crossbrowse u.ä. vollständig entfernt? Hallo,
ich hatte mir bei einem Download wohl Adware eingefangen. Jedenfalls veränderte sich meine Startseite beim Firefox und ich bekam Warnmeldungen von Avira.
Ich habe versucht alles zu entfernen und habe dabei auch Firefox deinstalliert. Ich kenne mich aber nicht gut aus, deswegen habe ich die Schritte versucht zu machen, die hier auf der Seite erklärt wurden und hänge mal die Log-Files an.
Defogger: Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 21:56 on 22/06/2015 (Rebekka)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=- Additions.txt
[CODE]Additional
FRST Logfile: Code:
scan result of Farbar Recovery Scan Tool (x64) Version:21-06-2015 01
Ran by Rebekka at 2015-06-22 22:05:32
Running from C:\Users\Rebekka\AppData\Local\Microsoft\Windows\INetCache\IE\IUF4524P
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-803216325-1454129970-1616761464-500 - Administrator - Disabled)
Gast (S-1-5-21-803216325-1454129970-1616761464-501 - Limited - Disabled)
Rebekka (S-1-5-21-803216325-1454129970-1616761464-1001 - Administrator - Enabled) => C:\Users\Rebekka
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus und Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
abDocs (HKLM-x32\...\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.07.2004 - Acer Incorporated)
abDocs Office AddIn (HKLM-x32\...\{DCBF3379-246B-47E1-8173-639B63940838}) (Version: 3.02.2000 - Acer Incorporated)
abFiles (HKLM-x32\...\{13885028-098C-4799-9B71-27DAC96502D5}) (Version: 2.00.3006 - Acer Incorporated)
abMedia (HKLM-x32\...\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.08.2003.3 - Acer Incorporated)
abPhoto (HKLM-x32\...\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 3.03.2004.4 - Acer Incorporated)
Acer Care Center (HKLM\...\{A424844F-CDB3-45E2-BB77-1DDE4A091E76}) (Version: 1.00.3013 - Acer Incorporated)
Acer Explorer Agent (HKLM\...\{4D0F42CF-1693-43D9-BDC8-19141D023EE0}) (Version: 2.00.3000 - Acer Incorporated)
Acer Launch Manager (HKLM\...\{C18D55BD-1EC6-466D-B763-8EEDDDA9100E}) (Version: 8.00.8115 - Acer Incorporated)
Acer Portal (HKLM-x32\...\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 3.06.2004 - Acer Incorporated)
Acer Power Management (HKLM\...\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.8106.0 - Acer Incorporated)
Acer Quick Access (HKLM\...\{C1FA525F-D701-4B31-9D32-504FC0CF0B98}) (Version: 1.01.3016.0 - Acer Incorporated)
Acer Recovery Management (HKLM\...\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.8108 - Acer Incorporated)
Acer User Experience Improvement Program App Monitor Plugin (HKLM\...\{978724F6-1863-4DD5-9E66-FB77F5AB5613}) (Version: 1.02.3005 - Acer Incorporated)
Acer User Experience Improvement Program Framework (HKLM\...\{12A718F2-2357-4D41-9E1F-18583A4745F7}) (Version: 1.02.3005 - Acer Incorporated)
Acer Video Player (HKLM-x32\...\{B6846F20-4821-11E3-8F96-0800200C9A66}) (Version: 1.00.2010.3 - Acer Incorporated)
Adobe Creative Suite 2 (HKLM-x32\...\{0134A1A1-C283-4A47-91A1-92F19F960372}) (Version: - )
AOP Framework (HKLM-x32\...\{4A37A114-702F-4055-A4B6-16571D4A5353}) (Version: 3.07.2004.0 - Acer Incorporated)
Avira (HKLM-x32\...\{8467e01f-0496-42ce-b247-88ef205b4880}) (Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.11.574 - Avira Operations GmbH & Co. KG)
CyberLink PhotoDirector 3 (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.1.5524 - CyberLink Corp.)
CyberLink Power Media Player 12 (HKLM-x32\...\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.3.4218 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.4220 - CyberLink Corp.)
EPSON WF-2530 Series Printer Uninstall (HKLM\...\EPSON WF-2530 Series) (Version: - SEIKO EPSON Corporation)
Foxit PhantomPDF (HKLM-x32\...\{D4DF5498-C95C-4A02-9951-725FB2D7BC0D}) (Version: 6.0.121.624 - Foxit Corporation)
GIMP 2.8.14 (HKLM\...\GIMP-2_is1) (Version: 2.8.14 - The GIMP Team)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3574 - Intel Corporation)
Intel(R) Trusted Execution Engine (HKLM\...\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1064 - Intel Corporation)
Malwarebytes Anti-Malware Version 2.1.6.1022 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.6.1022 - Malwarebytes Corporation)
McAfee LiveSafe – Internet Security (HKLM-x32\...\MSC) (Version: 13.6.1599 - McAfee, Inc.)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{d491dd9d-2eda-4d75-b504-1a201436e7fd}) (Version: 11.0.61030.0 - Microsoft Corporation)
PDF24 Creator 6.9.2 (HKLM-x32\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.322 - Qualcomm Atheros Communications)
Qualcomm Atheros WLAN and Bluetooth Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 12.33 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.39059 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.33.529.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7288 - Realtek Semiconductor Corp.)
Spotify (HKLM-x32\...\Spotify) (Version: 0.9.6.81.gd359a796 - Spotify AB)
Suite Specific (x32 Version: 2.0.0 - Adobe Systems, Incorporated) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-803216325-1454129970-1616761464-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
==================== Restore Points =========================
15-06-2015 14:47:08 Nitro Reader 3 wird installiert
22-06-2015 16:39:11 Nitro Reader 3 wurde entfernt
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0653988E-7172-4927-B134-4620C947CBEC} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => C:\Windows\system32\compattel\DiagTrackRunner.exe [2015-03-16] (Microsoft Corporation)
Task: {0A2751E4-1766-4943-A9A6-3927F63A8DE6} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-05-06] (Microsoft Corporation)
Task: {0B5EF587-0371-40C6-9A26-898FF9020AF4} - System32\Tasks\Software Update Application => C:\ProgramData\OEM\UpgradeTool\ListCheck.exe [2014-06-08] (Acer Incorporated)
Task: {11A50953-88B2-4669-A214-1CF04E99F4B3} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => schtasks
Task: {1389282E-F668-489F-B57A-8EC6EDFE1C88} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {2BF4F092-DAF5-456F-B0AB-95D50AEE117C} - System32\Tasks\Recovery Management\Notification => C:\Program Files\Acer\Acer Recovery Management\Notification\Notification.exe [2014-06-17] (Acer Incorporated)
Task: {51A18307-A5BE-4FEB-A76A-E483FDF3BAE9} - System32\Tasks\Launch Manager => C:\Program Files\Acer\Acer Launch Manager\LMLauncher.exe [2014-12-30] (Acer Incorporate)
Task: {5D907F8F-44F3-4EA3-BBF6-94061AD17930} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {769B4F1A-FC5A-405A-9E18-042E6F2618D1} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {852E6F47-E040-4060-A45A-9741FBB136B7} - System32\Tasks\ACCAgent => C:\Program Files (x86)\Acer\Care Center\LiveUpdateAgent.exe [2014-08-29] ()
Task: {8709471D-F0C8-43B4-9AAD-E5A2155FF3DC} - System32\Tasks\ACC => C:\Program Files (x86)\Acer\Care Center\LiveUpdateChecker.exe [2014-08-29] ()
Task: {8C853093-AD7F-4076-B1E3-E492034E9D5C} - System32\Tasks\Quick Access Quick Launcher => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {8FE949DD-B643-42D6-82A6-6118DEC3C31D} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Time-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {990906C2-06F0-49C9-AE10-928CB862289C} - System32\Tasks\AcerCloud => C:\Program Files (x86)\Acer\Acer Portal\AcerPortal.exe [2015-05-06] (Acer)
Task: {AD50163C-08B8-49BD-AFB1-261B5E744858} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-06-10] (Microsoft Corporation)
Task: {BB4FFDFF-A203-4B74-9133-C9424F0838AD} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
Task: {BEBBAE1F-AFBB-45B4-BAB6-BBD7172BB666} - System32\Tasks\UbtFrameworkService => C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe [2014-03-13] (TODO: <Company name>)
Task: {D0F7780E-CF8F-4666-9B8B-D19C85BC3BD9} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTrayLauncher.exe [2014-07-22] (Acer Incorporated)
Task: {DD7DC33F-FDEB-4D09-80EE-6C44E278AD2E} - System32\Tasks\Quick Access => C:\Program Files\Acer\Acer Quick Access\QALauncher.exe [2014-06-26] (Acer Incorporate)
Task: {F1237C24-C758-41D9-AA5F-64EA8461D1BA} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-10s => C:\Windows\system32\GWX\GWX.exe [2015-05-06] (Microsoft Corporation)
==================== Loaded Modules (Whitelisted) ==============
2014-11-22 16:54 - 2012-04-24 12:43 - 00254512 _____ () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
2014-04-29 03:38 - 2014-04-29 03:38 - 00011264 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\ActivateDesktopDebugger\ActivateDesktopDebugger.dll
2014-04-29 03:35 - 2014-04-29 03:35 - 00086016 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\Modules\Map\MAP.dll
2014-04-29 03:42 - 2014-04-29 03:42 - 00012928 _____ () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
2015-05-06 16:14 - 2015-05-06 16:14 - 00092928 _____ () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe
2015-05-06 16:14 - 2015-05-06 16:14 - 00090368 _____ () C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
2015-06-04 20:48 - 2015-06-04 20:48 - 00015616 _____ () C:\Windows\assembly\GAC_MSIL\MyService\1.0.0.1__2dfa3f50f0bed57d\MyService.dll
2015-05-06 10:08 - 2015-05-06 10:08 - 00013568 _____ () C:\Program Files (x86)\Acer\AOP Framework\ServiceInterface.dll
2014-07-01 10:57 - 2014-07-01 10:57 - 00279296 _____ () C:\Program Files (x86)\Acer\AcerCloud Docs\libcurl.dll
2015-05-08 10:41 - 2015-05-08 10:41 - 00203008 _____ () C:\Program Files (x86)\Acer\abPhoto\curllib.dll
2015-05-08 10:41 - 2015-05-08 10:41 - 00654552 _____ () C:\Program Files (x86)\Acer\abPhoto\sqlite3.dll
2015-05-08 10:41 - 2015-05-08 10:41 - 00641792 _____ () C:\Program Files (x86)\Acer\abPhoto\tag.dll
2015-05-08 10:41 - 2015-05-08 10:41 - 00119552 _____ () C:\Program Files (x86)\Acer\abPhoto\OpenLDAP.dll
2015-05-06 16:15 - 2015-05-06 16:15 - 00279296 _____ () C:\Program Files (x86)\Acer\abDocs\libcurl.dll
==================== Safe Mode (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2ce.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-803216325-1454129970-1616761464-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\acer01.jpg
DNS Servers: 192.168.138.254
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{E36E08AB-BFD5-41E4-A5DC-59A9C520D3D0}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{C6CA5BC3-D225-44D1-8CE1-0B754081A29D}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{D1487E55-BCB4-46C7-8F89-EE33887BEE0B}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{E9B55FCF-928C-4C0B-9A86-D0038F4FEE27}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{134B1523-77FD-45C9-901D-3E88A9363889}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{846263F6-B423-4510-920D-AE07E5DEA0F9}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{0FFA6AB4-D4F4-4E2B-A090-374563DFB0DC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{0C0A6A44-5F2E-44E6-A6A0-487F68675C72}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{D9AEFAE9-0EBE-498D-AE09-A2218D6ED8C9}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{33EBD72D-9A12-46C7-A2DD-2E2ECA72E38B}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{8C471226-D90C-4D71-B3AA-0D4E2A670318}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{064CDAB3-0565-4E8E-96EC-278BA4741611}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{770500DF-4813-4C4F-A5C6-A06FDBD0884A}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{A77AD9B5-0D88-43AD-9294-03094B2B6261}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{1C94BC55-32A9-4427-A9EF-E06AC61088C2}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{3E0FE99C-D9EA-41B3-BF2C-124F8C2A12E4}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Play.exe
FirewallRules: [{71203AFF-72E8-4C87-900E-CAE0333E153C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{09ACCEBF-B917-4B66-AF6A-A5E7DB84B671}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{AC83408A-6CAA-4D37-A48B-AC25853298A6}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{06BE1187-7D1D-4582-AE53-74EC1532BA65}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{0C717AEC-2017-415D-B7BE-327FBF959789}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{D5D11108-190B-4C92-8D0B-D33082A580EF}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{4149BC7A-AAEB-442A-9C5C-A1F704D98EB6}] => (Allow) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
FirewallRules: [{00ACFD8F-7E60-46E8-AE34-90ACB62F809B}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{B4375310-757E-42F1-A6D0-4C7A5B3F4EB1}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\DMCDaemon.exe
FirewallRules: [{CBCFF799-AD7E-44C4-856B-C4466B32675A}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{CDA02CE4-C824-406F-9059-A5FBBB7C2124}] => (Allow) C:\Program Files (x86)\Acer\abPhoto\WindowsUpnp.exe
FirewallRules: [{DEF82F83-1E02-4256-8CAF-12CF32F2D87B}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{35948912-A3AA-4919-A4ED-13654962A10D}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{C201AF7C-EC85-4160-832C-3EF65D70038B}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{B450CB49-01BC-4F66-8C2B-28012D4B9CB5}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{085755E2-3D0D-4C1B-8902-0C641A0F6763}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{46C1F317-BF6E-4687-9C71-0BE8C5C7A8C9}] => (Allow) C:\Program Files (x86)\Acer\abMedia\DMCDaemon.exe
FirewallRules: [{0F657EF0-BE61-4AA9-8635-7E8AD979542F}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
FirewallRules: [{CB364EDF-2062-4F61-821E-48970EBA88C6}] => (Allow) C:\Program Files (x86)\Acer\abMedia\WindowsUpnpMV.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/22/2015 08:27:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Au_.exe, Version: 1.36.1.22, Zeitstempel: 0x50be00b6
Name des fehlerhaften Moduls: uqxbpyr.dll, Version: 0.0.0.0, Zeitstempel: 0x5587ed3b
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00014f4b
ID des fehlerhaften Prozesses: 0x980
Startzeit der fehlerhaften Anwendung: 0xAu_.exe0
Pfad der fehlerhaften Anwendung: Au_.exe1
Pfad des fehlerhaften Moduls: Au_.exe2
Berichtskennung: Au_.exe3
Vollständiger Name des fehlerhaften Pakets: Au_.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Au_.exe5
Error: (06/22/2015 08:20:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: GWXUX.exe, Version: 6.3.9600.17813, Zeitstempel: 0x554a15f3
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17736, Zeitstempel: 0x550f4336
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000003b2de
ID des fehlerhaften Prozesses: 0x196c
Startzeit der fehlerhaften Anwendung: 0xGWXUX.exe0
Pfad der fehlerhaften Anwendung: GWXUX.exe1
Pfad des fehlerhaften Moduls: GWXUX.exe2
Berichtskennung: GWXUX.exe3
Vollständiger Name des fehlerhaften Pakets: GWXUX.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: GWXUX.exe5
Error: (06/22/2015 05:02:10 PM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail (876) WindowsMail0: Die Sicherung wurde abgebrochen, weil sie vom Client angehalten wurde, oder weil die Verbindung mit dem Client unterbrochen wurde.
Error: (06/22/2015 04:59:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: avscan.exe, Version: 15.0.11.574, Zeitstempel: 0x55659e49
Name des fehlerhaften Moduls: AVSCPLR.DLL, Version: 15.0.11.550, Zeitstempel: 0x555acc76
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000539b
ID des fehlerhaften Prozesses: 0x624
Startzeit der fehlerhaften Anwendung: 0xavscan.exe0
Pfad der fehlerhaften Anwendung: avscan.exe1
Pfad des fehlerhaften Moduls: avscan.exe2
Berichtskennung: avscan.exe3
Vollständiger Name des fehlerhaften Pakets: avscan.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: avscan.exe5
Error: (06/22/2015 04:29:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.17840, Zeitstempel: 0x555fe1bb
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000409
Fehleroffset: 0x00000000
ID des fehlerhaften Prozesses: 0x1bdc
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3
Vollständiger Name des fehlerhaften Pakets: IEXPLORE.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: IEXPLORE.EXE5
Error: (06/16/2015 08:15:48 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (06/15/2015 08:35:24 PM) (Source: MsiInstaller) (EventID: 11730) (User: Josephine2)
Description: Product: Adobe Stock Photos 1.0 -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an Administrator, or contact your technical support group for assistance.
Error: (06/15/2015 08:35:19 PM) (Source: MsiInstaller) (EventID: 11721) (User: Josephine2)
Description: Product: Adobe Help Center 1.0 -- Error 1721.There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor. Action: UninstallHelp, location: C:\Program Files (x86)\Adobe\Adobe Help Center\ahc.exe, command: -uninstall AdobeHelpCenter 1.0 en_US
Error: (06/15/2015 08:35:09 PM) (Source: MsiInstaller) (EventID: 11404) (User: Josephine2)
Description: Product: Adobe Common File Installer -- Error 1404.Could not delete key \SOFTWARE\Adobe\CommonFiles\Adobe\installer. System error . Verify that you have sufficient access to that key, or contact your support personnel.
Error: (06/15/2015 08:34:56 PM) (Source: MsiInstaller) (EventID: 11730) (User: Josephine2)
Description: Product: Adobe Bridge 1.0 -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an Administrator, or contact your technical support group for assistance.
System errors:
=============
Error: (06/22/2015 09:47:26 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Avira Service Host" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 10000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/22/2015 09:47:26 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Druckwarteschlange" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 5000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/22/2015 09:47:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/22/2015 09:47:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Windows Presentation Foundation-Schriftartcache 3.0.0.0" wurde unerwartet beendet. Dies ist bereits 2 Mal passiert.
Error: (06/22/2015 09:47:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Intel(R) Capability Licensing Service Interface" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 0 Millisekunden durchgeführt: Neustart des Diensts.
Error: (06/22/2015 09:45:49 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Search" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:
%%1056
Error: (06/22/2015 09:45:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "User Experience Improvement Program" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/22/2015 09:45:21 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Quick Access RadioMgr Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/22/2015 09:45:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "ePower Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Error: (06/22/2015 09:45:19 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Quick Access Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.
Microsoft Office:
=========================
Error: (06/22/2015 08:27:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Au_.exe1.36.1.2250be00b6uqxbpyr.dll0.0.0.05587ed3bc000000500014f4b98001d0ad18fb9f9aa9C:\Users\Rebekka\AppData\Local\Temp\~nsu.tmp\Au_.exeC:\Users\Rebekka\AppData\Local\Temp\nszAB15.tmp\uqxbpyr.dll5a33ef3b-190c-11e5-8268-206a8aa45d80
Error: (06/22/2015 08:20:09 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GWXUX.exe6.3.9600.17813554a15f3ntdll.dll6.3.9600.17736550f4336c0000005000000000003b2de196c01d0ad1806117f13C:\Windows\System32\GWX\GWXUX.exeC:\Windows\SYSTEM32\ntdll.dll4fe7eea4-190b-11e5-8268-206a8aa45d80
Error: (06/22/2015 05:02:10 PM) (Source: ESENT) (EventID: 215) (User: )
Description: WinMail876WindowsMail0:
Error: (06/22/2015 04:59:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: avscan.exe15.0.11.57455659e49AVSCPLR.DLL15.0.11.550555acc76c00000050000539b62401d0acfbd9f13d8fC:\Program Files (x86)\Avira\Antivirus\avscan.exeC:\Program Files (x86)\Avira\Antivirus\AVSCPLR.DLL5374e216-18ef-11e5-8268-206a8aa45d80
Error: (06/22/2015 04:29:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: IEXPLORE.EXE11.0.9600.17840555fe1bbunknown0.0.0.000000000c0000409000000001bdc01d0acf7cb99e1bcC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEunknown127a19a8-18eb-11e5-8267-206a8aa45d80
Error: (06/16/2015 08:15:48 AM) (Source: Customer Experience Improvement Program) (EventID: 1008) (User: )
Description: 80070005
Error: (06/15/2015 08:35:24 PM) (Source: MsiInstaller) (EventID: 11730) (User: Josephine2)
Description: Product: Adobe Stock Photos 1.0 -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an Administrator, or contact your technical support group for assistance.(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (06/15/2015 08:35:19 PM) (Source: MsiInstaller) (EventID: 11721) (User: Josephine2)
Description: Product: Adobe Help Center 1.0 -- Error 1721.There is a problem with this Windows Installer package. A program required for this install to complete could not be run. Contact your support personnel or package vendor. Action: UninstallHelp, location: C:\Program Files (x86)\Adobe\Adobe Help Center\ahc.exe, command: -uninstall AdobeHelpCenter 1.0 en_US (NULL)(NULL)(NULL)(NULL)(NULL)
Error: (06/15/2015 08:35:09 PM) (Source: MsiInstaller) (EventID: 11404) (User: Josephine2)
Description: Product: Adobe Common File Installer -- Error 1404.Could not delete key \SOFTWARE\Adobe\CommonFiles\Adobe\installer. System error . Verify that you have sufficient access to that key, or contact your support personnel.(NULL)(NULL)(NULL)(NULL)(NULL)
Error: (06/15/2015 08:34:56 PM) (Source: MsiInstaller) (EventID: 11730) (User: Josephine2)
Description: Product: Adobe Bridge 1.0 -- Error 1730.You must be an Administrator to remove this application. To remove this application, you can log on as an Administrator, or contact your technical support group for assistance.(NULL)(NULL)(NULL)(NULL)(NULL)
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU N2940 @ 1.83GHz
Percentage of memory in use: 42%
Total physical RAM: 3977.98 MB
Available physical RAM: 2295.22 MB
Total Pagefile: 4681.98 MB
Available Pagefile: 2483.84 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:451.17 GB) (Free:410.09 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 30688187)
Partition: GPT Partition Type.
==================== End of log ============================ --- --- --- Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-06-22 22:18:27
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000029 ST500LT012-1DG142 rev.0001SDM1 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\Rebekka\AppData\Local\Temp\kflyraow.sys
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [700:724] fffff960009a52d0
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.06.2015
Suchlauf-Zeit: 20:57:25
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.03.09.05
Rootkit Datenbank: v2015.06.22.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Rebekka
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 345119
Verstrichene Zeit: 29 Min, 49 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 3
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [6c0d66dd0e7c9f973d57e8457590e020],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [c1b8d0733852af87286d8da04cb9f808],
PUP.Optional.Wajam.A, HKU\S-1-5-21-803216325-1454129970-1616761464-1001\SOFTWARE\WajIEnhance, In Quarantäne, [bcbdc97a5d2d3df94862f1c1cb38936d],
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 6
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG),Ersetzt,[215887bcb7d3a294e7ba25b0b3527987]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG&q={searchTerms}),Ersetzt,[6613e261e7a3ab8b51bf963f0afb56aa]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG&q={searchTerms}),Ersetzt,[dc9da69d99f1bf777b955481778ec63a]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG),Ersetzt,[9adf2a19ed9dbf774e53cf0607fecb35]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG&q={searchTerms}),Ersetzt,[245546fd9ceea88e89871cb911f449b7]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1434977280&z=c7ee753dadbcce45b7c08cdg9zec7zbtem5mboam4b&from=tugs&uid=ST500LT012-1DG142_S3PJ9RYGXXXXS3PJ9RYG&q={searchTerms}),Ersetzt,[c0b9cd768a00ec4a2fe150854abb738d]
Ordner: 1
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
Dateien: 20
PUP.Optional.SkyTech.A, C:\Users\Rebekka\AppData\Local\Temp\xtmp1021049453\QQBrowserFrame.dll, In Quarantäne, [ceab1d26acde2412643cfa067e8432ce],
PUP.Optional.MyStartSearch.A, C:\Users\Rebekka\AppData\Local\Temp\b817f4b7-17ae-4da3-8c93-01d6356b93f9\lly_mystartsearch.exe, In Quarantäne, [9fda90b357335bdb417cd54338ced32d],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\0d9b30bf-3dd8-4d33-b489-0d779fb7ceb6-1-6, In Quarantäne, [e9906ad9494191a50e6345895da67e82],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\0d9b30bf-3dd8-4d33-b489-0d779fb7ceb6-1-7, In Quarantäne, [5029d172e2a88babf879c9055aa93dc3],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\0d9b30bf-3dd8-4d33-b489-0d779fb7ceb6-5, In Quarantäne, [f386b68d0d7d7bbb0071d3fb3fc44cb4],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\0d9b30bf-3dd8-4d33-b489-0d779fb7ceb6-5_user, In Quarantäne, [d2a7ee55bbcf2c0aacc507c70201a65a],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\0d9b30bf-3dd8-4d33-b489-0d779fb7ceb6-1-6.job, In Quarantäne, [84f541021e6c7fb7dd90b6759d68f907],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\0d9b30bf-3dd8-4d33-b489-0d779fb7ceb6-1-7.job, In Quarantäne, [5f1a2a19800abb7b4a23cb608481fc04],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\0d9b30bf-3dd8-4d33-b489-0d779fb7ceb6-5.job, In Quarantäne, [02771c2784066cca6508a68507fe8878],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\0d9b30bf-3dd8-4d33-b489-0d779fb7ceb6-5_user.job, In Quarantäne, [69102c1794f681b5d6970526a065b34d],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\globalupdate.exe, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\globalupdateBroker.exe, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\globalupdateCrashHandler.exe, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\globalupdateHelper.msi, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\globalupdateOnDemand.exe, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\goopdate.dll, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\goopdateres_en.dll, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\npglobalupdateUpdate4.dll, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\psmachine.dll, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
PUP.Optional.GlobalUpdate.A, C:\Users\Rebekka\AppData\Local\Temp\comh.198740\psuser.dll, In Quarantäne, [5029e063f298082ecbbe8ff34cb7bf41],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) |