So jetzt glaube ich, habe ich alle Scans...und Omiga-plus scheint auch verschwunden... Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 05.01.2015
Scan Time: 19:58:25
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.01.05.09
Rootkit Database: v2014.12.30.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: TanteLila
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 323729
Time Elapsed: 13 min, 57 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1056, Delete-on-Reboot, [bd10db18b9d091a5fbea338fd031ba46]
Modules: 0
(No malicious items detected)
Registry Keys: 13
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, Quarantined, [bd10db18b9d091a5fbea338fd031ba46],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Quarantined, [646940b34b3e6acc47f75575dc288779],
PUP.Optional.ISearch.A, HKLM\SOFTWARE\WOW6432NODE\omiga-plusSoftware, Quarantined, [408de310880156e007977363db290ef2],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, Quarantined, [309ddb18c2c778be375f924c37cd43bd],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Quarantined, [9538c33079105cdaec52e2e8d52f2ad6],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, Quarantined, [6f5ec33048410a2cc672cbaea45f4fb1],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, Quarantined, [c00de90a79101f17701f99d5e81b6997],
PUP.Optional.ICinema.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\I - Cinema, Quarantined, [bf0e43b03653fc3a525389f2dd26817f],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-3417622803-1274620155-1545275548-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, Quarantined, [0bc247acd1b89c9a17e7774857add12f],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3417622803-1274620155-1545275548-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [9e2f8c678aff082efee059795da7b34d],
PUP.Optional.Qone8, HKU\S-1-5-21-3417622803-1274620155-1545275548-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Quarantined, [923bbc3747420d29b6871dadf410f808],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
Registry Values: 1
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, Quarantined, [6f5ec33048410a2cc672cbaea45f4fb1]
Registry Data: 11
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://isearch.omiga-plus.com/?type=sc&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://isearch.omiga-plus.com/?type=sc&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX),Replaced,[98351ad94841be7851c0c1caa95c4eb2]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX&q={searchTerms}),Replaced,[15b8f1020c7d989ec64fb1dae2238779]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://isearch.omiga-plus.com/?type=hp&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/?type=hp&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX),Replaced,[a32a8a6953364cead341008be42133cd]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX&q={searchTerms}),Replaced,[a8259f54fd8c112544d5117afe0734cc]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[517cac47c0c93ff7e460b3d6eb1a05fb]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://isearch.omiga-plus.com/?type=sc&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://isearch.omiga-plus.com/?type=sc&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX),Replaced,[a32ab93a078291a58b8644479b6ab34d]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX&q={searchTerms}),Replaced,[4e7f955e8bfe6acc7a9b5932bf4631cf]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://isearch.omiga-plus.com/?type=hp&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/?type=hp&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX),Replaced,[02cb7f743b4e7bbb7d971e6d1bea36ca]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX&q={searchTerms}),Replaced,[0bc2df141c6d22141801672449bc57a9]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[e5e832c11673e650ee56b3d60cf95ca4]
PUP.Optional.OmigaPlus.A, HKU\S-1-5-21-3417622803-1274620155-1545275548-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://isearch.omiga-plus.com/?type=hp&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/?type=hp&ts=1419717981&from=ild&uid=TOSHIBAXTHNSNJ128GMCU_74PB30MCK8XX30MCK8XX),Replaced,[616ca053ec9d6dc9e22cd7b4917416ea]
Folders: 37
Rogue.Multiple, C:\ProgramData\1078601655, Quarantined, [ad2044af9beefd392d8728f6dc27d729],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\Allin1Convert_8hEI, Quarantined, [5677ba39bdcc9f97c48a0b2cc043de22],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\Allin1Convert_8hEI\Installr, Quarantined, [5677ba39bdcc9f97c48a0b2cc043de22],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\Allin1Convert_8hEI\Installr\1.bin, Quarantined, [5677ba39bdcc9f97c48a0b2cc043de22],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\Allin1Convert_8hEI\Installr\setups, Quarantined, [5677ba39bdcc9f97c48a0b2cc043de22],
PUP.Optional.MindSpark.A, C:\Users\TanteLila\AppData\LocalLow\Allin1Convert_8hEI, Quarantined, [fecf15ded4b55bdbda1d102ee023e21e],
PUP.Optional.MindSpark.A, C:\Users\TanteLila\AppData\LocalLow\Allin1Convert_8hEI\Installr, Quarantined, [fecf15ded4b55bdbda1d102ee023e21e],
PUP.Optional.MindSpark.A, C:\Users\TanteLila\AppData\LocalLow\Allin1Convert_8hEI\Installr\Cache, Quarantined, [fecf15ded4b55bdbda1d102ee023e21e],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Delete-on-Reboot, [9835b2417c0d4fe73ad71e286a99ce32],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, Quarantined, [9835b2417c0d4fe73ad71e286a99ce32],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, Quarantined, [b41931c24346cd69bc611438000312ee],
Files: 100
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Delete-on-Reboot, [bd10db18b9d091a5fbea338fd031ba46],
PUP.Optional.1ClickMovieDownload.A, C:\Users\TanteLila\AppData\Roaming\FMYUZB.exe, Quarantined, [06c705ee82076fc7d3d55e5747ba44bc],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Quarantined, [a12cfaf95a2f20161d8b188e9c65936d],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, Quarantined, [24a9856ebbcefb3bfdab5353c43dfd03],
PUP.Optional.IEPluginService.A, C:\Program Files (x86)\SupTab\RSHP.exe, Quarantined, [765736bd6425dc5a2e716623aa57cf31],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, Quarantined, [fbd2d41f57326accf7b1d4d2f50cfa06],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, Quarantined, [9637e60d553410261a8edfc7917054ac],
PUP.Optional.IePluginService.A, C:\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe, Quarantined, [18b5d41f12773006f5d281f58f729967],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, Quarantined, [8647975ccfba5fd7565ddb5a26da18e8],
PUP.Optional.CrossRider.A, C:\Users\TanteLila\AppData\Local\Temp\DwlTempFolder\temp.exe, Quarantined, [ebe29a59ee9b5cda3110c021fa07de22],
PUP.Optional.SupTab.A, C:\Users\TanteLila\AppData\Local\Temp\~dl8FE9\~dljyb\tmp\SupTab_v5.8.8.777_noblank.exe, Quarantined, [686504efd2b743f338ae312f60a0cd33],
PUP.Optional.WindowsProtectManger.A, C:\Users\TanteLila\AppData\Local\Temp\~dl8FE9\~dljyb\tmp\wpm_v20.0.0.1277_.exe, Quarantined, [55782bc89eeb1d19d2135f636a970df3],
PUP.Optional.CrossRider.A, C:\Users\TanteLila\AppData\Local\Temp\~nsu.tmp\Au_.exe, Quarantined, [a32acb282960d75fc1a05cf0897731cf],
PUP.Optional.BoBrowser.A, C:\Windows\System32\Tasks\Run_Bobby_Browser, Quarantined, [4a83955ee7a2be78597fd98a4cb719e7],
PUP.Optional.WebInstrNew.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNewH_01009.Wdf, Quarantined, [a52811e2b8d147efb9f784e0c04341bf],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\0d39e319-fd7f-47d5-a922-5508daad6bfd-11, Quarantined, [ddf046ad1e6b979f9e0468190bf843bd],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\0d39e319-fd7f-47d5-a922-5508daad6bfd-2, Quarantined, [e0ed60931574b77f762c027ff21104fc],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\0d39e319-fd7f-47d5-a922-5508daad6bfd-5_user, Quarantined, [daf39f548ffaf2445151522fd23137c9],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a27c12c9-5ea6-48e1-97ab-f0865cce19af-1, Quarantined, [c00dc231147572c4b1f1730ea45f9d63],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a27c12c9-5ea6-48e1-97ab-f0865cce19af-2, Quarantined, [735a6390f4950a2cf5ad354c4cb72dd3],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a27c12c9-5ea6-48e1-97ab-f0865cce19af-5, Quarantined, [deefdf1400896dc9346e255c02014eb2],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a27c12c9-5ea6-48e1-97ab-f0865cce19af-5_user, Quarantined, [e8e57e750782b4824a58532e52b1d12f],
PUP.Optional.BetterMarkIT.A, C:\Windows\System32\Tasks\BetterMarkIt Update, Quarantined, [20adae45bccd9d9918254d397e85e21e],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA1d02221eca99abd, Quarantined, [5479a84b474213233d0a469931d3728e],
PUP.Optional.CrossRider.A, C:\Windows\System32\Tasks\temp_0d39e319-fd7f-47d5-a922-5508daad6bfd-2, Quarantined, [6865f30088010432f5f00ade4eb65da3],
PUP.Optional.CrossRider.A, C:\Windows\System32\Tasks\temp_a27c12c9-5ea6-48e1-97ab-f0865cce19af-2, Quarantined, [aa236291f6930e28c0257a6ed3316b95],
Rogue.Multiple, C:\ProgramData\1078601655\BITF623.tmp, Quarantined, [ad2044af9beefd392d8728f6dc27d729],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\Allin1Convert_8hEI\Installr\1.bin\8hEIPlug.dll, Quarantined, [5677ba39bdcc9f97c48a0b2cc043de22],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\Allin1Convert_8hEI\Installr\1.bin\8hEZSETP.dll, Quarantined, [5677ba39bdcc9f97c48a0b2cc043de22],
PUP.Optional.MindSpark.A, C:\Program Files (x86)\Allin1Convert_8hEI\Installr\1.bin\NP8hEISb.dll, Quarantined, [5677ba39bdcc9f97c48a0b2cc043de22],
PUP.Optional.MindSpark.A, C:\Users\TanteLila\AppData\LocalLow\Allin1Convert_8hEI\Installr\Cache\15D9AB3F.exe, Quarantined, [fecf15ded4b55bdbda1d102ee023e21e],
PUP.Optional.MindSpark.A, C:\Users\TanteLila\AppData\LocalLow\Allin1Convert_8hEI\Installr\Cache\files.ini, Quarantined, [fecf15ded4b55bdbda1d102ee023e21e],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, Quarantined, [9835b2417c0d4fe73ad71e286a99ce32],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\GoogleCrashHandler.exe, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\GoogleUpdate.exe, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\GoogleUpdateBroker.exe, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\GoogleUpdateHelper.msi, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\GoogleUpdateOnDemand.exe, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\goopdate.dll, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\goopdateres_en.dll, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\npGoogleUpdate4.dll, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\psmachine.dll, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.420189\psuser.dll, Quarantined, [d1fce50ed6b3ea4c738ca7a0986bd32d],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\GoogleCrashHandler.exe, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\GoogleUpdate.exe, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\GoogleUpdateBroker.exe, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\GoogleUpdateHelper.msi, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\GoogleUpdateOnDemand.exe, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\goopdate.dll, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\goopdateres_en.dll, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\npGoogleUpdate4.dll, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\psmachine.dll, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.GlobalUpdate.A, C:\Users\TanteLila\AppData\Local\Temp\comh.428460\psuser.dll, Quarantined, [94396b884841dc5adc23fc4b45be9967],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\BHOEnabler.exe, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcp110.dll, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\msvcr110.dll, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll32.dll, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WindowsSupportDll64.dll, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\btn.png, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\close.png, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\skin\main.xml, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit-ie8.js, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit2.0.js, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, Quarantined, [b41931c24346cd69bc611438000312ee],
Physical Sectors: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v4.106 - Bericht erstellt am 05/01/2015 um 20:51:30
# Aktualisiert 21/12/2014 von Xplode
# Database : 2015-01-03.1 [Live]
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : TanteLila - LILA
# Gestartet von : C:\Users\TanteLila\AppData\Local\Microsoft\Windows\INetCache\IE\26W5OUDE\AdwCleaner_4.106.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\TanteLila\AppData\Local\cool_mirage
Ordner Gelöscht : C:\Users\TanteLila\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\TanteLila\Documents\Optimizer Pro
Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk
***** [ Tasks ] *****
Task Gelöscht : bettermarkit Update
Task Gelöscht : Run_Bobby_Browser
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\TanteLila\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\TanteLila\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\BoBrowser
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\Clara
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ams1.ib.adnxs.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ib.adnxs.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\isearch.omiga-plus.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\microsoft-office-2010.en.softonic.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\omiga-plus.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\searches.omiga-plus.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17416
*************************
AdwCleaner[R0].txt - [3062 octets] - [05/01/2015 20:46:55]
AdwCleaner[S0].txt - [3010 octets] - [05/01/2015 20:51:30]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3070 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 8.1 x64
Ran by TanteLila on 05.01.2015 at 21:02:03,05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.01.2015 at 21:09:23,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |