Hi,
ich hab alles wie gefordert ausgeführt und folgendes bekommen: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 23.04.2014
Suchlauf-Zeit: 16:35:31
Logdatei: suchlaufprotokoll.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.23.06
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Lars Brauer
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 284670
Verstrichene Zeit: 18 Min, 37 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, 1500, Löschen bei Neustart, [f50bd62a926ea65a918aa5b7b74a8080]
PUP.Optional.ReMarkit.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe, 1628, Löschen bei Neustart, [0cf4fa06af51986865d93f378a7856aa]
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQLOWw.exe, 360, Löschen bei Neustart, [8878e31d5ea233cd72fb81e609f9ec14]
Adware.EoRezo, C:\Users\Lars Brauer\AppData\Local\fst_de_1\upfst_de_1.exe, 2824, Löschen bei Neustart, [a0602cd4e9179769a70d82e80cf61fe1]
Module: 1
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.dll, Löschen bei Neustart, [8878e31d5ea233cd72fb81e609f9ec14],
Registrierungsschlüssel: 42
PUP.Optional.WpManager, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wpm, In Quarantäne, [f50bd62a926ea65a918aa5b7b74a8080],
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, In Quarantäne, [07f97e822ed22dd3e4e8143d1de48e72],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [20e0a35d29d73dc344e32eeb53afa55b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [20e0a35d29d73dc344e32eeb53afa55b],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A69A551A-1AAE-4B67-8C2E-52F8B8A19504}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{E1EF512D-604D-4776-AF11-410704DA1911}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4CCDB009-EC10-4696-9991-419D39D3D1DD}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7C2D1DAA-5535-4742-B248-AD8CAE93D75A}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4CCDB009-EC10-4696-9991-419D39D3D1DD}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7C2D1DAA-5535-4742-B248-AD8CAE93D75A}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E1EF512D-604D-4776-AF11-410704DA1911}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\CLASSES\SuperfishIEAddon.ExtentionUI.1, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\CLASSES\SuperfishIEAddon.ExtentionUI, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SuperfishIEAddon.ExtentionUI, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SuperfishIEAddon.ExtentionUI.1, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A69A551A-1AAE-4B67-8C2E-52F8B8A19504}, Löschen bei Neustart, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\{A69A551A-1AAE-4B67-8C2E-52F8B8A19504}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\CLASSES\SuperfishIEAddon.BHObject.1, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\CLASSES\SuperfishIEAddon.BHObject, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SuperfishIEAddon.BHObject, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SuperfishIEAddon.BHObject.1, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SharedBHO.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}, Löschen bei Neustart, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [07f9c8385ea2e11fd48f82f37989cc34],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [8779748cb14fdd23c79ca8cd689ad22e],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [8e7240c047b9be426adf01a3be4547b9],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\MediaPlayerplus, In Quarantäne, [d22ef40c9a6605fb88e45a1a9f63cc34],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [ec146d9333cdf40c78ccff76b34f24dc],
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\WOW6432NODE\FREE_SOFT_TODAY\fst_de_1, In Quarantäne, [e31d2cd4639dfe02a7557feecb37e41c],
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pelmeidfhdlhlbjimpabfcbnnojbboma, In Quarantäne, [d32d867ae818e7191ae6373f5ea4a65a],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [9a664ab625db619f99ca690c9f63c13f],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [659b32ce966ae61a21427ef730d2619f],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [827e37c90df3916f8dbc9212da29d52b],
PUP.Optional.ReMarkit.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Re-markit, In Quarantäne, [0cf4fa06af51986865d93f378a7856aa],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, Löschen bei Neustart, [d729e31d1ce46f917dd8b8e01ee5cd33],
PUP.Optional.SavingsSidekick.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Savings Sidekick, Löschen bei Neustart, [b848d22e0cf4da263792d4a80af8cc34],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, Löschen bei Neustart, [798729d7b05013ed87ddd89db54d3dc3],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, Löschen bei Neustart, [4eb2dd239c64ac545c0891e4cf33629e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Freeven, Löschen bei Neustart, [47b99e62f40cf30df2d99adee2207888],
PUP.Optional.Qone8, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [52ae46ba28d8ad5384c4efb5af546b95],
PUP.Optional.BProtector.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, Löschen bei Neustart, [d52b1be518e8e719a90a73284bb82dd3],
Registrierungswerte: 7
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com, In Quarantäne, [4bb5c937aa56bb45bb46fb7b25dd3ec2]
PUP.Optional.WpManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WPM|ImagePath, C:\ProgramData\WPM\wprotectmanager.exe -service, In Quarantäne, [b24e05fbc53bc33d86a1456433d024dc]
PUP.BProtector, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, Löschen bei Neustart, [9d63c838e31d639d8bcc6434e91ad42c],
PUP.BProtector, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}, Löschen bei Neustart, [b848728e28d8798764f482165da67d83]
PUM.Bad.Proxy, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:13828, Löschen bei Neustart, [5ba5e917a7592bd5402c426f7c874db3]
PUP.Optional.SpecialSavings.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|specialsavings@superfish.com, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles/croh3rmo.default\extensions\specialsavings@superfish.com, Löschen bei Neustart, [2cd4f50b738df0109a3bd89baf5345bb]
Adware.EoRezo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|upfst_de_1.exe, C:\Users\Lars Brauer\AppData\Local\fst_de_1\upfst_de_1.exe -runonce, In Quarantäne, [a0602cd4e9179769a70d82e80cf61fe1]
Registrierungsdaten: 7
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB),Ersetzt,[d42c9e62f60aee123d80101214f0a55b]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[59a7ff01b54ba45cbb33ce5ee321d52b]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB&q={searchTerms}),Ersetzt,[1fe1da263dc39e621e9d7ba70df7a15f]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB),Ersetzt,[d62aaa56e917827e09b0b46eac58db25]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB),Ersetzt,[ed130af6817f49b7c9f438eab94bbc44]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[ea16d22ed32dc33dc628062613f1de22]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-3413570040-2433938332-2956246672-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB),Löschen bei Neustart,[50b057a98d73867a942a00220df77b85]
Ordner: 85
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, In Quarantäne, [c33d639d23ddd9277e4c0063966c9070],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [c33d639d23ddd9277e4c0063966c9070],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\extensionCode, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\lib, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\defaults, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\defaults\preferences, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\locale, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\locale\en-US, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft, Löschen bei Neustart, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\include, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\include\tools, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\en, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\en-US, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\es, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\es-419, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr-BE, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr-CA, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr-CH, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr-LU, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\it, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\it-CH, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\pl, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\pt-BR, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\ru, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\ru-MO, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\tr, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\vi, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\zh-CN, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\zh-TW, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\weather, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\defaults, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\defaults\preferences, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\images, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome\superfish, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome\superfish\content, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome\superfish\skin, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\components, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\defaults, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\defaults\preferences, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Program Files (x86)\SpecialSavings, In Quarantäne, [d729ec147f81619fd3fba9bf5ea4aa56],
Adware.EoRezo, C:\Users\Lars Brauer\AppData\Local\fst_de_1, Löschen bei Neustart, [a0602cd4e9179769a70d82e80cf61fe1],
Adware.EoRezo, C:\Users\Lars Brauer\AppData\Local\fst_de_1\Download, In Quarantäne, [a0602cd4e9179769a70d82e80cf61fe1],
Adware.EoRezo, C:\Program Files (x86)\fst_de_1, In Quarantäne, [42be27d99a66aa56d2e50862c43e768a],
PUP.Optional.TheBestDeals.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc, In Quarantäne, [20e00000f30ddd237440b7b56b9755ab],
PUP.Optional.TheBestDeals.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0, In Quarantäne, [20e00000f30ddd237440b7b56b9755ab],
Dateien: 217
PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, Löschen bei Neustart, [f50bd62a926ea65a918aa5b7b74a8080],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, In Quarantäne, [07f97e822ed22dd3e4e8143d1de48e72],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [20e0a35d29d73dc344e32eeb53afa55b],
PUP.Optional.SharedBHO.A, C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll, In Quarantäne, [09f7a858d52bf10f9c2752c53cc6aa56],
PUP.Optional.SupTab.A, C:\Users\Lars Brauer\AppData\Roaming\SupTab\SupTab.dll, In Quarantäne, [fe02fb05af516997ad9dce67fc04aa56],
PUP.Optional.OutBrowse, C:\Users\Lars Brauer\Downloads\setup.exe, In Quarantäne, [8e725ea208f88d7312895967659eb24e],
PUP.Optional.BundleInstaller.A, C:\Users\Lars Brauer\Downloads\Java.exe, In Quarantäne, [956b22de54ac6f910be064dc768bd12f],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\b006f55f-fff4-48a1-9ec3-9d911621410a-5.job, In Quarantäne, [ac54689829d7728ee4f91e55788ae41c],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx, In Quarantäne, [97692ed22cd4709031e9acc8c14112ee],
PUP.Optional.WebsSearches.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml, In Quarantäne, [629ebc446f91e41ce75f5520857df30d],
PUP.Optional.ReMarkIt.A, C:\Windows\Tasks\Re-markit Update.job, In Quarantäne, [f709718fb7497789b48b82f49d6551af],
PUP.Optional.ReMarkIt.A, C:\Windows\Tasks\Re-markit_wd.job, In Quarantäne, [ae5242be8a769868043b36407f8329d7],
PUP.Optional.BProtector.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\bProtector_extensions.sqlite, In Quarantäne, [42be18e8fc0406fa3ec1b5c1c53d21df],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [54acc8389e62b74963a07e0112f08878],
PUP.Optional.ReMarkit.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.exe, Löschen bei Neustart, [0cf4fa06af51986865d93f378a7856aa],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [c33d639d23ddd9277e4c0063966c9070],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome.manifest, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\install.rdf, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\background.html, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\browser.xul, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\crossrider.js, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\crossriderapi.js, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\CrossriderEXT.js, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\dialog.js, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\options.js, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\options.xul, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\search_dialog.xul, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\update.html, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\extensionCode\backgroundCode.js, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\extensionCode\pageCode.js, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\chrome\content\lib\reports.js, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\defaults\preferences\prefs.js, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\locale\en-US\translations.dtd, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\button1.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\button2.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\button3.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\button4.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\button5.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\crossrider_statusbar.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\icon128.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\icon16.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\icon24.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\icon48.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\panelarrow-up.png, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\popup.css, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\popup.html, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\popup_binding.xml, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\skin.css, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.CrossFire.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\crossriderapp5060@crossrider.com\skin\update.css, In Quarantäne, [2bd5c937669abb45c20c7fe740c207f9],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\158.crx, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\158.dat, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\158.xpi, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\a.db, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\b.db, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL.exe, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.bin, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.dll, Löschen bei Neustart, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQL158.ini, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Re-markitfQLOWw.exe, Löschen bei Neustart, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Sqlite3.dll, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit-soft\Uninstall.exe, In Quarantäne, [8878e31d5ea233cd72fb81e609f9ec14],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome.manifest, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\install.rdf, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\index.html, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\quick_start.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\quick_start.xul, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\include\speed_dial.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\include\tools\about_blank_hook.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\include\tools\misc.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\include\tools\popup_image_helper.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\include\tools\urlrequestor.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\js\common.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\js\doT.min.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\js\ga.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\js\jquery-2.1.0.min.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\js\jquery.autocomplete.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\js\js.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\content\js\xagainit.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\en\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\en-US\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\es\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\es-419\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr-BE\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr-CA\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr-CH\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\fr-LU\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\it\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\it-CH\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\pl\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\pt-BR\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\ru\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\ru-MO\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\tr\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\vi\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\zh-CN\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\locale\zh-TW\locale.properties, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\arrow.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\default_add_logo.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\default_add_logo_hover.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\default_logo.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\googlelogo.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\googlelogo2.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\google_trends.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\icon.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\loading.gif, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\logo.ico, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\logo.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\logo32.ico, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\style.css, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\chrome\skin\weather\0.png, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\defaults\preferences\fvd.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\addonmanager.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\aes.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\config.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\dialogs.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\last_tab.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\misc.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\properties.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\remoterequest.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\restoreprefs.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.QuickStart.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\quick_start@gmail.com\modules\settings.js, In Quarantäne, [966aa8584ab62ed2faa31552d72bf10f],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\92.json, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\uninstallDlg.xml, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\UninstallManager.exe, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\images\bg1.png, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\images\button1.png, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\images\checked.png, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\images\close.png, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\images\min.png, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\images\Thumbs.db, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\webssearches\images\unchecked.png, In Quarantäne, [738d3bc5000013ed0ff05215f60c966a],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome.manifest, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\install.rdf, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\Settings.xml, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\sfStatistics.xml, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome\superfish\content\about-showme.xul, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome\superfish\content\status-bar-superfish.js, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome\superfish\content\status-bar-superfish.xul, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome\superfish\skin\specialsavings_logo.png, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome\superfish\skin\superfish_logo.png, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\chrome\superfish\skin\Thumbs.db, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\components\nsSuperfishComponent.js, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\extensions\specialsavings@superfish.com\defaults\preferences\pref.js, In Quarantäne, [41bf5ba5d62ab947e8e54e1a748e21df],
PUP.Optional.SpecialSavings.A, C:\Program Files (x86)\SpecialSavings\Settings.xml, In Quarantäne, [d729ec147f81619fd3fba9bf5ea4aa56],
PUP.Optional.SpecialSavings.A, C:\Program Files (x86)\SpecialSavings\Uninstall.exe, In Quarantäne, [d729ec147f81619fd3fba9bf5ea4aa56],
Adware.EoRezo, C:\Users\Lars Brauer\AppData\Local\fst_de_1\upfst_de_1.cyp, In Quarantäne, [a0602cd4e9179769a70d82e80cf61fe1],
Adware.EoRezo, C:\Users\Lars Brauer\AppData\Local\fst_de_1\upfst_de_1.exe, Löschen bei Neustart, [a0602cd4e9179769a70d82e80cf61fe1],
Adware.EoRezo, C:\Users\Lars Brauer\AppData\Local\fst_de_1\user_profil.cyp, In Quarantäne, [a0602cd4e9179769a70d82e80cf61fe1],
Adware.EoRezo, C:\Users\Lars Brauer\AppData\Local\fst_de_1\Download\majfst.exe, In Quarantäne, [a0602cd4e9179769a70d82e80cf61fe1],
Adware.EoRezo, C:\Program Files (x86)\fst_de_1\unins000.dat, In Quarantäne, [42be27d99a66aa56d2e50862c43e768a],
Adware.EoRezo, C:\Program Files (x86)\fst_de_1\unins000.exe, In Quarantäne, [42be27d99a66aa56d2e50862c43e768a],
Adware.EoRezo, C:\Program Files (x86)\fst_de_1\unins000.msg, In Quarantäne, [42be27d99a66aa56d2e50862c43e768a],
PUP.Optional.TheBestDeals.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\b.html, In Quarantäne, [20e00000f30ddd237440b7b56b9755ab],
PUP.Optional.TheBestDeals.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\b.js, In Quarantäne, [20e00000f30ddd237440b7b56b9755ab],
PUP.Optional.TheBestDeals.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\c.js, In Quarantäne, [20e00000f30ddd237440b7b56b9755ab],
PUP.Optional.TheBestDeals.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\icon128.png, In Quarantäne, [20e00000f30ddd237440b7b56b9755ab],
PUP.Optional.TheBestDeals.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\icon16.png, In Quarantäne, [20e00000f30ddd237440b7b56b9755ab],
PUP.Optional.TheBestDeals.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\icon48.png, In Quarantäne, [20e00000f30ddd237440b7b56b9755ab],
PUP.Optional.TheBestDeals.A, C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikcggonfhgaingjbhjanbibmlfeomooc\1.158.0.0_0\manifest.json, In Quarantäne, [20e00000f30ddd237440b7b56b9755ab],
PUP.Optional.WebsSearches.A, C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB");), Ersetzt,[3bc54bb54fb145bb2f71075042c2be42]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.201 - Bericht erstellt am 23/04/2014 um 16:50:41
# Aktualisiert 22/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Lars Brauer - LARSBRAUER-PC
# Gestartet von : C:\Users\Lars Brauer\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\free_soft_today
Ordner Gelöscht : C:\Program Files (x86)\MediaPlayerplus
Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin
Ordner Gelöscht : C:\Users\Lars Brauer\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmijdhkcgeclpfjmibnginbbkfcbpep
Datei Gelöscht : C:\Users\Lars Brauer\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Users\Lars Brauer\Desktop\Continue VuuPC Installation.lnk
Datei Gelöscht : C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\searchplugins\bProtect.xml
Datei Gelöscht : C:\Windows\System32\Tasks\bProtector
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Lars Brauer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Lars Brauer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Lars Brauer\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{372479DD-B552-F0A8-F0E5-EEEEA6602285}]
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{B64982B1-D112-42B5-B1E4-D3867C4533F8}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dhdepfaagokllfmhfbcfmocaeigmoebo
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\icmijdhkcgeclpfjmibnginbbkfcbpep
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Savings Sidekick_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Savings Sidekick_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_minecraft_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_minecraft_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220022502260}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{33333333-3333-3333-3333-330033503360}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066506660}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077507760}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F994E0D9-8335-48F1-99C2-A712C21F8D5F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066506660}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{77777777-7777-7777-7777-770077507760}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\Tutorials
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SpecialSavings
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\Software\supTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\Tutorials
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "webssearches");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "webssearches");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hp&ts=1398147453&from=tugs&uid=ST500DM002-1BD142_Z2A99QTBXXXXZ2A99QTB");
*************************
AdwCleaner[R0].txt - [6597 octets] - [23/04/2014 16:46:57]
AdwCleaner[S0].txt - [5526 octets] - [23/04/2014 16:50:41]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5586 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Lars Brauer on 23.04.2014 at 17:03:37,03
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9
Successfully deleted: [Registry Key] HKEY_USERS\.DEFAULT\Software\bProtector
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Lars Brauer\AppData\Roaming\mozilla\firefox\profiles\croh3rmo.default\minidumps [683 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.04.2014 at 17:07:19,63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014
Ran by Lars Brauer (administrator) on LARSBRAUER-PC on 23-04-2014 17:13:34
Running from C:\Users\Lars Brauer\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\D-Link\DWA-140 revB\ANIWConnService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Vtune\TBPANEL.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
() C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Bogdan Sharkov) C:\Program Files (x86)\Clownfish\Clownfish.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe
(D-Link Corp.) C:\Program Files (x86)\D-Link\DWA-140 revB\AirNCFG.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_77.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor)
HKLM-x32\...\Run: [D-Link D-Link DWA-140] => C:\Program Files (x86)\D-Link\DWA-140 revB\AirNCFG.exe [1074496 2011-06-29] (D-Link Corp.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-04-15] (LogMeIn Inc.)
HKU\S-1-5-21-3413570040-2433938332-2956246672-1000\...\Run: [TBPanel] => C:\Program Files (x86)\Vtune\TBPanel.exe [2240512 2011-06-02] ()
HKU\S-1-5-21-3413570040-2433938332-2956246672-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1826496 2014-04-22] (Valve Corporation)
HKU\S-1-5-21-3413570040-2433938332-2956246672-1000\...\Run: [Pando Media Booster] => C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe [3093624 2012-11-27] ()
HKU\S-1-5-21-3413570040-2433938332-2956246672-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3413570040-2433938332-2956246672-1000\...\Run: [Clownfish] => C:\Program Files (x86)\Clownfish\Clownfish.exe [1313536 2014-04-01] (Bogdan Sharkov)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC5D05F9A06C1CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 62.109.121.2 62.109.121.1
FireFox:
========
FF ProfilePath: C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default
FF NewTab: chrome://quick_start/content/index.html
FF SearchEngineOrder.user_pref("browser.search.order.1", "");: user_pref("browser.search.order.1", "");
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/JavaPlugin,version=10.5.0 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: SearchGBY - C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\Extensions\plugin@searchgby.com [2013-07-17]
FF Extension: searchOnTab - C:\Users\Lars Brauer\AppData\Roaming\Mozilla\Firefox\Profiles\croh3rmo.default\Extensions\searchontab@sogame.cat.xpi [2011-09-23]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2011-09-23]
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (Skype Click to Call) - C:\Users\Lars Brauer\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-12-12]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2012-01-17]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 D_Link_DWA-140_WPS; C:\Program Files (x86)\D-Link\DWA-140 revB\ANIWConnService.exe [53248 2010-07-12] ()
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [377616 2014-04-08] (LogMeIn, Inc.)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
R1 anodlwf; C:\Windows\System32\DRIVERS\anodlwfx.sys [15872 2011-02-21] ()
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] ()
S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [303616 2011-10-19] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [35328 2011-10-19] ()
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
S3 netr28ux; C:\Windows\System32\DRIVERS\Dnetr28ux.sys [1617472 2011-04-28] (Ralink Technology Corp.)
S3 TBPanel; No ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-23 17:07 - 2014-04-23 17:07 - 00000980 _____ () C:\Users\Lars Brauer\Desktop\JRT.txt
2014-04-23 17:03 - 2014-04-23 17:03 - 00000000 ____D () C:\Windows\ERUNT
2014-04-23 17:02 - 2014-04-23 17:02 - 01016261 _____ (Thisisu) C:\Users\Lars Brauer\Desktop\JRT.exe
2014-04-23 16:52 - 2014-04-23 16:52 - 00005682 _____ () C:\Users\Lars Brauer\Desktop\AdwCleaner[S0].txt
2014-04-23 16:46 - 2014-04-23 16:50 - 00000000 ____D () C:\AdwCleaner
2014-04-23 16:44 - 2014-04-23 16:44 - 01345299 _____ () C:\Users\Lars Brauer\Desktop\adwcleaner.exe
2014-04-23 16:41 - 2014-04-23 16:41 - 00067670 _____ () C:\Users\Lars Brauer\Desktop\mbam.txt
2014-04-23 16:14 - 2014-04-23 16:52 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 16:14 - 2014-04-23 16:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-23 16:14 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-23 16:14 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-23 16:12 - 2014-04-23 16:13 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lars Brauer\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-23 00:10 - 2014-04-23 00:10 - 00022230 _____ () C:\ComboFix.txt
2014-04-23 00:03 - 2014-04-23 00:10 - 00000000 ____D () C:\Qoobox
2014-04-23 00:03 - 2014-04-23 00:09 - 00000000 ____D () C:\Windows\erdnt
2014-04-23 00:03 - 2014-04-23 00:03 - 00000000 ___RD () C:\Users\Lars Brauer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-23 00:03 - 2014-04-23 00:03 - 00000000 ___RD () C:\Users\Lars Brauer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-23 00:03 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-23 00:03 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-23 00:03 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-23 00:03 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-23 00:03 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-23 00:03 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-23 00:03 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-23 00:03 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-22 23:57 - 2014-04-22 23:57 - 05196870 ____R (Swearware) C:\Users\Lars Brauer\Desktop\ComboFix.exe
2014-04-22 10:36 - 2014-04-23 17:13 - 00011655 _____ () C:\Users\Lars Brauer\Desktop\FRST.txt
2014-04-22 10:36 - 2014-04-23 17:13 - 00000000 ____D () C:\FRST
2014-04-22 10:36 - 2014-04-22 10:37 - 00021808 _____ () C:\Users\Lars Brauer\Desktop\Addition.txt
2014-04-22 10:35 - 2014-04-22 10:35 - 02061312 _____ (Farbar) C:\Users\Lars Brauer\Desktop\FRST64.exe
2014-04-22 08:17 - 2014-04-23 16:59 - 00000000 ____D () C:\Program Files (x86)\HQ-V-Pro-1.91
2014-04-22 08:17 - 2014-04-22 08:17 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-04-22 08:12 - 2014-04-22 08:12 - 00001707 _____ () C:\Users\Lars Brauer\Desktop\Continue FLV Player.lnk
2014-04-19 09:07 - 2014-04-19 09:08 - 01070840 _____ (Solid State Networks) C:\Users\Lars Brauer\Downloads\install_flashplayer13x32au_ltr5x64d_awc_aih.exe
2014-04-17 21:46 - 2014-04-17 21:46 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-04-10 00:36 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-10 00:36 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-10 00:36 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-10 00:36 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-10 00:36 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-10 00:36 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-10 00:36 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-10 00:36 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-10 00:36 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-10 00:36 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-10 00:36 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-10 00:36 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-10 00:36 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-10 00:36 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-10 00:36 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-10 00:36 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-10 00:36 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-10 00:36 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-10 00:36 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-10 00:36 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-10 00:36 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-10 00:36 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-10 00:36 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-10 00:36 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-10 00:36 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-10 00:36 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-10 00:36 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-10 00:36 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-10 00:36 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-10 00:36 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-10 00:36 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-10 00:36 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-10 00:36 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-10 00:36 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-10 00:36 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-10 00:36 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-10 00:36 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-10 00:36 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-10 00:36 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-10 00:36 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-10 00:36 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-10 00:36 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-10 00:36 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-10 00:36 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-10 00:36 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-10 00:36 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-10 00:36 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-10 00:36 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-09 14:01 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 14:01 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 14:01 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 14:01 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 14:01 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 14:01 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 14:01 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 14:01 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 14:01 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 14:01 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 14:01 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 14:01 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 14:01 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 14:01 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 14:01 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 14:01 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 14:01 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-02 14:24 - 2014-04-02 14:24 - 00000000 ____D () C:\Users\Lars Brauer\Documents\Skype Voice Records
2014-04-02 14:24 - 2014-04-02 14:24 - 00000000 ____D () C:\Users\Lars Brauer\Documents\Clownfish Avatars
2014-04-02 14:21 - 2014-04-02 14:21 - 00681424 _____ (Shark Labs) C:\Users\Lars Brauer\Downloads\CFSetup352.exe
2014-04-02 14:21 - 2014-04-02 14:21 - 00001905 _____ () C:\Users\Lars Brauer\Desktop\Clownfish.lnk
2014-04-02 14:21 - 2014-04-02 14:21 - 00000000 ____D () C:\Program Files (x86)\Clownfish
2014-03-26 20:33 - 2014-03-26 20:33 - 00000000 ____D () C:\Users\Lars Brauer\AppData\Local\Skype
==================== One Month Modified Files and Folders =======
2014-04-23 17:13 - 2014-04-22 10:36 - 00011655 _____ () C:\Users\Lars Brauer\Desktop\FRST.txt
2014-04-23 17:13 - 2014-04-22 10:36 - 00000000 ____D () C:\FRST
2014-04-23 17:13 - 2011-09-28 13:26 - 00000000 ____D () C:\Users\Lars Brauer\AppData\Local\PMB Files
2014-04-23 17:07 - 2014-04-23 17:07 - 00000980 _____ () C:\Users\Lars Brauer\Desktop\JRT.txt
2014-04-23 17:07 - 2012-09-20 12:10 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-23 17:03 - 2014-04-23 17:03 - 00000000 ____D () C:\Windows\ERUNT
2014-04-23 17:02 - 2014-04-23 17:02 - 01016261 _____ (Thisisu) C:\Users\Lars Brauer\Desktop\JRT.exe
2014-04-23 16:59 - 2014-04-22 08:17 - 00000000 ____D () C:\Program Files (x86)\HQ-V-Pro-1.91
2014-04-23 16:59 - 2009-07-14 06:45 - 00022080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-23 16:59 - 2009-07-14 06:45 - 00022080 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-23 16:57 - 2011-04-12 09:43 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2014-04-23 16:57 - 2011-04-12 09:43 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2014-04-23 16:57 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-23 16:52 - 2014-04-23 16:52 - 00005682 _____ () C:\Users\Lars Brauer\Desktop\AdwCleaner[S0].txt
2014-04-23 16:52 - 2014-04-23 16:14 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 16:52 - 2012-11-11 17:58 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-04-23 16:52 - 2012-07-12 19:08 - 00000000 ____D () C:\Users\Lars Brauer\AppData\Local\LogMeIn Hamachi
2014-04-23 16:52 - 2011-09-23 17:40 - 00000000 ____D () C:\Users\Lars Brauer\AppData\Roaming\Skype
2014-04-23 16:51 - 2012-09-20 12:10 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-23 16:51 - 2011-09-23 15:55 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-04-23 16:51 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-23 16:51 - 2009-07-14 06:51 - 00227191 _____ () C:\Windows\setupact.log
2014-04-23 16:50 - 2014-04-23 16:46 - 00000000 ____D () C:\AdwCleaner
2014-04-23 16:50 - 2011-09-23 16:30 - 00001282 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-23 16:50 - 2011-09-23 15:19 - 01808559 _____ () C:\Windows\WindowsUpdate.log
2014-04-23 16:44 - 2014-04-23 16:44 - 01345299 _____ () C:\Users\Lars Brauer\Desktop\adwcleaner.exe
2014-04-23 16:41 - 2014-04-23 16:41 - 00067670 _____ () C:\Users\Lars Brauer\Desktop\mbam.txt
2014-04-23 16:38 - 2010-11-21 05:47 - 00248190 _____ () C:\Windows\PFRO.log
2014-04-23 16:37 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Registration
2014-04-23 16:32 - 2013-04-20 17:39 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-23 16:14 - 2014-04-23 16:14 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-23 16:14 - 2012-07-26 21:07 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-23 16:14 - 2012-07-26 21:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-23 16:13 - 2014-04-23 16:12 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Lars Brauer\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-23 10:41 - 2011-09-28 13:26 - 00000000 ____D () C:\ProgramData\PMB Files
2014-04-23 00:10 - 2014-04-23 00:10 - 00022230 _____ () C:\ComboFix.txt
2014-04-23 00:10 - 2014-04-23 00:03 - 00000000 ____D () C:\Qoobox
2014-04-23 00:09 - 2014-04-23 00:03 - 00000000 ____D () C:\Windows\erdnt
2014-04-23 00:09 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-23 00:08 - 2011-09-23 17:40 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-04-23 00:03 - 2014-04-23 00:03 - 00000000 ___RD () C:\Users\Lars Brauer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-23 00:03 - 2014-04-23 00:03 - 00000000 ___RD () C:\Users\Lars Brauer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-04-22 23:57 - 2014-04-22 23:57 - 05196870 ____R (Swearware) C:\Users\Lars Brauer\Desktop\ComboFix.exe
2014-04-22 10:57 - 2012-10-24 18:16 - 00000000 ____D () C:\Users\Lars Brauer\Documents\TmForever
2014-04-22 10:37 - 2014-04-22 10:36 - 00021808 _____ () C:\Users\Lars Brauer\Desktop\Addition.txt
2014-04-22 10:35 - 2014-04-22 10:35 - 02061312 _____ (Farbar) C:\Users\Lars Brauer\Desktop\FRST64.exe
2014-04-22 08:32 - 2013-04-20 17:39 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-22 08:32 - 2012-07-26 23:36 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-22 08:32 - 2011-09-23 16:30 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-22 08:17 - 2014-04-22 08:17 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-04-22 08:17 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-22 08:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-22 08:12 - 2014-04-22 08:12 - 00001707 _____ () C:\Users\Lars Brauer\Desktop\Continue FLV Player.lnk
2014-04-19 09:08 - 2014-04-19 09:07 - 01070840 _____ (Solid State Networks) C:\Users\Lars Brauer\Downloads\install_flashplayer13x32au_ltr5x64d_awc_aih.exe
2014-04-17 21:46 - 2014-04-17 21:46 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2014-04-17 21:46 - 2012-07-12 19:08 - 00000926 _____ () C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
2014-04-15 08:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-10 12:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-10 00:36 - 2013-08-15 18:22 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 00:35 - 2011-09-30 12:01 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-03 22:24 - 2012-04-10 12:52 - 00000000 ____D () C:\Users\Lars Brauer\AppData\Roaming\.minecraft
2014-04-03 09:51 - 2014-04-23 16:14 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-23 16:14 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2012-07-26 21:07 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 14:24 - 2014-04-02 14:24 - 00000000 ____D () C:\Users\Lars Brauer\Documents\Skype Voice Records
2014-04-02 14:24 - 2014-04-02 14:24 - 00000000 ____D () C:\Users\Lars Brauer\Documents\Clownfish Avatars
2014-04-02 14:21 - 2014-04-02 14:21 - 00681424 _____ (Shark Labs) C:\Users\Lars Brauer\Downloads\CFSetup352.exe
2014-04-02 14:21 - 2014-04-02 14:21 - 00001905 _____ () C:\Users\Lars Brauer\Desktop\Clownfish.lnk
2014-04-02 14:21 - 2014-04-02 14:21 - 00000000 ____D () C:\Program Files (x86)\Clownfish
2014-04-01 18:02 - 2011-09-23 16:30 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-01 18:02 - 2011-09-23 16:30 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-31 09:35 - 2010-11-21 05:27 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-29 05:00 - 2011-09-23 16:24 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-26 20:33 - 2014-03-26 20:33 - 00000000 ____D () C:\Users\Lars Brauer\AppData\Local\Skype
2014-03-26 20:32 - 2011-09-23 17:48 - 00000000 ____D () C:\ProgramData\Skype
Some content of TEMP:
====================
C:\Users\Lars Brauer\AppData\Local\Temp\avgnt.exe
C:\Users\Lars Brauer\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-19 10:07
==================== End Of Log ============================ --- --- ---
--- --- ---
Liebe Grüße,
Lerrix |