7E97865-918F-41E4-9CD0-25AB1C574CE8}PUP.Optional.InboxToolBar.Asuccess AdwCleaner Logfile: Code: # AdwCleaner v3.100 - Bericht erstellt am 20/04/2014 um 09:16:26 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Marcus Vogelgsang on 20.04.2014 at 9:21:47,42 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3727746948-312616605-306874443-1001\Software\sweetim Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3727746948-312616605-306874443-1001\Software\wajam Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\torchsetupfull_rasapi32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\torchsetupfull_rasmancs Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311901130} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C0F25880-3649-4E9D-8377-CACBAA942BD0} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F9BA8761-2258-46B5-9F12-FCC57CED83C0} ~~~ Files Successfully deleted: [File] "C:\Users\Marcus Vogelgsang\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\user pinned\startmenu\startfenster.lnk" Successfully deleted: [File] "C:\Users\Marcus Vogelgsang\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\user pinned\taskbar\startfenster.lnk" ~~~ Folders Successfully deleted: [Folder] "C:\Users\Marcus Vogelgsang\appdata\locallow\datamngr" Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{146E3582-09F1-4D43-96B5-C0BA1022FD01} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{19EF52DF-74BA-4B10-B2B7-F84BE4E62B2D} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{1F9152C4-1886-4110-A06C-4AA831CF6780} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{2712F35C-0880-4927-9080-3A3AA4A768A0} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{2CC8AA98-E1AA-4D74-93B2-20470A32BACE} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{2CD98239-6E5B-4920-8A29-F71DFCBF2F76} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{2EB3BF1D-5280-4F55-8874-18447B088EED} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{446C6F1B-8116-4253-A248-3A3DBA3EE8FD} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{4A340B4C-9243-4557-8B87-7A26A23BF577} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{60946E68-948E-4186-A25B-6256B6F187C5} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{6F7ABDE5-0BBA-49E0-A415-15BE6B41FAA9} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{725268D9-FDD7-44B9-98F4-69CE66DA0B20} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{7EFC7BFE-59FE-4090-9DA4-73CFEF2C9623} Successfully deleted: [Empty Folder] C:\Users\Marcus Vogelgsang\appdata\local\{BD8A9438-8164-4137-9AAF-07FE485F2646} ~~~ Chrome Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20.04.2014 at 9:30:31,52 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-04-2014 --- --- --- |
Hier nochmal die mbam.txt <?xml version="1.0" encoding="UTF-8" ?> <mbam-log> <header> <date>2014/04/20 09:03:40 +0200</date> <log>m.Xml</log> <isadmin>yes</isadmin> </header> <engine> <version>2.00.1.1004</version> <rules-database>v2014.04.20.03</rules-database> <swissarmy-database>v2014.03.27.01</swissarmy-database> <license>trial</license> <file-protection>enabled</file-protection> <web-protection>enabled</web-protection> <self-protection>disabled</self-protection> </engine> <system> <osversion>Windows 7 Service Pack 1</osversion> <arch>x64</arch> <username>Marcus Vogelgsang</username> <filesys>NTFS</filesys> </system> <summary> <type>threat</type> <result>completed</result> <objects>273138</objects> <time>615</time> <processes>1</processes> <modules>1</modules> <keys>99</keys> <values>4</values> <datas>9</datas> <folders>19</folders> <files>113</files> <sectors>0</sectors> </summary> <options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>disabled</rootkits> <deeprootkit>disabled</deeprootkit> <shuriken>enabled</shuriken> <pup>enabled</pup> <pum>enabled</pum> </options> <items> <process><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>delete-on-reboot</action><pid>2208</pid><hash>5f340e1e9fdce452b22410612ad803fd</hash></process> <module><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdate.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>delete-on-reboot</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></module> <key><path>HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>662d60cc611ae74f79b4ce7ed32f9769</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}</path><vendor>PUP.Optional.Delta.A</vendor><action>success</action><hash>662d60cc611ae74f79b4ce7ed32f9769</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}</path><vendor>PUP.Optional.Wajam.A</vendor><action>success</action><hash>dab963c9c0bb0333f215da73dd25d42c</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}</path><vendor>PUP.Optional.Wajam.A</vendor><action>success</action><hash>dab963c9c0bb0333f215da73dd25d42c</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}</path><vendor>PUP.Optional.Iminent.A</vendor><action>success</action><hash>c6cdd05c2e4d2c0acba8a6a66f93e51b</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}</path><vendor>PUP.Optional.Iminent.A</vendor><action>success</action><hash>c0d32dff1a6168cec6ae123a9969669a</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\CrossriderApp0039030.BHO</path><vendor>PUP.Optional.CrossRider.A</vendor><action>success</action><hash>543f48e4374479bde49250469e65ec14</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\CrossriderApp0039030.BHO.1</path><vendor>PUP.Optional.CrossRider.A</vendor><action>success</action><hash>880b34f845364ee8314597ff867d9868</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\CrossriderApp0039030.Sandbox</path><vendor>PUP.Optional.CrossRider.A</vendor><action>success</action><hash>d6bd9a92314ac175c1b5623407fcaf51</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\CrossriderApp0039030.Sandbox.1</path><vendor>PUP.Optional.CrossRider.A</vendor><action>success</action><hash>fd96ce5edf9c1a1c3244544233d06f91</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\iMeshIEHelper.DNSGuard</path><vendor>PUP.Optional.iMeshMusicBoxTB.A</vendor><action>success</action><hash>484b3cf01269ce68ca5aef93cb37c63a</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\iMeshIEHelper.DNSGuard.1</path><vendor>PUP.Optional.iMeshMusicBoxTB.A</vendor><action>success</action><hash>f1a2ce5ec1ba47ef9d87c4be13ef6e92</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickCtrl.9</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>c9ca76b699e275c17168a0d1857d629e</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>395a88a4a6d51323d009b8b924def40c</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>385b6fbddaa1043210c98be6877b619f</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.Update3WebControl.3</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>920170bc136873c3eeea4928a161a55b</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>98fb62ca19626dc9e4f588e9649e9967</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>0f848ca00972ab8b8c4d353c91711ae6</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>a1f2e349bbc08caad207db961ee4ad53</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass.1</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>eda6d5579edd3afc2bae056c1be7f20e</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>147fbd6fec8fab8bdefba8c9c24038c8</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass.1</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>e6ad65c7b4c70b2b54851f5227dbb050</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>a6edf4383d3eb87eb92094ddba48768a</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>365d220a196223138b4e036e659d06fa</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>c0d353d97cff2e087366c4ad04fe7f81</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>2073a28ab7c44ceaf6e3c6ab0ef47c84</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>e3b00923fd7e142203d6a1d0887a8e72</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>deb5042832497eb89d3cff72f50d9070</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>276c0c201a6145f1895028498a7818e8</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>b5dec16b4a3156e0f4e5e889ce347d83</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>eba86ebe96e5d75fdefb83eeef1324dc</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>2c672408d9a265d1f6e31e5350b2d030</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>e8ab58d4accf6accd801521f2ad81be5</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>2370b874d0ab122411c88fe2f60c659b</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>d0c38f9d0477a98d8257b8b98082ce32</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>0c876cc086f5d6607c5ddb9641c1e719</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>c8cb4fdd0576a98ddefb165b986ad729</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>474c6dbfb7c40a2c01d89ed326dc7f81</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>355e1913ea9160d6f0e93839659df30d</hash></key> <key><path>HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>c8cb17150873999d2eabd79add251be5</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\DealPlyLive</path><vendor>PUP.Optional.DealPly.A</vendor><action>success</action><hash>850e7cb093e88aac4fa1a8eea1623ac6</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\Iminent</path><vendor>PUP.Optional.Iminent.A</vendor><action>success</action><hash>8f04d65697e4a591f26020607191c739</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\Plus-HD-3.8</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>1281c369daa142f465c25230a85a847c</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0039030.BHO</path><vendor>PUP.Optional.CrossRider.A</vendor><action>success</action><hash>ace7a7858bf0b77f2551672f8a790ef2</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0039030.BHO.1</path><vendor>PUP.Optional.CrossRider.A</vendor><action>success</action><hash>f79cb87489f268ce05716432768d6799</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0039030.Sandbox</path><vendor>PUP.Optional.CrossRider.A</vendor><action>success</action><hash>ace7012bc9b243f3b3c31c7a42c1748c</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CrossriderApp0039030.Sandbox.1</path><vendor>PUP.Optional.CrossRider.A</vendor><action>success</action><hash>167d1715cfac41f580f697ffe41f19e7</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\iMeshIEHelper.DNSGuard</path><vendor>PUP.Optional.iMeshMusicBoxTB.A</vendor><action>success</action><hash>3063c66693e879bd47dd87fb44be0ff1</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\iMeshIEHelper.DNSGuard.1</path><vendor>PUP.Optional.iMeshMusicBoxTB.A</vendor><action>success</action><hash>f0a3f83407749b9b3de7641efd058080</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickCtrl.9</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>4251cc60116a04325683c7aa946e827e</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>f79cca62601b48ee1cbdd89908fab848</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>147f1616502b46f08d4c3d340af837c9</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.Update3WebControl.3</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>603332fab2c9fc3a03d5125f43bf14ec</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>e2b1b6760e6d0f27cc0d9ad78181bc44</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>7e1514185b20f34307d23b36768c5aa6</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>058e9f8db7c457dfd405de93b74b768a</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass.1</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>deb5919bb1ca0e28e1f896dbef137a86</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>880b85a77cffd95d56832a474bb7da26</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass.1</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>a8eb0725413af73fb128d899ee14cf31</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>43509b91235841f5cb0ec0b15aa8e020</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>31623af2423963d39544fc75936f34cc</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>41524ce05922df574f8a4031f70b50b0</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>d8bb37f57b00ca6c4693ff72738f53ad</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>890a61cb0972bd798752caa731d16f91</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>0093c369b6c5a98db128f9788d75a25e</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>751e71bb02798fa7f3e6502130d2c53b</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>3b58b379d2a91c1a8e4b0c65c9396e92</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>266d939998e3f83e5d7cbab71ee433cd</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>3b581418aad1b77fa6330c65c83a02fe</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>00931d0f87f44cea439611600cf646ba</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>296ad557235835019346f1803fc3cb35</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>b8db0b21433804328455403104fe1ce4</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>c6cd44e8a6d53006c811541d34cef60a</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>454ed25ae695082ed2076b06e61c768a</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>930086a604777abc9049f27fa55d3bc5</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>524178b490eb67cf6970e28fdb27f010</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>6231bd6fd0ab65d1ae2b74fd1de523dd</hash></key> <key><path>HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pricemeterliveUpdate</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>5f340e1e9fdce452b22410612ad803fd</hash></key> <key><path>HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pricemeterliveUpdatem</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>5f340e1e9fdce452b22410612ad803fd</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar</path><vendor>PUP.Optional.DataMngr.A</vendor><action>success</action><hash>afe4a686e39883b3cd97b1e48e756997</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent</path><vendor>PUP.Optional.Iminent.A</vendor><action>success</action><hash>c7ccb27af289af87a3b01e6245bd35cb</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-3.8</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>f59eb27afc7f68ce1ff98ae8d32faf51</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong</path><vendor>PUP.Optional.PriceGong.A</vendor><action>success</action><hash>444f77b5bfbc72c44d51ee8b21e1a55b</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\ValueApps</path><vendor>PUP.Optional.ValueApps.A</vendor><action>success</action><hash>761d0a220576db5bc0100c7311f157a9</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DISTROMATIC\Toolbars</path><vendor>PUP.Optional.AlexaTB.A</vendor><action>success</action><hash>593a83a9b6c531050b1794088b78be42</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S</path><vendor>PUP.Optional.InstallCore.A</vendor><action>success</action><hash>227153d9ef8c49edc6934f30917102fe</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE</path><vendor>PUP.Optional.InstallCore.A</vendor><action>success</action><hash>4c475ece8eed37ffe3a9dfb6788b16ea</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Plus HD</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>3a59d35973082115a574b4be52b06997</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT</path><vendor>PUP.Optional.SearchProtect.A</vendor><action>success</action><hash>c6cd5ad2cead61d5554bfd8110f2c43c</hash></key> <key><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>355e17158bf06ccab8cb76f70cf6a45c</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Plus-HD-3.8</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{89449F37-4AB2-46ED-A566-BB3A7797701B}</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89449F37-4AB2-46ED-A566-BB3A7797701B}</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{89449F37-4AB2-46ED-A566-BB3A7797701B}</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F509ADC2-B40E-470F-A7B7-45191486B5CB}</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F509ADC2-B40E-470F-A7B7-45191486B5CB}</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{F509ADC2-B40E-470F-A7B7-45191486B5CB}</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4211E851-747F-4470-923D-6EF683EE79CA}</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{74930D00-2198-46FE-B6BC-FEEC60C666C9}</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></key> <value><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}</path><valuename></valuename><vendor>PUP.Optional.InboxToolBar.A</vendor><action>success</action><valuedata></valuedata><hash>662d48e4cfaca5915619eb62c93921df</hash></value> <value><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER</path><valuename>{D7E97865-918F-41E4-9CD0-25AB1C574CE8}</valuename><vendor>PUP.Optional.InboxToolBar.A</vendor><action>success</action><valuedata>exéבäAœÐ%«WLè</valuedata><hash>662d48e4cfaca5915619eb62c93921df</hash></value> <value><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE</path><valuename>tb</valuename><vendor>PUP.Optional.InstallCore.A</vendor><action>success</action><valuedata>0L1N1H2O1S</valuedata><hash>4c475ece8eed37ffe3a9dfb6788b16ea</hash></value> <value><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT</path><valuename>Install</valuename><vendor>PUP.Optional.SearchProtect.A</vendor><action>success</action><valuedata>1</valuedata><hash>c6cd5ad2cead61d5554bfd8110f2c43c</hash></value> <data><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN</path><valuename>Default_Search_URL</valuename><vendor>Hijack.SearchPage</vendor><action>replaced</action><valuedata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</valuedata><baddata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</baddata><gooddata>hxxp://www.google.com</gooddata><hash>9ef51c10eb90e74fa0354cdb48bc36ca</hash></data> <data><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN</path><valuename>Start Page</valuename><vendor>Hijack.StartPage</vendor><action>replaced</action><valuedata>hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9</valuedata><baddata>hxxp://search.certified-toolbar.com?si=66920&st=home&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9</baddata><gooddata>hxxp://www.google.com</gooddata><hash>bad9ca629ae1db5b567b59ce0ef6bd43</hash></data> <data><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN</path><valuename>Search Page</valuename><vendor>Hijack.SearchPage</vendor><action>replaced</action><valuedata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</valuedata><baddata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</baddata><gooddata>hxxp://www.google.com</gooddata><hash>b4df2efe037849ed8a4d0d1ab15302fe</hash></data> <data><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN</path><valuename>Search Bar</valuename><vendor>Hijack.SearchPage</vendor><action>replaced</action><valuedata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</valuedata><baddata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</baddata><gooddata>hxxp://www.google.com</gooddata><hash>f3a00c20ed8e4aec00d6ce591fe5837d</hash></data> <data><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH</path><valuename>Default_Search_URL</valuename><vendor>Hijack.SearchPage</vendor><action>replaced</action><valuedata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</valuedata><baddata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</baddata><gooddata>hxxp://www.google.com/</gooddata><hash>d2c168c42e4d2b0bffd961c623e147b9</hash></data> <data><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN</path><valuename>Default_Search_URL</valuename><vendor>Hijack.SearchPage</vendor><action>replaced</action><valuedata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</valuedata><baddata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</baddata><gooddata>hxxp://www.google.com</gooddata><hash>b3e0bf6dc7b4a1958b472afd26dec838</hash></data> <data><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH</path><valuename>Default_Search_URL</valuename><vendor>Hijack.SearchPage</vendor><action>replaced</action><valuedata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</valuedata><baddata>hxxp://search.certified-toolbar.com?si=66920&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&st=chrome&q=</baddata><gooddata>hxxp://www.google.com/</gooddata><hash>9cf7d05c79020c2a66739e89e51fed13</hash></data> <data><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH</path><valuename>SearchAssistant</valuename><vendor>PUP.Optional.Snapdo</vendor><action>replaced</action><valuedata>hxxp://feed.snapdo.com/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=fd8dd8a6-bd80-4116-acaa-32bcd857b46a&searchtype=ds&q={searchTerms}&installDate=28/04/2013</valuedata><baddata>hxxp://feed.snapdo.com/?publisher=Bundlore&dpid=Bundlore&co=DE&userid=fd8dd8a6-bd80-4116-acaa-32bcd857b46a&searchtype=ds&q={searchTerms}&installDate=28/04/2013</baddata><gooddata>hxxp://www.google.com</gooddata><hash>a8ebce5ef38842f41c9688a02bd9c13f</hash></data> <data><path>HKU\S-1-5-21-3727746948-312616605-306874443-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURI</path><valuename>(Default)</valuename><vendor>PUP.Optional.SearchCertifiedTB.A</vendor><action>replaced</action><valuedata>hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&q=%s</valuedata><baddata>hxxp://search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=4.8&ts=1380578400000.000008&tguid=66920-6787-1380617223299-9BCA2DF632088B28D1BF5D06723459E9&q=%s</baddata><gooddata>hxxp://www.google.com</gooddata><hash>029177b52655a0965ba6002aee162ed2</hash></data> <folder><path>C:\ProgramData\IBUpdaterService</path><vendor>Adware.InstallBrain</vendor><action>success</action><hash>91024ddf36450630e071d798af5409f7</hash></folder> <folder><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\SpeedAnalysis2</path><vendor>PUP.Optional.SpeedAnalysis.A</vendor><action>success</action><hash>1f74f7350873e650732d9bf8b25103fd</hash></folder> <folder><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\OpenCandy</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ff945ecec8b3be78798f223dc33ffd03</hash></folder> <folder><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\OpenCandy\787794313D9E4C4F8F476AC981F509E6</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ff945ecec8b3be78798f223dc33ffd03</hash></folder> <folder><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\OpenCandy\9F712565036A4067B138BE468BAA59A7</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ff945ecec8b3be78798f223dc33ffd03</hash></folder> <folder><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\OpenCandy\AD2F533A6DC34439AE2E5402F29BDFB6</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ff945ecec8b3be78798f223dc33ffd03</hash></folder> <folder><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\File Scout</path><vendor>PUP.Optional.FileScout.A</vendor><action>success</action><hash>a8eb012b3a41d26441df76e94cb68f71</hash></folder> <folder><path>C:\ProgramData\Conduit\IE</path><vendor>PUP.Optional.Conduit.A</vendor><action>success</action><hash>96fdfb317dfe5dd943517ee1c83aa060</hash></folder> <folder><path>C:\Program Files (x86)\Plus-HD-3.8</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></folder> <folder><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\PriceMeterUpdater</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>454e1f0d7dfe5cdac07773f327dba45c</hash></folder> <folder><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\PriceMeterUpdater\UpdateProc</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>454e1f0d7dfe5cdac07773f327dba45c</hash></folder> <folder><path>C:\Program Files (x86)\PriceMeterLiveUpdate</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>delete-on-reboot</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></folder> <folder><path>C:\Program Files (x86)\PriceMeterLiveUpdate\CrashReports</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></folder> <folder><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>delete-on-reboot</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></folder> <folder><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>delete-on-reboot</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></folder> <folder><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Download</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></folder> <folder><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Install</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></folder> <folder><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Offline</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></folder> <folder><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Offline\{34BE3099-740D-44EC-9F56-46A01F0AC703}</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></folder> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\File Scout\filescout.exe</path><vendor>PUP.Optional.FileScout.A</vendor><action>success</action><hash>365daf7dbbc0231322aee51db150ea16</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\iLividSetup-r1228-n-bc.exe</path><vendor>PUP.Optional.Bandoo</vendor><action>success</action><hash>662d8e9e700bf5417039fd07ad5436ca</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\Java.exe</path><vendor>PUP.Optional.BundleInstaller.A</vendor><action>success</action><hash>eca7cb61215a3ff7e4d24defd130af51</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\Java7.exe</path><vendor>Trojan.Dropper.FJ</vendor><action>success</action><hash>187b6fbd0c6f50e6d23618121ae6ee12</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\Player-Chrome.exe</path><vendor>PUP.Optional.OptimumInstaller.A</vendor><action>success</action><hash>f1a2f13be398b185a70a30186f928a76</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\rcpsetupmapp3_mapp31518191 (1).exe</path><vendor>PUP.Optional.RegCleanerPro</vendor><action>success</action><hash>336059d3c7b4ef47717219ecb24fb44c</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\rcpsetupmapp3_mapp31518191.exe</path><vendor>PUP.Optional.RegCleanerPro</vendor><action>success</action><hash>2b688ca0c4b75dd9f7ec699c55acbd43</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\Setup (1).exe</path><vendor>PUP.Optional.MSILLauncher.A</vendor><action>success</action><hash>5b386fbd4338ed4951a7d535bf42728e</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\Setup (2).exe</path><vendor>PUP.Optional.MSILLauncher.A</vendor><action>success</action><hash>d2c1b8740f6c2511ec0c15f53fc233cd</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\MyPhoneExplorer_Setup_1.8.5.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>0b88f23aa2d91224a7facb81d1330af6</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\setup (3).exe</path><vendor>PUP.Optional.OutBrowse</vendor><action>success</action><hash>4a494ede90eb70c622298637976c35cb</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\setup (4).exe</path><vendor>PUP.Optional.OutBrowse</vendor><action>success</action><hash>6e25bd6fbebd58decd7e6459f80bfc04</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\setup (5).exe</path><vendor>PUP.Optional.OutBrowse</vendor><action>success</action><hash>a1f244e8bcbfff3789c23c8123e0f709</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\setup (6).exe</path><vendor>PUP.Optional.OutBrowse</vendor><action>success</action><hash>dbb859d3007bb3834a014a738d7607f9</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\SoftonicDownloader_fuer_malwarebytes-anti-malware.exe</path><vendor>PUP.Optional.Softonic.A</vendor><action>success</action><hash>d6bdd25a8eed7abc9276c3588e7348b8</hash></file> <file><path>C:\Users\Marcus Vogelgsang\Downloads\Babylon9_setup.exe</path><vendor>PUP.Optional.Babylon.A</vendor><action>success</action><hash>543fc666344790a605b40816857b0000</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Local\DownloadGuide\mconduitinstaller.exe</path><vendor>PUP.Optional.Conduit.A</vendor><action>success</action><hash>b2e1e24aabd058de1bb9e43a5aa6936d</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Local\DownloadGuide\plus-hd-3-8.exe</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>f69d9993ee8dd95d889f8994ef12d927</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Local\DownloadGuide\wajam_download.exe</path><vendor>PUP.Optional.Wajam</vendor><action>success</action><hash>0093ab81176451e5025f66b8bd43b749</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Local\DownloadGuide\Offers\hometab.exe</path><vendor>PUP.Optional.HomeTab.A</vendor><action>success</action><hash>870cfa328eed1323970d33dcec15be42</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Local\DownloadGuide\Offers\plus-hd-3-8.exe</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>415243e96f0c50e6ab7c70ad37cafb05</hash></file> <file><path>C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1e75d25a6d0e62d41cbe482959a93fc1</hash></file> <file><path>C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>d6bdc765c3b8211507d31f52a35f37c9</hash></file> <file><path>C:\Windows\System32\roboot64.exe</path><vendor>PUP.Optional.PCPerformer.A</vendor><action>success</action><hash>e0b3a686a1da25118e856b0ee31f8e72</hash></file> <file><path>C:\Program Files (x86)\Mozilla Firefox\searchplugins\Web Search.xml</path><vendor>PUP.Optional.SearchCertifiedTB.A</vendor><action>success</action><hash>eba81f0dea914ceaa1cb057647bbb050</hash></file> <file><path>C:\ProgramData\IBUpdaterService\repository.xml</path><vendor>Adware.InstallBrain</vendor><action>success</action><hash>91024ddf36450630e071d798af5409f7</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\SpeedAnalysis2\speedanalysis.crx</path><vendor>PUP.Optional.SpeedAnalysis.A</vendor><action>success</action><hash>1f74f7350873e650732d9bf8b25103fd</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\speedanalysis.ico</path><vendor>PUP.Optional.SpeedAnalysis2.A</vendor><action>success</action><hash>b9dac26a88f3de58d8ac1086887b6898</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>delete-on-reboot</action><hash>5f340e1e9fdce452b22410612ad803fd</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\OpenCandy\787794313D9E4C4F8F476AC981F509E6\TuneUpUtilities2013_2200218_de-DE.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ff945ecec8b3be78798f223dc33ffd03</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\OpenCandy\9F712565036A4067B138BE468BAA59A7\spotflux-latestPC.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ff945ecec8b3be78798f223dc33ffd03</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\OpenCandy\AD2F533A6DC34439AE2E5402F29BDFB6\TuneUpUtilities2013_2200218_de-DE.exe</path><vendor>PUP.Optional.OpenCandy</vendor><action>success</action><hash>ff945ecec8b3be78798f223dc33ffd03</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\File Scout\uninst.exe</path><vendor>PUP.Optional.FileScout.A</vendor><action>success</action><hash>a8eb012b3a41d26441df76e94cb68f71</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\39030.crx</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\background.html</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\Installer.log</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\Plus-HD-3.8-bg.exe</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\Plus-HD-3.8-buttonutil.dll</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\Plus-HD-3.8-buttonutil.exe</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\Plus-HD-3.8-buttonutil64.dll</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\Plus-HD-3.8-buttonutil64.exe</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\Plus-HD-3.8-helper.exe</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\Plus-HD-3.8.ico</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\Uninstall.exe</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Program Files (x86)\Plus-HD-3.8\utils.exe</path><vendor>PUP.Optional.PlusHD.A</vendor><action>success</action><hash>2e651d0f007b270f8f9d6105d1310af6</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\PriceMeterUpdater\UpdateProc\config.dat</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>454e1f0d7dfe5cdac07773f327dba45c</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\PriceMeterUpdater\UpdateProc\info.dat</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>454e1f0d7dfe5cdac07773f327dba45c</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\PriceMeterUpdater\UpdateProc\STTL.DAT</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>454e1f0d7dfe5cdac07773f327dba45c</hash></file> <file><path>C:\Users\Marcus Vogelgsang\AppData\Roaming\PriceMeterUpdater\UpdateProc\TTL.DAT</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>454e1f0d7dfe5cdac07773f327dba45c</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_de.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_el.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_en-GB.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_en.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_es-419.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_es.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_et.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fa.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fi.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fil.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fr.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_gu.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hi.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hr.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hu.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_id.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_it.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_iw.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ja.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_kn.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ko.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_lt.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_lv.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ml.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_mr.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ms.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_nl.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_no.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pl.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pt-BR.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pt-PT.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ro.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdate.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>delete-on-reboot</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_am.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ar.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_bg.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_bn.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ca.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_cs.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sk.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sl.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sr.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sv.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sw.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ta.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_te.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_th.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_tr.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_uk.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ur.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_vi.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_zh-CN.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_zh-TW.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdate.exe</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateBroker.exe</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateHandler.exe</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateHelper.msi</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateOnDemand.exe</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\psmachine.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\psuser.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_da.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_is.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> <file><path>C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ru.dll</path><vendor>PUP.Optional.PriceMeter.A</vendor><action>success</action><hash>1d762705ef8c211555e33c2a689a30d0</hash></file> </items> </mbam-log> |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=74bb930daae8f34d82fb9fe9d572202f # engine=17967 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-21 06:32:49 # local_time=2014-04-21 08:32:49 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 71 76 287718 287737 0 0 # compatibility_mode=5893 16776573 100 94 125462 149735019 0 0 # scanned=214377 # found=5 # cleaned=0 # scan_time=5374 sh=813F99C162730B22A391A287FA9BA6A954C2977C ft=1 fh=545f8627a3352333 vn="a variant of Win32/Adware.Yontoo.A application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Yontoo\YontooIEClient.dll.vir" sh=AEC860E4CDE64D747F215B83C8DE70EE0EBCB3A0 ft=1 fh=cde73a4bb58c0fe9 vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir" sh=FDF652F803592E6840E076A89A19BF655686B8A8 ft=1 fh=de76e936397b25d2 vn="a variant of Win32/Adware.Yontoo.B application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll.vir" sh=12A9313D86CC0E3AF8D9EE8CC318DE4C9A7C3974 ft=0 fh=0000000000000000 vn="LNK/Agent.AK trojan" ac=I fn="C:\Users\Marcus Vogelgsang\Documents\Peter Orth\Abschluss - Jahres Ordner Motodrom ab 2005-\Motordrom2005.lnk" sh=DFB417DF1C57E81CC616AC37AD86FE95B3567180 ft=0 fh=0000000000000000 vn="Win32/TrojanDownloader.Wauchos.A trojan" ac=I fn="C:\Users\Marcus Vogelgsang\Dropbox\.dropbox.cache\2014-04-18\Rechnung (deleted 2eac846de2de1403b59acbd31c2174c6).zip" Results of screen317's Security Check version 0.99.81 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` AVG PC TuneUp 2014 (de-DE) Java(TM) 6 Update 37 Java 7 Update 51 Adobe Flash Player 12.0.0.77 Adobe Reader XI Mozilla Thunderbird (24.4.0) Google Chrome 34.0.1847.116 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Google Chrome Application AvastSvc.exe -?- AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-04-2014 01 --- --- --- --- --- --- Also die Verlinkungen auf den Sticks sind immer noch da!!! |
Die Verknüpfungen sind in ner Minute erledigt, erstmal muss die Kiste sauber werden. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
|
Er sagt mir das er die Fixlist.txt nicht findet. |
Zitat:
|
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-04-2014 Ran by Marcus Vogelgsang at 2014-04-24 08:33:18 Run:1 Running from C:\Users\Marcus Vogelgsang\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\.DEFAULT\...\RunOnce: [SpUninstallDeleteDir] - rmdir /s /q "\SearchProtect" HKU\S-1-5-21-3727746948-312616605-306874443-1001\...\Run: [Microsoft] => wscript.exe //B "C:\Users\Marcus Vogelgsang\AppData\Roaming\Microsoft.vbe" C:\Users\Marcus Vogelgsang\AppData\Roaming\Microsoft.vbe ***************** HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\IsMyWinLockerReboot => Value deleted successfully. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce\\SpUninstallDeleteDir => Value deleted successfully. HKU\S-1-5-21-3727746948-312616605-306874443-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Microsoft => Value deleted successfully. Could not move "C:\Users\Marcus Vogelgsang\AppData\Roaming\Microsoft.vbe" => Scheduled to move on reboot. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-04-24 08:34:43)<= C:\Users\Marcus Vogelgsang\AppData\Roaming\Microsoft.vbe => Is moved successfully. ==== End of Fixlog ==== |
reboot, frisches FRST log bitte. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 22:23 Uhr. |
Copyright ©2000-2025, Trojaner-Board