So endlich alles durchgeführt ;)
Hier nun mal alle erwünschten Scripte
Mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 08.04.2015
Suchlauf-Zeit: 08:52:25
Logdatei: mbam2.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.04.08.01
Rootkit Datenbank: v2015.03.31.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: vicky
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 320692
Verstrichene Zeit: 23 Min, 56 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.DownloadProtect.A, C:\ProgramData\dlprotect.exe, 2904, Löschen bei Neustart, [2af74b1fd3b73bfbef03132d4cb9b34d]
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 12
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [57cae585ec9e2a0c3e1148ee679c639d],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [57cae585ec9e2a0c3e1148ee679c639d],
PUP.Optional.MyFreeze.A, HKLM\SOFTWARE\Freeze.com, In Quarantäne, [bc65b2b88901d066930b9339c43fc040],
PUP.Optional.SpeedTestAnalysis.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\kckgnnipheglejoddfhekdjpbdbinhmb, In Quarantäne, [75acf67474164fe775607b8cdb29fb05],
PUP.Optional.PlusHD.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-4.9, In Quarantäne, [78a9c9a1cebced49e32b7985db281be5],
PUP.Optional.DigitalSites.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\DSiteProducts, In Quarantäne, [6cb5294171194ee851758bbc9273e61a],
PUP.Optional.WeDownLoadManager.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\WeDlMngr, In Quarantäne, [6fb288e2355588ae198d21c10df69967],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-4.9, In Quarantäne, [9f8280ea008ac57139d5bd41d132c53b],
PUP.Optional.AlexaTB.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\DISTROMATIC\Toolbars, In Quarantäne, [00212842b2d845f1f180c85ee71ea858],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [e1404723f199e056ab8553b77a8abd43],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\INSTALLCORE, In Quarantäne, [8e93f773aedc0b2b788b27f9c93c0cf4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Plus HD, In Quarantäne, [65bc096171194fe7ae835a846e950cf4],
Registrierungswerte: 6
PUP.Optional.ICQToolbar.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{855F3B16-6D32-4fe6-8A56-BBB695989046}, In Quarantäne, [59c83832e1a961d5b29eb878c241df21],
PUP.Optional.ICQToolbar.A, HKU\S-1-5-18\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{855F3B16-6D32-4FE6-8A56-BBB695989046}, In Quarantäne, [59c83832e1a961d5b29eb878c241df21],
PUP.Optional.DownloadProtect.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Download Protect, C:\ProgramData\dlprotect.exe, In Quarantäne, [2af74b1fd3b73bfbef03132d4cb9b34d]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\INSTALLCORE|tb, 0T1F1P1F1C0U2W, In Quarantäne, [8e93f773aedc0b2b788b27f9c93c0cf4]
PUP.Optional.Conduit.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|URL, hxxp://search.conduit.com/Results.aspx?ctid=CT3322611&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP82CEFFDE-5628-4902-BC9E-A1DBC21B6D93&q={searchTerms}&SSPV=, In Quarantäne, [52cfce9c602a64d28b2eb207659e7a86]
PUP.Optional.Conduit.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|SuggestionsURL_JSON, hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}, In Quarantäne, [72afc6a4d1b99c9a6f4ac5f4758e867a]
Registrierungsdaten: 1
PUP.Optional.Conduit.A, HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?ctid=CT3322611&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP82CEFFDE-5628-4902-BC9E-A1DBC21B6D93&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://search.conduit.com/?ctid=CT3322611&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP82CEFFDE-5628-4902-BC9E-A1DBC21B6D93&SSPV=),Ersetzt,[8c95c6a41b6fe452bef9f0014bba8878]
Ordner: 43
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\defaults, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\defaults\preferences, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\userCode, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\defaults, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\defaults\preferences, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\locale, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\locale\en-US, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\locale, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\locale\en-US, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.SpeedTestAnalysis.A, C:\Users\vicky\AppData\Roaming\SpeedTestAnalysis, In Quarantäne, [54cd0e5cbbcff5411abad13629db7888],
PUP.Optional.PlusHD.A, C:\Users\vicky\AppData\LocalLow\Plus-HD-4.9, In Quarantäne, [bc6549219af020160eb494f5d13233cd],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect, In Quarantäne, [ab7670fa8bff1e1854390f870cf77987],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [ab7670fa8bff1e1854390f870cf77987],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [ab7670fa8bff1e1854390f870cf77987],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaavxvyex, In Quarantäne, [2001b3b70e7c979fcdb7446f847f768a],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaxvavya, In Quarantäne, [70b188e2a1e9e2544d37b7fcb44f1ce4],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\DE, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
Dateien: 226
PUP.Optional.Softonic.A, C:\Users\vicky\Downloads\SoftonicDownloader_fuer_ixjingleplayer.exe, In Quarantäne, [22ff96d453372a0cba15b19e25dcf60a],
PUP.Optional.BundleInstaller.A, C:\Users\vicky\Downloads\microsoft powerpoint 2010 setup.exe, In Quarantäne, [11102b3f4842e5514af11058847d946c],
PUP.Optional.Conduit.A, C:\Users\vicky\AppData\Local\DownloadGuide\SPIdentifier.exe, In Quarantäne, [a37ec9a1008aa1953be57ac250b18977],
Adware.Linkular, C:\Users\vicky\AppData\Local\DownloadGuide\Offers\Lollipop.exe, In Quarantäne, [968b77f3b5d5a0966ee439ea818509f7],
PUP.Optional.Conduit.A, C:\Users\vicky\AppData\Local\DownloadGuide\Offers\sp-downloader.exe, In Quarantäne, [dd4481e9ccbe6ec82524113b49b8f808],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\crossrider_statusbar.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\button1.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\button2.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\button3.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\button4.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\button5.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\icon128.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\icon16.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\icon24.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\icon48.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\panelarrow-up.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\popup.html, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\skin.css, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\skin\update.css, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome.manifest, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\install.rdf, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\2cf4b59b2feff930af75ba672737252f.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\46fb7cdd9a86ef2f0972a4ba78cd75a7.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\5ea16bea9eddf8e1533ea64aa9df9835.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\7ee66f0b4b51eb8a895aba7df9332a75.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\abf1ea56d25bf9465b7ce5b9f551fa31.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\b19877b0146b27240d9ae55edbb07d28.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\background.html, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\browser.xul, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\dialog.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\ffCoreFilesIndex.txt, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\options.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\options.xul, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\search_dialog.xul, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\90a15d866351708c66c8656480d13399.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\0d716c40e460a32d5e8507f448354792.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\0f07f700f70fbe88ee7079ee0dc22dee.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\1b56fc2b582362fc54dc7723226110af.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\2d79435b595b09cec64f16c6d23214d1.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\2f64ce77a56790e395338f64b359f75c.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\36272c0f4e83e32dfe70a4bf07f97b2f.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\4cb1fad05902d91d2a1bf0d4840c66cf.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\525480f133ca304641316ce1d20552ae.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\987aaa2937f7033c7588ee9ba3089cf3.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\9d478857e82d696de0a2893ad00c939e.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\b8a751150bbce363571b099acf32fc62.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\be0d2f4fbaed1b0ff5a7a17dfac11be0.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\c593231a306d3d89572b7e9f93cac764.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\d11586edf3bbdec5cf627219b25b3664.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\api\d287069228d9cf501c73a854dc8bd299.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\994b2899fe47a7ccd63809787ffd20c2.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\01d1f70378d02436224e27a4b5eabfda.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\028b4469f9525f264b6c4ab3db8795b7.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\1da770a177dfb2b9c0a93226e7dbf97d.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\340e584b5ec700bb83fd1a5dce7b47da.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\5b37e5eb0b4ef80a3a43fed768014359.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\5dac56f800dd39abc282e77417791219.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\658d711562f2a24a016c6a1a77bc24b1.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\68202df664ccf32a67ac6d2be46aa21b.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\6832036e0eb1d1dd71156c6e5347029d.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\6ca71b61f7990d38509d24e9e1310ed0.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\721936dbb274c77591b5e98e7b7712da.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\7ddea7a05d9cac7e1a7041531b0c10fa.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\93e22a97ac6cce962d33766254177a44.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\c2056e79ed2f8f2fe81016bbcfb6598d.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\d2e67dc17da591f10ca569c619937060.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\d698f953c1107b37a0931ea3236edd81.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\edaec8357f20b8c9ef1bfc5c22d434cf.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\ee9fde7d6f721d5d180a6d155a2fbe17.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\fbfe7fc86aa4916beecbeeb49d10036f.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\chrome\content\core\installer.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\defaults\preferences\prefs.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\manifest.xml, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins.json, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\102.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\13.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\14.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\16.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\17.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\195.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\220.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\246.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\253.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\263.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\345.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\354.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\4.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\47.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\64.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\7.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\78.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\9.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\91.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\plugins\93.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\userCode\background.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\extensionData\userCode\extension.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome.manifest, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\install.rdf, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\background.html, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\baseObject.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\browser.xul, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\dialog.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\ffCoreFilesIndex.txt, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\main.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\migration.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\options.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\options.xul, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\platformVersion.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\search_dialog.xul, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\setup.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\asyncDB.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\background.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\browserAction.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\contextMenu.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\dbManager.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\dom_bg.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\fileManager.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\firefox.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\firefoxNotifications.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\firefoxOmnibox.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\message.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\pageAction.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\request.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\tabs.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\webRequest.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\api\windowsMessagingHandler.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\addressBarChangeObserver.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\console.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\consts.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\delegate.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\extensionDataStore.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\folderIOWrapper.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\httpObserver.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\IDBWrapper.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\installer.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\logFile.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\prefs.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\progressListenerObserver.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\registry.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\reloadObserver.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\reports.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\requestObject.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\searchSettings.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\uninstallObserver.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\updateManager.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\utils.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\chrome\content\core\xhr.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\defaults\preferences\prefs.js, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\locale\en-US\translations.dtd, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\button1.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\button2.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\button3.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\button4.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\button5.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\crossrider_statusbar.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\icon24.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\icon48.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\panelarrow-up.png, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\popup.html, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\skin.css, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\firefox-production\skin\update.css, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.CrossRider.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\extensions\VIKKKAJ71978004@TOINN37338714.com\locale\en-US\translations.dtd, In Quarantäne, [61c083e7b0daa3939969f0c8ee156c94],
PUP.Optional.Trovi.A, C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\searchplugins\trovi-search.xml, In Quarantäne, [9889105aee9c1a1c574c90630af97888],
PUP.Optional.SpeedTestAnalysis.A, C:\Users\vicky\AppData\Roaming\SpeedTestAnalysis\speedtestanalysis.crx, In Quarantäne, [54cd0e5cbbcff5411abad13629db7888],
PUP.Optional.SpeedTestAnalysis.A, C:\Users\vicky\AppData\Roaming\SpeedTestAnalysis\DeskTopIcon.ico, In Quarantäne, [54cd0e5cbbcff5411abad13629db7888],
PUP.Optional.SpeedTestAnalysis.A, C:\Users\vicky\AppData\Roaming\SpeedTestAnalysis\install_helper.exe, In Quarantäne, [54cd0e5cbbcff5411abad13629db7888],
PUP.Optional.DownloadProtect.A, C:\ProgramData\dlprotect.exe, Löschen bei Neustart, [2af74b1fd3b73bfbef03132d4cb9b34d],
PUP.Optional.PlusHD.A, C:\Users\vicky\AppData\LocalLow\Plus-HD-4.9\DTFProxyToServerSect_bCrossriderApp0045918_p4668.dat, In Quarantäne, [bc6549219af020160eb494f5d13233cd],
PUP.Optional.PlusHD.A, C:\Users\vicky\AppData\LocalLow\Plus-HD-4.9\DTFProxyToServerSect_bCrossriderApp0045918_p4688.dat, In Quarantäne, [bc6549219af020160eb494f5d13233cd],
PUP.Optional.PlusHD.A, C:\Users\vicky\AppData\LocalLow\Plus-HD-4.9\DTFProxyToServerSect_bCrossriderApp0045918_p5576.dat, In Quarantäne, [bc6549219af020160eb494f5d13233cd],
PUP.Optional.PlusHD.A, C:\Users\vicky\AppData\LocalLow\Plus-HD-4.9\DTFProxyToServerSect_bCrossriderApp0045918_p6100.dat, In Quarantäne, [bc6549219af020160eb494f5d13233cd],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [ab7670fa8bff1e1854390f870cf77987],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaavxvyex\stb.dat, In Quarantäne, [2001b3b70e7c979fcdb7446f847f768a],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaxvavya\bahvxfk, In Quarantäne, [70b188e2a1e9e2544d37b7fcb44f1ce4],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaxvavya\mkfvxfk, In Quarantäne, [70b188e2a1e9e2544d37b7fcb44f1ce4],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaxvavya\pvpqbjobmlpfqlovvawq, In Quarantäne, [70b188e2a1e9e2544d37b7fcb44f1ce4],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaxvavya\qokvxfk, In Quarantäne, [70b188e2a1e9e2544d37b7fcb44f1ce4],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaxvavya\rfobmlpfqlovvawq, In Quarantäne, [70b188e2a1e9e2544d37b7fcb44f1ce4],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaxvavya\rpboobmlpfqlovvawq, In Quarantäne, [70b188e2a1e9e2544d37b7fcb44f1ce4],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaxvavya\stb.dat, In Quarantäne, [70b188e2a1e9e2544d37b7fcb44f1ce4],
PUP.Optional.SearchProtect.A, C:\Users\vicky\AppData\Local\avaxvavya\ycfvxfk, In Quarantäne, [70b188e2a1e9e2544d37b7fcb44f1ce4],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\BG\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\CZ\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\EN\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\ES\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\FR\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\HE\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\IT\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\RU\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\SK\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\Configuration.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\OptionDlg.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\RegionalSettings.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
PUP.Optional.ICQToolbar.A, C:\ProgramData\ICQ\ICQToolbar\XML\TR\UserInterface.xml, In Quarantäne, [55cc4e1c74166bcb812780332bd87888],
Physische Sektoren: 0 AdwClearner Code:
# AdwCleaner v4.200 - Bericht erstellt 08/04/2015 um 09:39:55
# Aktualisiert 29/03/2015 von Xplode
# Datenbank : 2015-04-08.1 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x86)
# Benutzername : vicky - VICKY-PC
# Gestarted von : C:\Users\vicky\Downloads\AdwCleaner_4.200.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Windows\system32\SearchProtect
Ordner Gelöscht : C:\Users\vicky\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\vicky\AppData\Roaming\DigitalSites
Ordner Gelöscht : C:\Users\vicky\AppData\Roaming\RHEng
Datei Gelöscht : C:\END
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\AddonsFramework.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ButtonSite.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHost.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BackgroundHost.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{18B9B16E-716F-43DF-A6AD-512C7D2EB983}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{19975B78-1907-4DD6-A437-4C48120F46A4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9316-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{562B9317-C08A-444A-9482-62080DD851AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422592218}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455595518}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466596618}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\powerpack
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\SOFTWARE\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\icq.com
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17689
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v37.0.1 (x86 de)
*************************
AdwCleaner[R0].txt - [4425 Bytes] - [08/04/2015 09:33:27]
AdwCleaner[R1].txt - [4484 Bytes] - [08/04/2015 09:38:52]
AdwCleaner[S0].txt - [4347 Bytes] - [08/04/2015 09:39:55]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4406 Bytes] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.3 (04.07.2015:1)
OS: Windows 7 Home Premium x86
Ran by vicky on 08.04.2015 at 9:46:34.49
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\vicky\AppData\Roaming\getrighttogo"
~~~ FireFox
Emptied folder: C:\Users\vicky\AppData\Roaming\mozilla\firefox\profiles\9kpuzeef.default\minidumps [30 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.04.2015 at 9:49:32.62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und das frische FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 11-03-2015
Ran by vicky (administrator) on VICKY-PC on 08-04-2015 09:52:00
Running from C:\Users\vicky\Downloads
Loaded Profiles: vicky (Available profiles: vicky)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Cisco Systems, Inc.) C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-06-08] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1725736 2010-04-22] (Synaptics Incorporated)
HKLM\...\Run: [CLMLServer] => C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-02] (CyberLink)
HKLM\...\Run: [MGSysCtrl] => C:\Program Files\System Control Manager\MGSysCtrl.exe [2478080 2010-06-22] (Micro-Star International Co., Ltd.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9267816 2010-06-08] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [1481320 2010-06-08] (Realtek Semiconductor)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-01] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [127792 2015-02-12] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\...\Run: [Amazon Music] => C:\Users\vicky\AppData\Local\Amazon Music\Amazon Music Helper.exe [3162944 2014-06-24] ()
HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\...\Run: [Viber] => "C:\Users\vicky\AppData\Local\Viber\Viber.exe"
HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [878592 2010-11-20] (Microsoft Corporation)
Startup: C:\Users\vicky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\vicky\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\vicky\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\vicky\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\vicky\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1613706231-3109543469-1765141663-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://medion.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1613706231-3109543469-1765141663-1000 -> {CED673C2-D150-4ECD-B204-D033B1BC5329} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MEDTDF&pc=MAMD&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1613706231-3109543469-1765141663-1000 -> {EEAEC952-5C09-467C-A931-AF02AB5B8723} URL = hxxp://www.google.de/search?q={searchTerms}
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
BHO: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10] (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-06-22] (Sun Microsystems, Inc.)
Toolbar: HKU\.DEFAULT -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKU\S-1-5-21-1613706231-3109543469-1765141663-1000 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CC679CB8-DC4B-458B-B817-D447B3B6AC31} https://vpn.uni-marburg.de/CACHE/stc/1/binaries/vpnweb.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://active.macromedia.com/flash2/cabs/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2011-10-10] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-03-11] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll [2010-04-26] (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1613706231-3109543469-1765141663-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101753.dll [2012-10-30] (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\searchplugins\ecosia.xml [2014-02-26]
FF Extension: Avira Browser Safety - C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\Extensions\abs@avira.com [2015-04-01]
FF Extension: Adblock Plus - C:\Users\vicky\AppData\Roaming\Mozilla\Firefox\Profiles\9kpuzeef.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-26]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [434424 2015-04-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-01] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-01] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [184056 2015-02-12] (Avira Operations GmbH & Co. KG)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S2 Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [160768 2009-07-09] (Micro-Star International Co., Ltd.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-03-11] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-03-11] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-27] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37896 2015-03-11] (Avira Operations GmbH & Co. KG)
S3 CVirtA; C:\Windows\System32\DRIVERS\CVirtA.sys [5275 2007-01-18] (Cisco Systems, Inc.)
S4 DNE; C:\Windows\System32\DRIVERS\dne2000.sys [131984 2008-11-16] (Deterministic Networks, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
S3 PROCEXP113; C:\Windows\system32\Drivers\PROCEXP113.SYS [12568 2015-04-07] (Sysinternals - www.sysinternals.com) [File not signed]
S3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [168480 2009-12-02] (Realtek Semiconductor Corp.)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-26] (Avira GmbH)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\vicky\AppData\Local\Temp\catchme.sys [X]
S3 cmnsusbser; system32\DRIVERS\cmnsusbser.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-08 09:49 - 2015-04-08 09:49 - 00000837 _____ () C:\Users\vicky\Desktop\JRT.txt
2015-04-08 09:46 - 2015-04-08 09:46 - 02686959 _____ (Thisisu) C:\Users\vicky\Downloads\JRT.exe
2015-04-08 09:46 - 2015-04-08 09:46 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-VICKY-PC-Windows-7-Home-Premium-(32-bit).dat
2015-04-08 09:46 - 2015-04-08 09:46 - 00000000 ____D () C:\RegBackup
2015-04-08 09:43 - 2015-04-08 09:43 - 00004486 _____ () C:\Users\vicky\Desktop\AdwCleaner[S0].txt
2015-04-08 09:31 - 2015-04-08 09:39 - 00000000 ____D () C:\AdwCleaner
2015-04-08 09:31 - 2015-04-08 09:31 - 02208768 _____ () C:\Users\vicky\Downloads\AdwCleaner_4.200.exe
2015-04-08 09:29 - 2015-04-08 09:29 - 00060292 _____ () C:\Users\vicky\Desktop\mbam2.txt
2015-04-08 09:28 - 2015-04-08 09:28 - 00000828 _____ () C:\Users\vicky\Desktop\mbam.txt
2015-04-08 08:51 - 2015-04-08 09:26 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-08 08:50 - 2015-04-08 08:50 - 00001028 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-08 08:50 - 2015-04-08 08:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-08 08:50 - 2015-04-08 08:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-08 08:50 - 2015-04-08 08:50 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-08 08:50 - 2015-03-17 06:15 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-08 08:50 - 2015-03-17 06:15 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-08 08:50 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-08 08:49 - 2015-04-08 08:49 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\vicky\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-07 11:19 - 2015-04-07 11:19 - 00014386 _____ () C:\ComboFix.txt
2015-04-07 11:19 - 2015-04-07 11:19 - 00012568 _____ (Sysinternals - www.sysinternals.com) C:\Windows\system32\Drivers\PROCEXP113.SYS
2015-04-07 10:27 - 2015-04-07 10:23 - 05617096 ____R (Swearware) C:\Users\vicky\Desktop\ComboFix.exe
2015-04-07 10:25 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-07 10:25 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-07 10:25 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-07 10:25 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-07 10:25 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-07 10:25 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-07 10:25 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-07 10:25 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-07 10:24 - 2015-04-07 11:19 - 00000000 ____D () C:\Qoobox
2015-04-07 10:24 - 2015-04-07 11:09 - 00000000 ____D () C:\Windows\erdnt
2015-04-07 10:23 - 2015-04-07 10:23 - 05617096 ____R (Swearware) C:\Users\vicky\Downloads\ComboFix.exe
2015-04-07 08:42 - 2015-04-07 08:44 - 00033258 _____ () C:\Users\vicky\Downloads\Addition.txt
2015-04-07 08:41 - 2015-04-08 09:52 - 00012990 _____ () C:\Users\vicky\Downloads\FRST.txt
2015-04-07 08:40 - 2015-04-08 09:52 - 00000000 ____D () C:\FRST
2015-04-07 08:39 - 2015-04-07 08:40 - 01135104 _____ (Farbar) C:\Users\vicky\Downloads\FRST.exe
2015-04-07 08:24 - 2015-04-07 08:24 - 00001190 _____ () C:\Users\vicky\Desktop\Revo Uninstaller.lnk
2015-04-07 08:24 - 2015-04-07 08:24 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-04-07 08:21 - 2015-04-07 08:21 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\vicky\Downloads\revosetup95.exe
2015-04-05 10:34 - 2015-04-05 10:35 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-04 09:56 - 2015-04-04 09:56 - 00000000 ___SD () C:\Windows\system32\GWX
2015-03-31 10:06 - 2015-03-31 10:51 - 00027998 _____ () C:\Users\vicky\Desktop\Evaluationsbogen.odt
2015-03-31 09:43 - 2015-03-31 09:43 - 00024423 _____ () C:\Users\vicky\Downloads\Berichtvordruck_EVALUATION-MTV_2015.odt
2015-03-19 09:11 - 2015-03-19 09:11 - 00001793 _____ () C:\Users\vicky\Documents\Nepal - Verknüpfung.lnk
2015-03-15 15:23 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-03-15 15:23 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-03-15 15:23 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-03-15 15:23 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-03-15 15:23 - 2015-02-03 05:11 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-03-15 15:23 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-03-15 15:23 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-03-15 15:23 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-03-15 15:23 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-03-15 15:23 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-03-15 15:23 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-03-15 15:23 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-03-15 15:21 - 2015-01-09 01:44 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-03-11 19:37 - 2015-02-03 05:16 - 03973048 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-03-11 19:37 - 2015-02-03 05:16 - 03917760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-03-11 19:37 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-03-11 19:37 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-03-11 19:37 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-03-11 19:37 - 2015-02-03 05:12 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-03-11 19:37 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-03-11 19:37 - 2015-02-03 05:08 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-03-11 19:37 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-03-11 19:37 - 2015-01-09 04:48 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll
2015-03-11 19:37 - 2015-01-09 04:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll
2015-03-11 19:37 - 2015-01-09 04:48 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-03-11 19:36 - 2015-02-03 05:12 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2015-03-11 19:36 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-03-11 19:36 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-03-11 19:36 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-03-11 19:36 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-03-11 19:36 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-03-11 19:36 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-03-11 19:36 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-03-11 19:35 - 2015-02-26 05:11 - 02381312 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-03-11 19:35 - 2015-02-24 04:32 - 00342696 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-03-11 19:35 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-03-11 19:35 - 2015-02-21 02:27 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-03-11 19:35 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-03-11 19:35 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-03-11 19:35 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-03-11 19:35 - 2015-02-20 04:22 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-03-11 19:35 - 2015-02-20 04:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-03-11 19:35 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-03-11 19:35 - 2015-02-20 04:08 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-03-11 19:35 - 2015-02-20 04:08 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-03-11 19:35 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-03-11 19:35 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-03-11 19:35 - 2015-02-20 04:01 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-03-11 19:35 - 2015-02-20 04:00 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-03-11 19:35 - 2015-02-20 03:58 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-03-11 19:35 - 2015-02-20 03:56 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-03-11 19:35 - 2015-02-20 03:56 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-03-11 19:35 - 2015-02-20 03:56 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-03-11 19:35 - 2015-02-20 03:50 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-03-11 19:35 - 2015-02-20 03:41 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-03-11 19:35 - 2015-02-20 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-03-11 19:35 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-03-11 19:35 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-03-11 19:35 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-03-11 19:35 - 2015-02-20 03:24 - 00684544 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-03-11 19:35 - 2015-02-20 03:23 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-03-11 19:35 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-03-11 19:35 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-03-11 19:35 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-03-11 19:35 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-03-11 19:34 - 2015-03-06 07:15 - 00137656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-03-11 19:34 - 2015-03-06 07:15 - 00067512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-03-11 19:34 - 2015-03-06 07:10 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-03-11 19:34 - 2015-03-06 07:10 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-03-11 19:34 - 2015-03-06 07:09 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-03-11 19:34 - 2015-03-06 07:09 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-03-11 19:34 - 2015-03-06 07:07 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-03-11 19:34 - 2015-03-06 07:07 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-03-11 19:34 - 2015-03-06 07:06 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-03-11 19:34 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-03-11 19:29 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-03-11 19:29 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-03-11 19:29 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-03-11 19:29 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-03-11 19:29 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-03-11 19:29 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-03-11 19:29 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-08 09:48 - 2013-07-30 20:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-08 09:47 - 2009-07-14 06:34 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-08 09:47 - 2009-07-14 06:34 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-08 09:45 - 2012-01-09 19:32 - 00000000 ___RD () C:\Users\vicky\Dropbox
2015-04-08 09:43 - 2012-01-09 19:29 - 00000000 ____D () C:\Users\vicky\AppData\Roaming\Dropbox
2015-04-08 09:41 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-08 09:41 - 2009-07-14 06:39 - 00247898 _____ () C:\Windows\setupact.log
2015-04-08 09:40 - 2010-09-05 18:52 - 01163001 _____ () C:\Windows\WindowsUpdate.log
2015-04-08 09:40 - 2010-06-22 19:05 - 00391956 _____ () C:\Windows\PFRO.log
2015-04-08 09:17 - 2010-10-26 20:41 - 00000000 ____D () C:\ProgramData\ICQ
2015-04-07 11:19 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2015-04-07 11:12 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2015-04-07 08:11 - 2012-04-26 12:58 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-04-06 09:08 - 2011-07-12 19:41 - 00000000 ____D () C:\Users\vicky\AppData\Roaming\Skype
2015-04-02 08:32 - 2010-06-22 12:24 - 01621712 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-01 10:29 - 2011-01-31 20:04 - 00000000 ____D () C:\Users\vicky\Documents\EGL
2015-04-01 10:29 - 2010-12-28 17:48 - 00000000 ____D () C:\Users\vicky\Documents\Unikram
2015-04-01 08:52 - 2013-02-27 16:39 - 00000000 ____D () C:\Users\vicky\AppData\Roaming\Avira
2015-04-01 08:52 - 2013-02-27 16:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-01 08:50 - 2013-02-27 16:33 - 00000000 ____D () C:\ProgramData\Avira
2015-03-24 19:59 - 2013-05-22 07:56 - 00000000 ____D () C:\Users\vicky\Documents\Youcam
2015-03-17 21:37 - 2010-09-06 20:39 - 00000000 ____D () C:\Users\vicky\AppData\Roaming\SoftGrid Client
2015-03-16 20:42 - 2011-07-12 19:40 - 00000000 ___RD () C:\Program Files\Skype
2015-03-16 20:42 - 2011-07-12 19:40 - 00000000 ____D () C:\ProgramData\Skype
2015-03-16 09:58 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\tracing
2015-03-15 17:22 - 2009-07-14 06:33 - 00342624 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-03-15 15:57 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-03-15 15:37 - 2011-07-18 11:59 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-15 15:25 - 2013-08-16 21:55 - 00000000 ____D () C:\Windows\system32\MRT
2015-03-15 15:25 - 2010-06-22 12:24 - 119837696 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-03-15 15:11 - 2012-01-09 19:30 - 00000000 ____D () C:\Users\vicky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-03-11 19:06 - 2012-05-25 14:43 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-03-11 19:06 - 2011-09-28 17:50 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-03-11 18:40 - 2013-05-07 21:59 - 00037896 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-03-11 18:40 - 2013-02-27 16:33 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-03-11 18:40 - 2013-02-27 16:33 - 00105864 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
==================== Files in the root of some directories =======
2013-12-25 10:39 - 2013-12-25 10:39 - 49940480 _____ () C:\Program Files\GUTC7C2.tmp
2014-02-07 17:57 - 2014-04-03 22:38 - 0000106 _____ () C:\Users\vicky\AppData\Roaming\WB.CFG
2013-12-04 19:58 - 2013-12-04 19:58 - 0000848 _____ () C:\Users\vicky\AppData\Local\recently-used.xbel
2011-06-24 08:22 - 2012-02-08 10:10 - 0000952 ___SH () C:\ProgramData\KGyGaAvL.sys
Some content of TEMP:
====================
C:\Users\vicky\AppData\Local\temp\avgnt.exe
C:\Users\vicky\AppData\Local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvgjymm.dll
C:\Users\vicky\AppData\Local\temp\Quarantine.exe
C:\Users\vicky\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2012-11-30 13:44
==================== End Of Log ============================ --- --- ---
Vielen Vielen Dank nochmal! Ich hoffe jetzt ist alles soweit in Ordnung? |