hallo,
hier die logfiles:
mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 02.06.2014
Suchlauf-Zeit: 20:40:43
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.03.04.09
Rootkit Datenbank: v2014.05.21.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Vicky-PC
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 244460
Verstrichene Zeit: 13 Min, 9 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1108, Löschen bei Neustart, [b0998b74166478be56e42375f0110af6]
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\ExtensionUpdaterService.exe, 2280, Löschen bei Neustart, [0a3f22ddcbaf55e13b4aca7edf2212ee]
Module: 1
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
Registrierungsschlüssel: 109
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [b0998b74166478be56e42375f0110af6],
PUP.Optional.SweetPacks.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Updater By Sweetpacks, In Quarantäne, [0a3f22ddcbaf55e13b4aca7edf2212ee],
PUP.Optional.DealPly.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\dealplylive, In Quarantäne, [d277f00f0971d06613e184da0ff27987],
PUP.Optional.DealPly.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\dealplylivem, In Quarantäne, [d277f00f0971d06613e184da0ff27987],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\APPID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}, In Quarantäne, [56f34db26b0f6ec887d780f49072a957],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [56f34db26b0f6ec887d780f49072a957],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [56f34db26b0f6ec887d780f49072a957],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [56f34db26b0f6ec887d780f49072a957],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [56f34db26b0f6ec887d780f49072a957],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}, In Quarantäne, [56f34db26b0f6ec887d780f49072a957],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{80FABB17-63AF-4655-9F07-B6509EE37AF2}, In Quarantäne, [56f34db26b0f6ec887d780f49072a957],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\APPID\{F48FC5B2-094A-44C7-B48C-289738C9582D}, In Quarantäne, [61e86a95f88267cf9ec1037119e90ef2],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3COMClassService, In Quarantäne, [61e86a95f88267cf9ec1037119e90ef2],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [61e86a95f88267cf9ec1037119e90ef2],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3COMClassService, In Quarantäne, [61e86a95f88267cf9ec1037119e90ef2],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [61e86a95f88267cf9ec1037119e90ef2],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{F48FC5B2-094A-44C7-B48C-289738C9582D}, In Quarantäne, [61e86a95f88267cf9ec1037119e90ef2],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F48FC5B2-094A-44C7-B48C-289738C9582D}, In Quarantäne, [61e86a95f88267cf9ec1037119e90ef2],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1E0C9B2A-6447-452C-B012-2314A0C29412}, In Quarantäne, [54f5807fa5d52c0adb85f4800af8d927],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [54f5807fa5d52c0adb85f4800af8d927],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [54f5807fa5d52c0adb85f4800af8d927],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [54f5807fa5d52c0adb85f4800af8d927],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [54f5807fa5d52c0adb85f4800af8d927],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{34A8CEB6-89BB-49F1-B5E4-0D0D6C21F3B1}, In Quarantäne, [1b2eb44b710963d3baa7660e9a6826da],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CredentialDialogMachine.1.0, In Quarantäne, [1b2eb44b710963d3baa7660e9a6826da],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CredentialDialogMachine, In Quarantäne, [1b2eb44b710963d3baa7660e9a6826da],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CredentialDialogMachine, In Quarantäne, [1b2eb44b710963d3baa7660e9a6826da],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CredentialDialogMachine.1.0, In Quarantäne, [1b2eb44b710963d3baa7660e9a6826da],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [a0a951aef38705310f07023d887aaa56],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [a0a951aef38705310f07023d887aaa56],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [a0a951aef38705310f07023d887aaa56],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3A4DBD3A-98CC-41CE-AD21-352D42B6F754}, In Quarantäne, [9faa37c84931cd6929392c48639fb14f],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoCreateAsync.1.0, In Quarantäne, [9faa37c84931cd6929392c48639fb14f],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoCreateAsync, In Quarantäne, [9faa37c84931cd6929392c48639fb14f],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoCreateAsync, In Quarantäne, [9faa37c84931cd6929392c48639fb14f],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoCreateAsync.1.0, In Quarantäne, [9faa37c84931cd6929392c48639fb14f],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4F8A50F6-69DE-4BE3-A33A-A1079B9AC0DB}, In Quarantäne, [90b9649ba7d3b58164ff52224db55da3],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [90b9649ba7d3b58164ff52224db55da3],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebMachineFallback, In Quarantäne, [90b9649ba7d3b58164ff52224db55da3],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebMachineFallback, In Quarantäne, [90b9649ba7d3b58164ff52224db55da3],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [90b9649ba7d3b58164ff52224db55da3],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{501CB57A-D4E2-4855-96AD-EDB0A9083395}, In Quarantäne, [80c97a850b6f91a50d577bf9c63cd62a],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoreMachineClass.1, In Quarantäne, [80c97a850b6f91a50d577bf9c63cd62a],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoreMachineClass, In Quarantäne, [80c97a850b6f91a50d577bf9c63cd62a],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoreMachineClass, In Quarantäne, [80c97a850b6f91a50d577bf9c63cd62a],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoreMachineClass.1, In Quarantäne, [80c97a850b6f91a50d577bf9c63cd62a],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6FF2C4DD-77A4-4BB5-BA4C-B42DEFBF9137}, In Quarantäne, [e9602ad5ee8c3006580d1e5635cd5aa6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.ProcessLauncher.1.0, In Quarantäne, [e9602ad5ee8c3006580d1e5635cd5aa6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.ProcessLauncher, In Quarantäne, [e9602ad5ee8c3006580d1e5635cd5aa6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.ProcessLauncher, In Quarantäne, [e9602ad5ee8c3006580d1e5635cd5aa6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.ProcessLauncher.1.0, In Quarantäne, [e9602ad5ee8c3006580d1e5635cd5aa6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{83ABA270-8390-4CA6-AE48-FC089F55629E}, In Quarantäne, [db6e6e91a6d42b0b67ff86ee7b87af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [db6e6e91a6d42b0b67ff86ee7b87af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachine, In Quarantäne, [db6e6e91a6d42b0b67ff86ee7b87af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachine, In Quarantäne, [db6e6e91a6d42b0b67ff86ee7b87af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [db6e6e91a6d42b0b67ff86ee7b87af51],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8B218A5F-1A3D-4347-94EF-A79575EB8094}, In Quarantäne, [71d866998eecac8a99ce076de919c43c],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{0D89DE71-3D99-4288-84DC-F18F1047A7D8}, In Quarantäne, [71d866998eecac8a99ce076de919c43c],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLive.OneClickCtrl.9, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLive.OneClickCtrl.9, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{7F1796B2-BEC6-427B-B734-F9C75ED94A80}, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLive.Update3WebControl.3, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLive.Update3WebControl.3, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{8C338DDB-19FC-4C1F-B74D-6931EE55F7A1}, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9BDB5E09-4BBA-4422-8C2B-529B281C32B8}, In Quarantäne, [51f803fcd1a914224b1e5024de248a76],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{ae48ed75-5a56-4c5f-bbce-6f1ac3875f66}, In Quarantäne, [5fea58a7acce65d1b62d92af659d58a8],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{AE48ED75-5A56-4C5F-BBCE-6F1AC3875F66}, In Quarantäne, [5fea58a7acce65d1b62d92af659d58a8],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C536F080-57B7-46D6-8894-C647553F2889}, In Quarantäne, [d475cb340b6fb4822f3b8fe5c73b0cf4],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLive.OneClickProcessLauncherMachine.1.0, In Quarantäne, [d475cb340b6fb4822f3b8fe5c73b0cf4],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLive.OneClickProcessLauncherMachine, In Quarantäne, [d475cb340b6fb4822f3b8fe5c73b0cf4],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLive.OneClickProcessLauncherMachine, In Quarantäne, [d475cb340b6fb4822f3b8fe5c73b0cf4],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLive.OneClickProcessLauncherMachine.1.0, In Quarantäne, [d475cb340b6fb4822f3b8fe5c73b0cf4],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C536F080-57B7-46D6-8894-C647553F2889}, In Quarantäne, [d475cb340b6fb4822f3b8fe5c73b0cf4],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CA5D945F-E738-4D0B-A0B5-25AC51C64659}, In Quarantäne, [153446b93b3fc0765c0f1b59d82a11ef],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoreClass.1, In Quarantäne, [153446b93b3fc0765c0f1b59d82a11ef],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.CoreClass, In Quarantäne, [153446b93b3fc0765c0f1b59d82a11ef],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoreClass, In Quarantäne, [153446b93b3fc0765c0f1b59d82a11ef],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.CoreClass.1, In Quarantäne, [153446b93b3fc0765c0f1b59d82a11ef],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{DEDAF650-12B8-48f5-A843-BBA100716106}, In Quarantäne, [74d510ef3347072f7e10b48d738f768a],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{DEDAF650-12B8-48F5-A843-BBA100716106}, In Quarantäne, [74d510ef3347072f7e10b48d738f768a],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F7698761-4ABA-45C2-A5BB-D2163922C725}, In Quarantäne, [a8a15da283f7d4626b012a4ad032f50b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [a8a15da283f7d4626b012a4ad032f50b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebSvc, In Quarantäne, [a8a15da283f7d4626b012a4ad032f50b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebSvc, In Quarantäne, [a8a15da283f7d4626b012a4ad032f50b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [a8a15da283f7d4626b012a4ad032f50b],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{FFCC53E6-2655-47FC-A89B-54E8D7F305D1}, In Quarantäne, [1c2d639c8bef102678f52f4514ee738d],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebMachine.1.0, In Quarantäne, [1c2d639c8bef102678f52f4514ee738d],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\DealPlyLiveUpdate.Update3WebMachine, In Quarantäne, [1c2d639c8bef102678f52f4514ee738d],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebMachine, In Quarantäne, [1c2d639c8bef102678f52f4514ee738d],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\DealPlyLiveUpdate.Update3WebMachine.1.0, In Quarantäne, [1c2d639c8bef102678f52f4514ee738d],
PUP.Optional.SweetPacks.A, HKLM\SOFTWARE\Updater By Sweetpacks, In Quarantäne, [7ccde817a7d379bdc59f3d7309faea16],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\CLASSES\APPID\DealPlyLive.exe, In Quarantäne, [7dcc837ca8d2b086c2704f5d9c675ea2],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [4affe8175f1b2016c9dd189ee12222de],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\DealPlyLive, In Quarantäne, [4702fb047efcfb3b0f25b1fb34cf7d83],
PUP.Optional.SweetPacks.A, HKLM\SOFTWARE\WOW6432NODE\Updater By Sweetpacks, In Quarantäne, [2b1ecf30a0da8caa92d2bdf334cfd12f],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\DealPlyLive.exe, In Quarantäne, [f257ed127505b97db082842817eca45c],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [a0a96d928cee59ddffa7ebcb6b982ad6],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.dpliveupdate.com/DealPlyLive Update;version=3, In Quarantäne, [c4852ed14d2db87e0b2b0ca018eb9e62],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.dpliveupdate.com/DealPlyLive Update;version=9, In Quarantäne, [8dbccb34f08adb5b2115ab01897ac23e],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM, In Quarantäne, [03460bf4e2980e28a6183c6f23e0c43c],
PUP.Optional.DealPly.A, HKU\S-1-5-21-2032216053-89665452-871656621-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DealPlyLive, In Quarantäne, [db6e798696e4d066f44488240ef52ed2],
PUP.Optional.Qone8, HKU\S-1-5-21-2032216053-89665452-871656621-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [e168e51a82f8e452a302d0e65ba8ba46],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2032216053-89665452-871656621-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM, In Quarantäne, [85c45da2cbaf89ad9d207c2fd62d43bd],
PUP.Optional.InstallBrain.A, HKU\S-1-5-21-2032216053-89665452-871656621-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT, In Quarantäne, [be8b609f0e6c4de92dc5357c7d86f907],
PUP.Optional.SweetPacks.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{DEDAF650-12B8-48f5-A843-BBA100716106}_is1, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
Registrierungswerte: 3
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SWEETIM|simapp_id, 177713605334279193587185982904893508547, In Quarantäne, [03460bf4e2980e28a6183c6f23e0c43c]
PUP.Optional.SweetIM.A, HKU\S-1-5-21-2032216053-89665452-871656621-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SWEETIM|simapp_id, 177713605334279193587185982904893508547, In Quarantäne, [85c45da2cbaf89ad9d207c2fd62d43bd]
PUP.Optional.InstallBrain.A, HKU\S-1-5-21-2032216053-89665452-871656621-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT|URL, MYSEARCH_SWEETPACKS, In Quarantäne, [be8b609f0e6c4de92dc5357c7d86f907]
Registrierungsdaten: 4
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~1.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~1.DLL),Ersetzt,[a7a24ab5adcd9b9bbd61ccc5d9290cf4]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~2.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~2.DLL),Ersetzt,[a7a24ab5adcd9b9bbd61ccc5d9290cf4]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[bc8dd42bb0ca7db955ee60cf699b21df]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[a2a7c53a265488ae0d36ee41e51fb050]
Ordner: 52
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive, In Quarantäne, [bc8ddc2314662412430e157155ade11f],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update, In Quarantäne, [bc8ddc2314662412430e157155ade11f],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update\Log, In Quarantäne, [bc8ddc2314662412430e157155ade11f],
PUP.Optional.DealPly.A, C:\Users\Vicky-PC\AppData\Roaming\Dealply, In Quarantäne, [79d06c93b3c768cec48e493d9d65ab55],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\CrashReports, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\Download, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\Install, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\Offline, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\Offline\{7F0732A7-4846-4551-B697-0BC76182E2A7}, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks, Löschen bei Neustart, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\content, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\content\libraries, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\content\resources, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\locale, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\locale\en-US, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\skin, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\defaults, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\defaults\preferences, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\libraries, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\resources, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.DealPly.A, C:\Users\Vicky-PC\AppData\Local\DealPlyLive, In Quarantäne, [a4a56d923a400036545588fe18ea619f],
PUP.Optional.DealPly.A, C:\Users\Vicky-PC\AppData\Local\DealPlyLive\CrashReports, In Quarantäne, [a4a56d923a400036545588fe18ea619f],
Dateien: 146
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [b0998b74166478be56e42375f0110af6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\ExtensionUpdaterService.exe, Löschen bei Neustart, [0a3f22ddcbaf55e13b4aca7edf2212ee],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\DealPlyLive.exe, In Quarantäne, [d277f00f0971d06613e184da0ff27987],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [a0a951aef38705310f07023d887aaa56],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\psmachine.dll, In Quarantäne, [71d866998eecac8a99ce076de919c43c],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\npGoogleUpdate3.dll, In Quarantäne, [61e8ab54bdbdd95d095f75ff79895ba5],
PUP.Optional.InstallBrain.A, C:\Users\Vicky-PC\Downloads\cbsidlm-tr1_15-My_Screen_Recorder-ORG-10972953.exe, In Quarantäne, [c485ff00a2d8ad8976c576a046be8c74],
PUP.Optional.Softonic.A, C:\Users\Vicky-PC\Downloads\SoftonicDownloader_fuer_pdfbinder.exe, In Quarantäne, [4dfc98671f5b8ea838cb7ce6f011649c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [a7a24ab5adcd9b9bbd61ccc5d9290cf4],
PUP.Optional.DealPly.A, C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineCore.job, In Quarantäne, [1f2a9669a3d7c571cfc7bcf4b44f5fa1],
PUP.Optional.DealPly.A, C:\Windows\Tasks\DealPlyLiveUpdateTaskMachineUA.job, In Quarantäne, [e366639c4c2eb0867224238d966d21df],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update\Log\DealPlyLive.log, In Quarantäne, [bc8ddc2314662412430e157155ade11f],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\DealPlyLive.exe, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\DealPlyLiveBroker.exe, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\DealPlyLiveHandler.exe, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\DealPlyLiveHelper.msi, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\DealPlyLiveOnDemand.exe, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_bn.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ca.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_cs.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_da.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_de.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_el.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_en-GB.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_en.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_es-419.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_es.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_et.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_fa.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_fi.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_fil.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_fr.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_gu.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_hr.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_hu.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_id.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_is.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_it.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_iw.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ja.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_kn.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ko.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_lt.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_lv.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ml.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_mr.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ms.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_nl.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_no.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdate.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_am.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ar.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_pt-BR.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_pt-PT.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ro.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ru.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sk.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sl.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sr.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sv.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_sw.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ta.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_te.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_th.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_tr.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_uk.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_ur.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_vi.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_zh-CN.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_zh-TW.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\psuser.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_bg.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_hi.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\Update\1.3.23.0\goopdateres_pl.dll, In Quarantäne, [c188c6392159a88ebc97d5b15ea410f0],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Extension64.dll, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\InstallerHelper.dll, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\unins000.dat, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\unins000.exe, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome.manifest, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\install.rdf, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\content\main.js, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\content\main.js.bak, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\content\main.xul, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\content\libraries\DataExchangeScript.js, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\content\resources\localscript.js, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\locale\en-US\overlay.dtd, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\chrome\skin\overlay.css, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\Firefox\defaults\preferences\defaults.js, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\libraries\DataExchangeScript.js, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
PUP.Optional.SweetPacks.A, C:\Program Files\Updater By Sweetpacks\resources\localscript.js, In Quarantäne, [81c817e8cfab0234db7ecdb9a35f1ae6],
Physische Sektoren: 0
(No malicious items detected)
(end)
Adwcleaner: Code:
# AdwCleaner v3.211 - Bericht erstellt am 02/06/2014 um 21:08:45
# Aktualisiert 26/05/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Vicky-PC - VICKY
# Gestartet von : C:\Users\Vicky-PC\Downloads\adwcleaner_3.211(1).exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : BackupStack
[#] Dienst Gelöscht : globalUpdatem
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\IePluginServices
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Windows\SysWOW64\ARFC
Ordner Gelöscht : C:\Windows\SysWOW64\jmdp
Ordner Gelöscht : C:\Windows\SysWOW64\WNLT
Ordner Gelöscht : C:\Windows\System32\ljkb
Ordner Gelöscht : C:\Users\Vicky-PC\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\Activeris
Ordner Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Ordner Gelöscht : C:\Users\Vicky-PC\AppData\Local\Software
Ordner Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\Mozilla\Firefox\Profiles\g4rapp85.default\Extensions\{906000A4-88D9-4D52-B209-7A772970D91F}
Ordner Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\Mozilla\Firefox\Profiles\g4rapp85.default\Extensions\quick_start@gmail.com
Ordner Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\Mozilla\Firefox\Profiles\g4rapp85.default\Extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com
Datei Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\Mozilla\Firefox\Profiles\g4rapp85.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk
Datei Gelöscht : C:\Users\Vicky-PC\AppData\LocalLow\SkwConfig.bin
Datei Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Vicky-PC\Desktop\Continue VuuPC Installation.lnk
Datei Gelöscht : C:\Users\Vicky-PC\Desktop\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\Mozilla\Firefox\Profiles\g4rapp85.default\searchplugins\SweetIm.xml
Datei Gelöscht : C:\Users\Vicky-PC\AppData\Roaming\Mozilla\Firefox\Profiles\g4rapp85.default\searchplugins\Sweetpacks Search.xml
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml
Datei Gelöscht : C:\Users\Vicky-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx
Datei Gelöscht : C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job
Datei Gelöscht : C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore
Datei Gelöscht : C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job
Datei Gelöscht : C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Wert Gelöscht : [x64] HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{8E9E3331-D360-4f87-8803-52DE43566502}]
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [quick_start@gmail.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\webssearchesSoftware
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\Vicky-PC\AppData\Roaming\Mozilla\Firefox\Profiles\g4rapp85.default\prefs.js ]
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://istart.webssearches.com/newtab/?type=nt&ts=1401459184&from=tugs&uid=TOSHIBAXMQ01ABF050_Y2JSC2VBTXXY2JSC2VBT");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "webssearches");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "webssearches");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hp&ts=1401459184&from=tugs&uid=TOSHIBAXMQ01ABF050_Y2JSC2VBTXXY2JSC2VBT");
Zeile gelöscht : user_pref("extensions.afaf73efed6aa46eb8014e0b47ac07eada90d6ab4be694e96a9791fd9c1ae6f92com58488.58488.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "1464d83a79307ad939e084b1430d348a");
Zeile gelöscht : user_pref("{8E9E3331-D360-4f87-8803-52DE43566502}.ScriptData_product_name", "Updater By Sweetpacks");
-\\ Google Chrome v35.0.1916.114
[ Datei : C:\Users\Vicky-PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Startup_urls] : hxxp://istart.webssearches.com/?type=hp&ts=1401459184&from=tugs&uid=TOSHIBAXMQ01ABF050_Y2JSC2VBTXXY2JSC2VBT
Gelöscht [Homepage] : hxxp://istart.webssearches.com/?type=hp&ts=1401459184&from=tugs&uid=TOSHIBAXMQ01ABF050_Y2JSC2VBTXXY2JSC2VBT
Gelöscht [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma
*************************
AdwCleaner[R0].txt - [10730 octets] - [02/06/2014 21:06:52]
AdwCleaner[S0].txt - [8511 octets] - [02/06/2014 21:08:45]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8571 octets] ##########
JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by Vicky-PC on 02.06.2014 at 21:16:29,67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Failed to delete: [Folder] "C:\ProgramData\boost_interprocess"
~~~ FireFox
Emptied folder: C:\Users\Vicky-PC\AppData\Roaming\mozilla\firefox\profiles\g4rapp85.default\minidumps [20 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02.06.2014 at 21:19:53,06
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ neues FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by Vicky-PC (administrator) on VICKY on 02-06-2014 21:25:46
Running from C:\Users\Vicky-PC\Desktop
Platform: Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Fuyu LIMITED) C:\ProgramData\WindowsProtectManger\wprotectmanager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Broadcom Corp.) C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\RadioController\RfBtnHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2873744 2012-11-20] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-09-25] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [RadioController] => C:\Program Files (x86)\RadioController\RfBtnHelper.exe [111216 2013-03-09] (Dritek System Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2994880 2012-08-15] (Symantec Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-11-05] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2032216053-89665452-871656621-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk
ShortcutTarget: Acer Backup Manager Tray.lnk -> C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
Startup: C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {D1E91F4E-7933-4AB3-9124-EE056726F5BA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM-x32 - {D1E91F4E-7933-4AB3-9124-EE056726F5BA} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKCU - {D1E91F4E-7933-4AB3-9124-EE056726F5BA} URL =
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Vicky-PC\AppData\Roaming\Mozilla\Firefox\Profiles\g4rapp85.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: FireShot - C:\Users\Vicky-PC\AppData\Roaming\Mozilla\Firefox\Profiles\g4rapp85.default\Extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba} [2014-05-03]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR DefaultSearchKeyword: webssearches
CHR DefaultSearchProvider: webssearches
CHR DefaultSearchURL: hxxp://istart.webssearches.com/web/?type=ds&ts=1401459184&from=tugs&uid=TOSHIBAXMQ01ABF050_Y2JSC2VBTXXY2JSC2VBT&q={searchTerms}
CHR Extension: (Google Docs) - C:\Users\Vicky-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-10-08]
CHR Extension: (Google Drive) - C:\Users\Vicky-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-10-08]
CHR Extension: (YouTube) - C:\Users\Vicky-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-10-08]
CHR Extension: (Google-Suche) - C:\Users\Vicky-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-10-08]
CHR Extension: (Google Wallet) - C:\Users\Vicky-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-08]
CHR Extension: (Google Mail) - C:\Users\Vicky-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-10-08]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.)
R2 BrcmCardReader; C:\Program Files\Broadcom\MemoryCard\BrcmCardReader.exe [176640 2012-08-20] (Broadcom Corp.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2449552 2012-10-25] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-17] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658064 2012-10-23] (Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2012-11-20] (ELAN Microelectronics Corp.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3943104 2012-08-15] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-11-03] (NTI Corporation)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [96880 2013-03-09] (Dritek System INC.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R2 WindowsProtectManger; C:\ProgramData\WindowsProtectManger\wprotectmanager.exe [573344 2014-05-30] (Fuyu LIMITED)
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe [X]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-09-30] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-18] (Avira Operations GmbH & Co. KG)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6835784 2013-03-09] (Broadcom Corporation)
R1 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2013-03-09] (Dritek System Inc.)
S3 athr; \SystemRoot\system32\DRIVERS\athrx.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-02 21:25 - 2014-06-02 21:25 - 00000000 ____D () C:\Users\Vicky-PC\Desktop\FRST-OlderVersion
2014-06-02 21:20 - 2014-06-02 21:20 - 00001089 _____ () C:\Users\Vicky-PC\Desktop\JRT1.txt
2014-06-02 21:19 - 2014-06-02 21:19 - 00001089 _____ () C:\Users\Vicky-PC\Desktop\JRT.txt
2014-06-02 21:16 - 2014-06-02 21:16 - 00000000 ____D () C:\Windows\ERUNT
2014-06-02 21:15 - 2014-06-02 21:15 - 01016261 _____ (Thisisu) C:\Users\Vicky-PC\Desktop\JRT.exe
2014-06-02 21:13 - 2014-06-02 21:13 - 00008675 _____ () C:\Users\Vicky-PC\Desktop\AdwCleaner[S0].txt
2014-06-02 21:07 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-02 21:06 - 2014-06-02 21:09 - 00000000 ____D () C:\AdwCleaner
2014-06-02 21:05 - 2014-06-02 21:05 - 01327971 _____ () C:\Users\Vicky-PC\Downloads\adwcleaner_3.211(1).exe
2014-06-02 21:04 - 2014-06-02 21:05 - 01327971 _____ () C:\Users\Vicky-PC\Downloads\adwcleaner_3.211.exe
2014-06-02 21:01 - 2014-06-02 21:01 - 00046990 _____ () C:\Users\Vicky-PC\Desktop\mbam.txt
2014-06-02 20:39 - 2014-06-02 21:00 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-02 20:39 - 2014-06-02 20:39 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-02 20:39 - 2014-06-02 20:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-02 20:39 - 2014-06-02 20:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-02 20:39 - 2014-06-02 20:39 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-02 20:39 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-02 20:39 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-02 20:39 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-02 20:35 - 2014-06-02 20:38 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Vicky-PC\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-02 13:27 - 2014-06-02 13:28 - 00284784 _____ () C:\Windows\Minidump\060214-37250-01.dmp
2014-06-01 11:56 - 2014-06-01 11:56 - 00022756 _____ () C:\ComboFix.txt
2014-06-01 11:56 - 2014-06-01 11:56 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-01 11:56 - 2014-06-01 11:56 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-01 11:56 - 2014-06-01 11:56 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-01 11:40 - 2014-06-01 11:56 - 00000000 ____D () C:\Qoobox
2014-06-01 11:40 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-01 11:40 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-01 11:40 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-01 11:40 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-01 11:40 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-01 11:40 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-06-01 11:40 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-01 11:40 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-01 11:40 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-01 11:39 - 2014-06-01 11:53 - 00000000 ____D () C:\Windows\erdnt
2014-06-01 11:37 - 2014-06-01 11:38 - 05203398 ____R (Swearware) C:\Users\Vicky-PC\Desktop\ComboFix.exe
2014-06-01 10:48 - 2014-06-01 10:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Vicky-PC\Desktop\revosetup95.exe
2014-06-01 10:48 - 2014-06-01 10:48 - 00001264 _____ () C:\Users\Vicky-PC\Desktop\Revo Uninstaller.lnk
2014-06-01 10:48 - 2014-06-01 10:48 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 09:45 - 2014-06-01 09:45 - 00039415 _____ () C:\Users\Vicky-PC\Desktop\Addition.txt
2014-06-01 09:44 - 2014-06-02 21:25 - 00014985 _____ () C:\Users\Vicky-PC\Desktop\FRST.txt
2014-06-01 09:44 - 2014-06-02 21:25 - 00000000 ____D () C:\FRST
2014-06-01 09:43 - 2014-06-02 21:25 - 02068992 _____ (Farbar) C:\Users\Vicky-PC\Desktop\FRST64.exe
2014-06-01 08:39 - 2014-06-01 08:39 - 00284784 _____ () C:\Windows\Minidump\060114-36250-01.dmp
2014-05-30 16:19 - 2014-05-30 16:20 - 00284784 _____ () C:\Windows\Minidump\053014-41953-01.dmp
2014-05-30 16:14 - 2014-05-31 22:17 - 00000000 ____D () C:\Program Files (x86)\Fre_Ven_s Pro 23
2014-05-30 16:14 - 2014-05-31 08:17 - 00000000 ____D () C:\Program Files (x86)\Media_Play_AIR+
2014-05-30 16:14 - 2014-05-30 16:15 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-05-30 16:12 - 2014-05-30 16:12 - 00277816 _____ () C:\Users\Vicky-PC\Downloads\jvlsetup(1).exe
2014-05-30 16:11 - 2014-05-30 16:11 - 00277816 _____ () C:\Users\Vicky-PC\Downloads\jvlsetup.exe
2014-05-20 08:19 - 2014-05-20 08:20 - 00284784 _____ () C:\Windows\Minidump\052014-47953-01.dmp
2014-05-20 08:18 - 2014-05-20 08:18 - 00000000 ____D () C:\found.000
2014-05-19 07:16 - 2014-06-02 13:27 - 00000000 ____D () C:\Windows\Minidump
2014-05-19 07:16 - 2014-05-19 07:16 - 00284896 _____ () C:\Windows\Minidump\051914-22015-01.dmp
2014-05-19 07:15 - 2014-06-02 13:27 - 423953727 _____ () C:\Windows\MEMORY.DMP
2014-05-14 05:06 - 2014-03-28 10:23 - 19759104 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 05:06 - 2014-03-28 08:18 - 17562112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 05:05 - 2014-04-12 11:27 - 00172888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 05:05 - 2014-04-12 11:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 05:05 - 2014-04-12 11:09 - 01043968 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-05-14 05:05 - 2014-04-12 11:09 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-05-14 05:05 - 2014-04-12 11:09 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 05:05 - 2014-04-12 11:09 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 05:05 - 2014-04-12 11:08 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 05:05 - 2014-04-12 11:08 - 00827904 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 05:05 - 2014-04-12 11:08 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2014-05-14 05:05 - 2014-04-12 11:08 - 00318464 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 05:05 - 2014-04-12 11:07 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 05:05 - 2014-04-12 09:23 - 00961536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2014-05-14 05:05 - 2014-04-12 09:23 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-05-14 05:05 - 2014-04-12 09:23 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 05:05 - 2014-04-12 09:23 - 00178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 05:05 - 2014-04-12 09:23 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 05:05 - 2014-04-12 09:22 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 05:05 - 2014-04-12 09:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 05:05 - 2014-04-12 08:58 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\workerdd.dll
2014-05-14 05:05 - 2014-03-28 21:19 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2014-05-14 05:05 - 2014-03-24 00:11 - 00269592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2014-05-14 05:05 - 2014-03-11 05:32 - 06987096 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 05:05 - 2014-03-11 05:25 - 00100184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 05:05 - 2014-03-11 02:41 - 00559104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 05:05 - 2014-03-11 02:41 - 00323072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 05:05 - 2014-03-11 02:41 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 05:05 - 2014-03-11 02:39 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 05:05 - 2014-03-11 02:38 - 00982016 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 05:05 - 2014-03-11 02:38 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 05:05 - 2014-03-11 02:38 - 00419328 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 05:05 - 2014-03-11 02:38 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2014-05-14 05:05 - 2014-03-11 02:38 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 05:05 - 2014-03-11 02:38 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 05:05 - 2014-03-11 02:38 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 05:05 - 2014-03-10 05:05 - 00668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-14 05:05 - 2014-03-10 03:27 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 05:05 - 2014-03-04 01:07 - 00570216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-05-14 05:04 - 2014-05-06 07:14 - 19274752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 05:04 - 2014-05-06 07:14 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 05:04 - 2014-05-06 05:48 - 14367232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-14 05:04 - 2014-05-06 05:48 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 05:04 - 2014-05-06 05:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-14 05:04 - 2014-05-06 05:26 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-14 05:04 - 2014-03-28 10:23 - 01287168 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-05-14 05:04 - 2014-03-01 11:47 - 01258496 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-05-14 05:04 - 2014-03-01 11:47 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2014-05-14 05:04 - 2014-03-01 10:07 - 01075200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2014-05-14 05:04 - 2014-03-01 08:59 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-05-14 05:04 - 2014-02-27 01:18 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-05-14 05:04 - 2014-02-27 01:18 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-05-14 05:04 - 2014-02-27 01:18 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-05-14 05:04 - 2014-02-27 01:18 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-05-14 05:04 - 2014-02-15 06:15 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-05-12 12:59 - 2014-05-12 12:59 - 00000000 ____D () C:\ProgramData\TreeCardGames
2014-05-12 12:58 - 2014-05-12 12:58 - 07103672 _____ (TreeCardGames ) C:\Users\Vicky-PC\Downloads\123freesolitaire-v100-setup.exe
2014-05-12 12:58 - 2014-05-12 12:58 - 00001045 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\123 Free Solitaire.lnk
2014-05-12 12:58 - 2014-05-12 12:58 - 00001033 _____ () C:\Users\Public\Desktop\123 Free Solitaire.lnk
2014-05-12 12:58 - 2014-05-12 12:58 - 00000000 ____D () C:\Users\Vicky-PC\AppData\Roaming\TreeCardGames
2014-05-12 12:58 - 2014-05-12 12:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\123 Free Solitaire
2014-05-12 12:58 - 2014-05-12 12:58 - 00000000 ____D () C:\Program Files (x86)\123 Free Solitaire
2014-05-09 22:31 - 2014-05-09 22:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-06 07:04 - 2014-04-19 11:39 - 00628024 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-05-06 07:04 - 2014-04-19 10:45 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-05-06 07:04 - 2014-04-19 10:45 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-06 07:04 - 2014-04-19 08:57 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-05-06 07:04 - 2014-04-19 08:57 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
==================== One Month Modified Files and Folders =======
2014-06-02 21:26 - 2014-06-01 09:44 - 00014985 _____ () C:\Users\Vicky-PC\Desktop\FRST.txt
2014-06-02 21:26 - 2013-10-07 12:05 - 00000000 ____D () C:\Users\Vicky-PC\AppData\Local\Temp
2014-06-02 21:25 - 2014-06-02 21:25 - 00000000 ____D () C:\Users\Vicky-PC\Desktop\FRST-OlderVersion
2014-06-02 21:25 - 2014-06-01 09:44 - 00000000 ____D () C:\FRST
2014-06-02 21:25 - 2014-06-01 09:43 - 02068992 _____ (Farbar) C:\Users\Vicky-PC\Desktop\FRST64.exe
2014-06-02 21:22 - 2013-10-07 12:13 - 00003592 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2032216053-89665452-871656621-1001
2014-06-02 21:20 - 2014-06-02 21:20 - 00001089 _____ () C:\Users\Vicky-PC\Desktop\JRT1.txt
2014-06-02 21:19 - 2014-06-02 21:19 - 00001089 _____ () C:\Users\Vicky-PC\Desktop\JRT.txt
2014-06-02 21:16 - 2014-06-02 21:16 - 00000000 ____D () C:\Windows\ERUNT
2014-06-02 21:15 - 2014-06-02 21:15 - 01016261 _____ (Thisisu) C:\Users\Vicky-PC\Desktop\JRT.exe
2014-06-02 21:13 - 2014-06-02 21:13 - 00008675 _____ () C:\Users\Vicky-PC\Desktop\AdwCleaner[S0].txt
2014-06-02 21:12 - 2014-01-27 14:13 - 00000000 ____D () C:\Users\Vicky-PC\AppData\Roaming\Skype
2014-06-02 21:11 - 2013-10-08 16:36 - 00001122 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-02 21:11 - 2013-10-07 12:05 - 01277946 _____ () C:\Windows\WindowsUpdate.log
2014-06-02 21:10 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-02 21:09 - 2014-06-02 21:06 - 00000000 ____D () C:\AdwCleaner
2014-06-02 21:09 - 2012-11-23 07:21 - 00211972 _____ () C:\Windows\PFRO.log
2014-06-02 21:08 - 2013-10-08 16:37 - 00001278 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-02 21:08 - 2013-10-08 16:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-06-02 21:08 - 2013-10-07 13:53 - 00001061 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-02 21:08 - 2013-10-07 13:53 - 00001049 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-02 21:08 - 2013-10-07 12:07 - 00001005 _____ () C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-06-02 21:08 - 2013-10-07 12:07 - 00000000 ___RD () C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-06-02 21:07 - 2013-10-08 16:36 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-02 21:05 - 2014-06-02 21:05 - 01327971 _____ () C:\Users\Vicky-PC\Downloads\adwcleaner_3.211(1).exe
2014-06-02 21:05 - 2014-06-02 21:04 - 01327971 _____ () C:\Users\Vicky-PC\Downloads\adwcleaner_3.211.exe
2014-06-02 21:02 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-02 21:01 - 2014-06-02 21:01 - 00046990 _____ () C:\Users\Vicky-PC\Desktop\mbam.txt
2014-06-02 21:00 - 2014-06-02 20:39 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-02 20:56 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-06-02 20:39 - 2014-06-02 20:39 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-02 20:39 - 2014-06-02 20:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-02 20:39 - 2014-06-02 20:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-02 20:39 - 2014-06-02 20:39 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-02 20:38 - 2014-06-02 20:35 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Vicky-PC\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-02 13:32 - 2013-10-07 14:22 - 00000000 ____D () C:\Users\Vicky-PC\AppData\Local\Adobe
2014-06-02 13:28 - 2014-06-02 13:27 - 00284784 _____ () C:\Windows\Minidump\060214-37250-01.dmp
2014-06-02 13:27 - 2014-05-19 07:16 - 00000000 ____D () C:\Windows\Minidump
2014-06-02 13:27 - 2014-05-19 07:15 - 423953727 _____ () C:\Windows\MEMORY.DMP
2014-06-02 12:52 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-06-01 11:56 - 2014-06-01 11:56 - 00022756 _____ () C:\ComboFix.txt
2014-06-01 11:56 - 2014-06-01 11:56 - 00000000 ____D () C:\Users\Public\AppData\Local\temp
2014-06-01 11:56 - 2014-06-01 11:56 - 00000000 ____D () C:\Users\Default\AppData\Local\temp
2014-06-01 11:56 - 2014-06-01 11:56 - 00000000 ____D () C:\Users\Default User\AppData\Local\temp
2014-06-01 11:56 - 2014-06-01 11:40 - 00000000 ____D () C:\Qoobox
2014-06-01 11:56 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-06-01 11:53 - 2014-06-01 11:39 - 00000000 ____D () C:\Windows\erdnt
2014-06-01 11:50 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-06-01 11:49 - 2012-07-26 07:26 - 69730304 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-06-01 11:49 - 2012-07-26 07:26 - 13893632 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-06-01 11:49 - 2012-07-26 07:26 - 00786432 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-06-01 11:49 - 2012-07-26 07:26 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-06-01 11:49 - 2012-07-26 07:26 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-06-01 11:38 - 2014-06-01 11:37 - 05203398 ____R (Swearware) C:\Users\Vicky-PC\Desktop\ComboFix.exe
2014-06-01 10:48 - 2014-06-01 10:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Vicky-PC\Desktop\revosetup95.exe
2014-06-01 10:48 - 2014-06-01 10:48 - 00001264 _____ () C:\Users\Vicky-PC\Desktop\Revo Uninstaller.lnk
2014-06-01 10:48 - 2014-06-01 10:48 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-01 09:45 - 2014-06-01 09:45 - 00039415 _____ () C:\Users\Vicky-PC\Desktop\Addition.txt
2014-06-01 08:39 - 2014-06-01 08:39 - 00284784 _____ () C:\Windows\Minidump\060114-36250-01.dmp
2014-06-01 08:06 - 2013-10-07 13:50 - 00000000 ____D () C:\Users\Vicky-PC\AppData\Local\clear.fi
2014-05-31 22:17 - 2014-05-30 16:14 - 00000000 ____D () C:\Program Files (x86)\Fre_Ven_s Pro 23
2014-05-31 08:17 - 2014-05-30 16:14 - 00000000 ____D () C:\Program Files (x86)\Media_Play_AIR+
2014-05-30 22:58 - 2013-03-09 16:55 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-05-30 22:58 - 2013-03-09 16:55 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-05-30 22:58 - 2012-07-26 09:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-30 22:50 - 2013-10-07 12:05 - 00000000 ____D () C:\Users\Vicky-PC
2014-05-30 22:50 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-05-30 19:46 - 2013-12-22 11:24 - 00000000 ____D () C:\Users\Vicky-PC\AppData\Local\Deployment
2014-05-30 16:20 - 2014-05-30 16:19 - 00284784 _____ () C:\Windows\Minidump\053014-41953-01.dmp
2014-05-30 16:15 - 2014-05-30 16:14 - 00000000 ____D () C:\ProgramData\WindowsProtectManger
2014-05-30 16:12 - 2014-05-30 16:12 - 00277816 _____ () C:\Users\Vicky-PC\Downloads\jvlsetup(1).exe
2014-05-30 16:11 - 2014-05-30 16:11 - 00277816 _____ () C:\Users\Vicky-PC\Downloads\jvlsetup.exe
2014-05-22 13:50 - 2013-10-07 13:11 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-05-22 13:50 - 2013-10-07 13:11 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-05-20 08:20 - 2014-05-20 08:19 - 00284784 _____ () C:\Windows\Minidump\052014-47953-01.dmp
2014-05-20 08:18 - 2014-05-20 08:18 - 00000000 ____D () C:\found.000
2014-05-19 07:16 - 2014-05-19 07:16 - 00284896 _____ () C:\Windows\Minidump\051914-22015-01.dmp
2014-05-16 11:09 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-05-16 07:10 - 2013-10-07 12:07 - 00000000 ___RD () C:\Users\Vicky-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-16 07:08 - 2013-12-04 18:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-15 21:06 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-05-15 21:06 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-15 21:06 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-15 21:06 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-05-15 21:06 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-15 21:06 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-05-15 10:50 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-05-14 05:53 - 2013-12-22 11:02 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-14 05:50 - 2013-10-08 17:17 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 05:47 - 2013-10-08 17:17 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 05:47 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-05-14 04:53 - 2013-10-07 14:23 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-05-12 12:59 - 2014-05-12 12:59 - 00000000 ____D () C:\ProgramData\TreeCardGames
2014-05-12 12:58 - 2014-05-12 12:58 - 07103672 _____ (TreeCardGames ) C:\Users\Vicky-PC\Downloads\123freesolitaire-v100-setup.exe
2014-05-12 12:58 - 2014-05-12 12:58 - 00001045 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\123 Free Solitaire.lnk
2014-05-12 12:58 - 2014-05-12 12:58 - 00001033 _____ () C:\Users\Public\Desktop\123 Free Solitaire.lnk
2014-05-12 12:58 - 2014-05-12 12:58 - 00000000 ____D () C:\Users\Vicky-PC\AppData\Roaming\TreeCardGames
2014-05-12 12:58 - 2014-05-12 12:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\123 Free Solitaire
2014-05-12 12:58 - 2014-05-12 12:58 - 00000000 ____D () C:\Program Files (x86)\123 Free Solitaire
2014-05-12 07:26 - 2014-06-02 20:39 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-12 07:26 - 2014-06-02 20:39 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-12 07:25 - 2014-06-02 20:39 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-09 22:31 - 2014-05-09 22:31 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-07 08:02 - 2013-10-08 16:36 - 00004098 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-05-07 08:02 - 2013-10-08 16:36 - 00003862 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-05-06 07:14 - 2014-05-14 05:04 - 19274752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 07:14 - 2014-05-14 05:04 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 05:48 - 2014-05-14 05:04 - 14367232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:48 - 2014-05-14 05:04 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-06 05:37 - 2014-05-14 05:04 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:26 - 2014-05-14 05:04 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-04 21:40 - 2013-12-16 16:48 - 00004608 _____ () C:\Users\Vicky-PC\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-05-04 21:40 - 2013-12-16 16:45 - 00000000 ____D () C:\Users\Vicky-PC\Documents\My Recordings
2014-05-04 20:55 - 2013-12-14 15:31 - 00008355 _____ () C:\Windows\system32\lvcoinst.log
Some content of TEMP:
====================
C:\Users\Vicky-PC\AppData\Local\Temp\avgnt.exe
C:\Users\Vicky-PC\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe
[2014-05-14 05:05] - [2014-04-12 11:10] - 0578048 ____A (Microsoft Corporation) 75DD70A14145499C9F7D903CF9A8C91B
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-30 06:18
==================== End Of Log ============================ --- --- ---
--- --- ---
was muss ich jetzt danach machen? |