Hallo schrauber,
ich bin so weit :) Adware & Co. deinstallieren
Ich habe dort gar nichts gefunden und gleich weiter gemacht :) Malwarebytes Anti-Malware Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.06.2014
Suchlauf-Zeit: 20:09:20
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.03.06
Rootkit Datenbank: v2014.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Meins
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 266971
Verstrichene Zeit: 47 Min, 9 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, 5816, Löschen bei Neustart, [1200afc5ee8d4aecafb063ff56ab13ed]
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 6088, Löschen bei Neustart, [a969b4c091ea043225d531260ff2f20e]
Module: 1
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [64ae007485f6b086051ed1e01fe3c23e],
Registrierungsschlüssel: 17
PUP.Optional.WpManager, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wpm, In Quarantäne, [1200afc5ee8d4aecafb063ff56ab13ed],
PUP.Optional.WpManager, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WPM, In Quarantäne, [1200afc5ee8d4aecafb063ff56ab13ed],
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [a969b4c091ea043225d531260ff2f20e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [d53d5420f18abe780da278c0ae545ca4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [d53d5420f18abe780da278c0ae545ca4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [d53d5420f18abe780da278c0ae545ca4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [d53d5420f18abe780da278c0ae545ca4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [d53d5420f18abe780da278c0ae545ca4],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [d53d5420f18abe780da278c0ae545ca4],
PUP.Optional.SupTab.A, HKU\S-1-5-21-349266611-3360480010-2136296735-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [d53d5420f18abe780da278c0ae545ca4],
PUP.Optional.SupTab.A, HKU\S-1-5-21-349266611-3360480010-2136296735-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [d53d5420f18abe780da278c0ae545ca4],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [09098be9d2a9dc5a220829ad8e7504fc],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [5fb3ff7556253ff71f022ab515ee768a],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [53bf096b017a5fd7949612c454af9868],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-349266611-3360480010-2136296735-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [2de59bd994e79a9c8ad6d7ddb34ffa06],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-349266611-3360480010-2136296735-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [a270660e5c1f4de9a9c2d1f9db287a86],
PUP.Optional.Qone8, HKU\S-1-5-21-349266611-3360480010-2136296735-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [28ea63116417d561e14834a2699a0ff1],
Registrierungswerte: 3
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com, In Quarantäne, [40d24c2893e846f0e090f7b16b977789]
PUP.Optional.WpManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WPM|ImagePath, C:\ProgramData\WPM\wprotectmanager.exe -service, In Quarantäne, [35ddbbb93645fc3a7f88c3182bd8b947]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-349266611-3360480010-2136296735-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0P1M1O1HtR0S1E2Z1I, Löschen bei Neustart, [a270660e5c1f4de9a9c2d1f9db287a86]
Registrierungsdaten: 12
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~1.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~1.DLL),Ersetzt,[64ae007485f6b086051ed1e01fe3c23e]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~2.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~2.DLL),Ersetzt,[64ae007485f6b086051ed1e01fe3c23e]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2&q={searchTerms}),Ersetzt,[b35f6b09314a83b31b46432529db3bc5]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2),Ersetzt,[54be97dd05760e28b9a77bed04007d83]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2),Ersetzt,[8f83afc57a017db9055ddc8c20e4a55b]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[d63cb4c028538ea8e211baad7f85ca36]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2&q={searchTerms}),Ersetzt,[888a294b92e9270f124f7bed58acf010]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2),Ersetzt,[b0621f55ea9182b46df38cdccb396d93]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2),Ersetzt,[f81a7ff51467ff37560cd29603019d63]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[c54d13612655ae88559ef374659fc937]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-349266611-3360480010-2136296735-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2),Löschen bei Neustart,[6ba7a9cb17640d29fe5f74f4e61e5fa1]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-349266611-3360480010-2136296735-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1401720489&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2),Löschen bei Neustart,[060c5024c1ba94a2c5973d2b44c0768a]
Ordner: 59
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\include, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\include\tools, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\lib, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\pack, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\en, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\en-US, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\es, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\es-419, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr-BE, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr-CA, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr-CH, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr-LU, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\it, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\it-CH, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\pl, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\pt-BR, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\ru, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\ru-MO, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\tr, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\vi, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\zh-CN, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\zh-TW, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\weather, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\defaults, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\defaults\preferences, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
Dateien: 145
PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, Löschen bei Neustart, [1200afc5ee8d4aecafb063ff56ab13ed],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [a969b4c091ea043225d531260ff2f20e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [d53d5420f18abe780da278c0ae545ca4],
PUP.Optional.InstallCore, C:\Users\meins\AppData\Local\Temp\ICReinstall_Open OfficeSetup.exe, In Quarantäne, [63af7df7df9c89adc67d8cd1ad57867a],
PUP.Optional.RockTurner.A, C:\Users\meins\AppData\Local\Temp\~nsu.tmp\Au_.exe, In Quarantäne, [b45efd770d6e0d29b4fe6bdbac54ec14],
PUP.Optional.SkyTech.A, C:\Users\meins\AppData\Local\Temp\80975359\80975359.zipDir\alilog.dll, In Quarantäne, [e9290d67c2b9af87d34569c9a55ba65a],
PUP.Optional.IePluginService.A, C:\Users\meins\AppData\Local\Temp\80975359\80975359.zipDir\tmp\SupTab_Setup302.exe, In Quarantäne, [d43e64104f2cd75f49b16bec45bc7789],
PUP.Optional.WpManager, C:\Users\meins\AppData\Local\Temp\80975359\80975359.zipDir\tmp\wpm_v18.8.0.304.exe, In Quarantäne, [9c76245056252e08d689e57d38c906fa],
PUP.Optional.InstallCore, C:\Users\meins\Downloads\Open OfficeSetup.exe, In Quarantäne, [67ab14600477d561d76ca1bccd37bf41],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [64ae007485f6b086051ed1e01fe3c23e],
PUP.Optional.SweetPage.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml, In Quarantäne, [d73b0074aad13cfac957edf247bcc33d],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome.manifest, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\install.rdf, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\index.html, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\quick_start.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\quick_start.xul, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\include\pageload.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\include\speed_dial.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\include\tools\about_blank_hook.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\include\tools\misc.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\include\tools\popup_image_helper.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\include\tools\urlrequestor.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\js.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\toolbar.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\lib\doT.min.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\lib\jquery-2.1.0.min.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\lib\jquery.autocomplete.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\bookmark.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\helpGider.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\hotSearch.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\other.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\pageManager.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\pageNew.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\search.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\searchMode.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\stat.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\wallpaper.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\module\weather.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\pack\browerStart.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\pack\common.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\pack\ga.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\content\js\pack\xagainit.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\en\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\en-US\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\es\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\es-419\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr-BE\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr-CA\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr-CH\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\fr-LU\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\it\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\it-CH\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\pl\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\pt-BR\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\ru\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\ru-MO\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\tr\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\vi\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\zh-CN\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\locale\zh-TW\locale.properties, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\arrow.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\default_add_logo.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\default_add_logo_hover.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\default_logo.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\googlelogo.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\googlelogo2.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\google_trends.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\icon.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\loading.gif, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\logo.ico, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\logo.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\logo32.ico, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\media.css, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\style.css, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\chrome\skin\weather\0.png, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\defaults\preferences\fvd.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\defaults\preferences\preferences.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\addonmanager.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\aes.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\config.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\dialogs.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\last_tab.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\misc.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\properties.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\remoterequest.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\restoreprefs.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.QuickStart.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\extensions\quick_start@gmail.com\modules\settings.js, In Quarantäne, [f41ef77d2259f83e867abdcae81ab54b],
PUP.Optional.SweetPage.A, C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.sweet-page.com/?type=hppp&ts=1401722212&from=cor&uid=WDCXWD5000LPVX-22V0TT0_WD-WXU1E83NWYS2NWYS2");), Ersetzt,[db37b8bc0576f343ae6aa4f2a361e719]
Physische Sektoren: 0
(No malicious items detected)
(end) adwcleaner
Dort habe ich drei Textdateien. ich habe den cleaner auch ein Mal aus versehen abgebrochen und poste jetzt die Datei, die sich am Ende (nach vollständigem Durchlauf) von allein geöffnet hat :) Code:
# AdwCleaner v3.211 - Bericht erstellt am 03/06/2014 um 21:15:57
# Aktualisiert 26/05/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : meins - Meins
# Gestartet von : C:\Users\meins\Desktop\adwcleaner_3.211.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\IePluginServices
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Users\meins\AppData\Local\Pokki
Ordner Gelöscht : C:\Users\meins\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\meins\AppData\Roaming\sweet-page
Ordner Gelöscht : C:\Users\Public\Pokki
Datei Gelöscht : C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\Pokki
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sweet-page uninstaller
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17037
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "sweet-page");
*************************
AdwCleaner[R0].txt - [2889 octets] - [03/06/2014 21:08:32]
AdwCleaner[R1].txt - [2949 octets] - [03/06/2014 21:13:11]
AdwCleaner[S0].txt - [2398 octets] - [03/06/2014 21:15:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2458 octets] ########## Junkware Removal Tool Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Ich on 04.06.2014 at 15:38:07,90
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
~~~ FireFox
Emptied folder: C:\Users\meins\AppData\Roaming\mozilla\firefox\profiles\0aizol3b.default\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.06.2014 at 15:48:29,45
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Frisches FRST: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-06-2014
Ran by meins (administrator) on Meins on 04-06-2014 15:50:54
Running from C:\Users\meins\Desktop
Platform: Windows 8.1 (Update 1) (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe
(Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAEvent.exe
(Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QAMsg.exe
(Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Quick Access\QuickAccess.exe
(Acer Incorporate) C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMTray.exe
(Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Dropbox, Inc.) C:\Users\meins\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
() C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\BrccMCtl.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Recovery Management\Notification\Notification.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890056 2013-10-02] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13657304 2013-10-18] (Realtek Semiconductor)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [191016 2014-05-14] (Geek Software GmbH)
HKLM-x32\...\Run: [BrMfcWnd] => C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe [1163264 2012-09-25] ()
HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications))
Startup: C:\Users\meins\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\meins\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {D55760F1-93B8-406B-99BA-1AD360FF1CDB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=APJB
SearchScopes: HKLM-x32 - {D55760F1-93B8-406B-99BA-1AD360FF1CDB} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=APJB
SearchScopes: HKCU - {D55760F1-93B8-406B-99BA-1AD360FF1CDB} URL =
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\meins\AppData\Roaming\Mozilla\Firefox\Profiles\0aizol3b.default\Extensions\toolbar_AVIRA-V7C@apn.ask.com.xpi [2014-02-24]
==================== Services (Whitelisted) =================
R2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [811088 2014-05-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1039952 2014-05-20] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider)
R3 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [101192 2013-10-02] (ELAN Microelectronics Corp.)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
R2 LMSvc; C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe [457768 2013-08-03] (Acer Incorporate)
R3 QASvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe [457768 2013-08-02] (Acer Incorporate)
R3 RMSvc; C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe [448040 2013-08-02] (Acer Incorporate)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
S2 Update Rock Turner; "C:\Program Files (x86)\Rock Turner\updateRockTurner.exe" [X]
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-20] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-20] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2014-02-25] (Avira Operations GmbH & Co. KG)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [87568 2013-07-01] (Intel Corporation)
R3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation)
S3 OATool; \??\C:\Users\Administrator\AppData\Local\Temp\OAToolx64.sys [X]
S3 TDKLIB; \??\C:\Users\Administrator\AppData\Local\Temp\TdkLib64.sys [X]
==================== NetSvcs (Whitelisted) =================== |