Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 22.04.2014, 19:49   #1
caiphi
 
Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Icon17

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Der Windows 7 Rechner meiner Tochter ist Adware und anderer Malware verseucht. Beim Scan mit Malwarbytes wurde folgendes gefunden: mysearchdial, savingsbull, lizardlink, savesense, browsefox, valueapps, zulagames, crossrider, Qone8, awesomehlp, dealply, quickstart, hqtotals, mediaenhance, smartbar, alextb, installcore, advancesystemprotector, snapdo, installbrain, filescout, conduit, adpeak, valueappsplugin, viddyhd, optimuminstaller, cooltech, regcleanerpro, bundleinstaller, optimizerpro, bundlore, domalq, subtab, bandoo, trojan.Dropper.FJ, Supercoolapps, Searchprotect, Backdoor.bot, Skytech, Silenceinstall, WPmanager, searchprotect, pcperformer, Speedanalysis2, Funmoods und adpeak.

Ich dachte ich könnte das Problem durch einfaches Deinstallieren über Revo Uninstaller selbst beheben, aber nachdem ich ein VO Package deinstalliert hatte, hatte ich mir fast das ganze System zerschossen. Über Systemwiederherstellung konnte ich es wieder retten und habe fast alles deinstalliert bekommen aber nach der erneuten Deinstallation des VO-Package ging der Revo Uninstaller wieder nicht mehr.

So habe ich Malwarebytes laufen lassen. Der zeigte mir das Ausmaß des Elends, weshalb ich mich nach langer Zeit ein zweites Mal an Euch wende. Auch nach der Deinstallation der ganzen Adware hat der Internet Explorer und Google Chrome noch ein „Eigenleben mit Umleitungen und popup Fenstern auf sehr aggressive Werbung.

Ich habe jetzt die ersten 3 Schritte befolgt und schicke Euch die Logs von frst.txt und addition.txt.

[CODE]#
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014
Ran by xyz (administrator) on xyz on 22-04-2014 18:52:16
Running from C:\Users\xyz\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Windows\AsScrPro.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe
() C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe
() C:\Program Files (x86)\Lizardlink\updateLizardlink.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe
(Jumping Bytes) C:\Program Files (x86)\PureSync\PureSyncTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\Lizardlink\bin\FilterApp_C64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\Lizardlink\bin\Lizardlink.BrowserAdapter.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
() C:\Program Files (x86)\Zula Games\BackgroundHost.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-09-19] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2816808 2011-07-21] (Synaptics Incorporated)
HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [98088 2011-07-21] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-22] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [PureSync] => C:\Program Files (x86)\PureSync\PureSyncTray.exe [906928 2013-12-20] (Jumping Bytes)
HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
AppInit_DLLs: C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL => C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL File Not Found
AppInit_DLLs-x32: c:\progra~2\optimi~1\optpro~1.dll => "c:\progra~2\optimi~1\optpro~1.dll" File Not Found
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
URLSearchHook: HKLM-x32 - appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.)
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
SearchScopes: HKLM - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = 
SearchScopes: HKLM-x32 - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
SearchScopes: HKLM-x32 - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
SearchScopes: HKCU - URL hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3319116&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP5C705B91-74C4-49A1-A0D9-25AFC5B7A96E&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}
SearchScopes: HKCU - {10F02070-5C8C-4E0B-9D76-ED5DEC00A416} URL = hxxp://de.wikipedia.org/w/index.php?title=Spezial:Suche&search={searchTerms}
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
SearchScopes: HKCU - {433C345D-C1DE-4AE3-9E63-DFA494815841} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKCU - {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0C0EyBtA0E0DtA0EzzzztN0D0Tzu0CyBzztAtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=923418304&ir=
SearchScopes: HKCU - {7F1A9171-10E2-4C11-A42A-253499CDF7C5} URL = hxxp://dict.leo.org/ende?lp=ende&lang=de&searchLoc=0&cmpType=relaxed&sectHdr=on&spellToler=on&chinese=both&pinyin=diacritic&search={searchTerms}&relink=on
SearchScopes: HKCU - {C177248B-A9BC-4AF0-99CC-32A2CE37D81E} URL = hxxp://www.dict.cc/?s={searchTerms}
SearchScopes: HKCU - {DCBF59AF-92DF-4CD7-A341-6F448E532676} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=msd3_14_11_ch&cd=2XzuyEtN2Y1L1Qzu0CzzyCtDtDtDtDyEtAyD0FyCtA0EzzzztN0D0Tzu0SzztDyDtN1L2XzutBtFtCzztFtBtFtDtN1L1CzutCyEtDtAtDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StByByCyD0AyDyBtCtG0DtA0ByDtG0DzyzzzytGzyyD0FzytGtDzz0FyD0ByBzy0FtAzz0FyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StA0A0DyEtAtD0AtBtGyDzz0AtCtGtB0DyE0AtGtDyBtCyEtGyEzztBtDyD0AyEtD0EtByCyD2Q&cr=1048254177&ir=
BHO: media enhance - {11111111-1111-1111-1111-110411411150} - C:\Program Files (x86)\media enhance\media enhance-bho64.dll No File
BHO: HQTotalS - {11111111-1111-1111-1111-110511311172} - C:\Program Files (x86)\HQTotalS\HQTotalS-bho64.dll No File
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.)
BHO-x32: SaveSense - {71e129ff-6c2a-4984-818c-7e2c998b8d99} - C:\Users\xyz\AppData\Local\SaveSense\SaveSenseIE.dll No File
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: ValueApps - {93DBF2BB-A2B3-4683-A92E-57E60751F346} - C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll (Conduit Ltd.)
BHO-x32: Zula Games - {A9337080-7CBF-4E3E-80C1-3867BEDD88E0} - C:\Program Files (x86)\Zula Games\ScriptHost.dll (ZulaGames.com)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll No File
Toolbar: HKLM-x32 - appbarioDE Toolbar - {525ba996-1ce4-4677-91c5-9fc4ead2d245} - C:\Program Files (x86)\appbarioDE\prxtbappb.dll (Conduit Ltd.)
Toolbar: HKLM-x32 - No Name - {3004627E-F8E9-4E8B-909D-316753CBA923} -  No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.updaterss.com/SaveSenseLive Update;version=3 - C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense)
FF Plugin-x32: @tools.updaterss.com/SaveSenseLive Update;version=9 - C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll (SaveSense)
FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF Extension: Widget context - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2014-04-22]
FF HKLM-x32\...\Firefox\Extensions: [zulagames@ZulaGames.com] - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com
FF Extension: Zula Games - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com [2013-10-04]
FF HKLM-x32\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
FF Extension: Speed Analysis 2 - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com [2013-10-04]
FF HKCU\...\Firefox\Extensions: [zulagames@ZulaGames.com] - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com
FF Extension: Zula Games - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\zulagames@ZulaGames.com [2013-10-04]
FF HKCU\...\Firefox\Extensions: [speedanalysis02@SpeedAnalysis.com] - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com
FF Extension: Speed Analysis 2 - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\speedanalysis02@SpeedAnalysis.com [2013-10-04]

Chrome: 
=======
CHR HomePage: 
CHR StartupUrls: "hxxp://www.google.de/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Extension: (YouTube) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-15]
CHR Extension: (Google-Suche) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-15]
CHR Extension: (HQ-Video-Pro-1.9) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm [2014-03-22]
CHR Extension: (media enhance) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo [2014-03-22]
CHR Extension: (Google Wallet) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-22]
CHR Extension: (Widget context) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp [2014-04-22]
CHR Extension: (Google Mail) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-15]
CHR HKCU\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24]
CHR HKLM-x32\...\Chrome\Extension: [gflandjopdloblmlcoiidmncpinmmacn] - C:\Users\xyz\AppData\Roaming\zulagames\zulagames.crx [2013-07-01]
CHR HKLM-x32\...\Chrome\Extension: [jainjonnknhmbbkibcbmhihbopigapdm] - C:\Program Files (x86)\Lizardlink\jainjonnknhmbbkibcbmhihbopigapdm.crx [2013-07-01]
CHR HKLM-x32\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24]
CHR HKLM-x32\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx [2014-03-16]

==================== Services (Whitelisted) =================

R2 Level Quality Watcher; C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe [710976 2014-01-27] ()
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
S2 savesenselive; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-03-15] (SaveSense)
S3 savesenselivem; C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920 2014-03-15] (SaveSense)
R2 Update Lizardlink; C:\Program Files (x86)\Lizardlink\updateLizardlink.exe [350496 2014-04-22] ()
R2 Util Lizardlink; C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe [350496 2014-04-22] ()
S2 70e6ca8c; "C:\Windows\system32\rundll32.exe" "c:\progra~2\optimi~1\OptProCrashSvc.dll",ServiceMain

==================== Drivers (Whitelisted) ====================

R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [16768 2011-09-20] (ASUSTek Computer Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-22] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61120 2014-03-22] (StdLib)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-22 18:52 - 2014-04-22 18:52 - 00023395 _____ () C:\Users\xyz\Downloads\FRST.txt
2014-04-22 18:51 - 2014-04-22 18:52 - 00000000 ____D () C:\FRST
2014-04-22 18:51 - 2014-04-22 18:51 - 02061312 _____ (Farbar) C:\Users\xyz\Downloads\FRST64.exe
2014-04-22 18:48 - 2014-04-22 18:48 - 00000494 _____ () C:\Users\xyz\Desktop\defogger_disable.log
2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable
2014-04-22 18:47 - 2014-04-22 18:47 - 00050477 _____ () C:\Users\xyz\Downloads\Defogger.exe
2014-04-22 18:28 - 2014-04-22 18:28 - 00128584 _____ () C:\Users\xyz\Desktop\20140422_1827_malware_scan.txt
2014-04-22 17:06 - 2014-04-22 17:06 - 00000000 ____D () C:\Program Files\SavingsBull
2014-04-22 16:55 - 2014-04-22 16:56 - 00000000 ____D () C:\AdwCleaner
2014-04-22 16:54 - 2014-04-22 16:54 - 01335637 _____ () C:\Users\xyz\Downloads\adwcleaner.exe
2014-04-22 16:51 - 2014-04-22 17:08 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-22 16:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-22 16:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-22 16:51 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-22 14:51 - 2014-04-22 14:53 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files\iTunes
2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod
2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7}
2014-04-22 14:31 - 2014-04-22 14:31 - 00000000 ____D () C:\ProgramData\Systweak
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList
2014-04-13 12:00 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-13 12:00 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-13 12:00 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-13 12:00 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-13 11:59 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-13 11:59 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-13 11:59 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-13 11:59 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-13 11:59 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-13 11:59 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-13 11:59 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-13 11:59 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-13 11:59 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-13 11:59 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-13 11:59 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-13 11:59 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-13 11:26 - 2014-04-22 15:21 - 00003108 _____ () C:\Windows\System32\Tasks\RegClean Pro
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97}
2014-03-23 00:42 - 2014-04-22 14:27 - 00000000 ____D () C:\ProgramData\Free Download Manager
2014-03-23 00:41 - 2014-04-22 13:37 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Free Download Manager

==================== One Month Modified Files and Folders =======

2014-04-22 18:53 - 2013-03-15 17:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-22 18:52 - 2014-04-22 18:52 - 00023395 _____ () C:\Users\xyz\Downloads\FRST.txt
2014-04-22 18:52 - 2014-04-22 18:51 - 00000000 ____D () C:\FRST
2014-04-22 18:51 - 2014-04-22 18:51 - 02061312 _____ (Farbar) C:\Users\xyz\Downloads\FRST64.exe
2014-04-22 18:48 - 2014-04-22 18:48 - 00000494 _____ () C:\Users\xyz\Desktop\defogger_disable.log
2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable
2014-04-22 18:48 - 2014-03-15 20:47 - 00000320 _____ () C:\Windows\Tasks\MySearchDial.job
2014-04-22 18:48 - 2013-01-10 19:09 - 00000000 ____D () C:\Users\xyz
2014-04-22 18:47 - 2014-04-22 18:47 - 00050477 _____ () C:\Users\xyz\Downloads\Defogger.exe
2014-04-22 18:43 - 2014-03-15 20:38 - 00000952 _____ () C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job
2014-04-22 18:40 - 2014-03-15 20:39 - 00000320 _____ () C:\Windows\Tasks\AppCloudUpdater.job
2014-04-22 18:38 - 2014-03-15 20:38 - 00000320 _____ () C:\Windows\Tasks\SaveSense.job
2014-04-22 18:28 - 2014-04-22 18:28 - 00128584 _____ () C:\Users\xyz\Desktop\20140422_1827_malware_scan.txt
2014-04-22 18:20 - 2013-03-15 17:16 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-22 18:13 - 2012-08-22 09:17 - 02047682 _____ () C:\Windows\WindowsUpdate.log
2014-04-22 17:40 - 2014-03-16 18:40 - 00001598 _____ () C:\Windows\Tasks\media enhance-updater.job
2014-04-22 17:40 - 2014-03-16 18:40 - 00001552 _____ () C:\Windows\Tasks\media enhance-codedownloader.job
2014-04-22 17:40 - 2014-03-16 18:40 - 00001452 _____ () C:\Windows\Tasks\media enhance-enabler.job
2014-04-22 17:39 - 2014-03-16 18:39 - 00003122 _____ () C:\Windows\Tasks\media enhance-chromeinstaller.job
2014-04-22 17:39 - 2014-03-16 18:39 - 00002380 _____ () C:\Windows\Tasks\media enhance-firefoxinstaller.job
2014-04-22 17:38 - 2014-03-16 18:38 - 00003102 _____ () C:\Windows\Tasks\HQTotalS-chromeinstaller.job
2014-04-22 17:38 - 2014-03-16 18:38 - 00002540 _____ () C:\Windows\Tasks\HQTotalS-firefoxinstaller.job
2014-04-22 17:38 - 2014-03-16 18:38 - 00001512 _____ () C:\Windows\Tasks\HQTotalS-updater.job
2014-04-22 17:38 - 2014-03-16 18:38 - 00001466 _____ () C:\Windows\Tasks\HQTotalS-codedownloader.job
2014-04-22 17:38 - 2014-03-16 18:38 - 00001366 _____ () C:\Windows\Tasks\HQTotalS-enabler.job
2014-04-22 17:14 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-22 17:14 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-22 17:11 - 2013-10-04 13:22 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\File Scout
2014-04-22 17:08 - 2014-04-22 16:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-22 17:07 - 2009-07-14 04:34 - 00000678 _____ () C:\Windows\win.ini
2014-04-22 17:06 - 2014-04-22 17:06 - 00000000 ____D () C:\Program Files\SavingsBull
2014-04-22 17:06 - 2014-03-15 20:38 - 00000948 _____ () C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job
2014-04-22 17:06 - 2014-02-25 09:58 - 00001792 _____ () C:\Windows\setupact.log
2014-04-22 17:06 - 2013-03-15 17:16 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-22 17:06 - 2013-01-10 19:09 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe
2014-04-22 17:06 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-22 17:05 - 2014-02-25 09:58 - 00881608 _____ () C:\Windows\PFRO.log
2014-04-22 16:56 - 2014-04-22 16:55 - 00000000 ____D () C:\AdwCleaner
2014-04-22 16:54 - 2014-04-22 16:54 - 01335637 _____ () C:\Users\xyz\Downloads\adwcleaner.exe
2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-22 16:45 - 2014-03-22 15:23 - 54485192 _____ () C:\Windows\system32\SavingsBullFilterService.log
2014-04-22 16:31 - 2012-08-22 09:25 - 00000000 ____D () C:\ProgramData\P4G
2014-04-22 16:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-04-22 16:03 - 2014-03-22 15:22 - 00000000 ____D () C:\Program Files (x86)\Optimizer Pro
2014-04-22 16:03 - 2014-03-16 18:38 - 00000000 ____D () C:\Program Files (x86)\SupTab
2014-04-22 16:01 - 2014-03-16 18:37 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-04-22 15:52 - 2014-03-15 20:43 - 00000000 ____D () C:\Program Files (x86)\Mysearchdial
2014-04-22 15:52 - 2014-02-21 23:14 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\mysearchdial
2014-04-22 15:50 - 2014-03-16 18:38 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\SupTab
2014-04-22 15:46 - 2013-10-04 13:23 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\SearchProtect
2014-04-22 15:32 - 2014-03-22 15:22 - 00000000 ____D () C:\Program Files (x86)\PC Speed Maximizer
2014-04-22 15:28 - 2014-03-22 15:20 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\viddyhd
2014-04-22 15:24 - 2011-02-19 06:24 - 00710852 _____ () C:\Windows\system32\perfh007.dat
2014-04-22 15:24 - 2011-02-19 06:24 - 00153300 _____ () C:\Windows\system32\perfc007.dat
2014-04-22 15:24 - 2009-07-14 07:13 - 01650460 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-22 15:21 - 2014-04-13 11:26 - 00003108 _____ () C:\Windows\System32\Tasks\RegClean Pro
2014-04-22 15:17 - 2014-03-15 20:39 - 00000000 ____D () C:\Program Files (x86)\Advanced System Protector
2014-04-22 15:13 - 2014-03-16 18:39 - 00000000 ____D () C:\Program Files (x86)\MyPC Backup
2014-04-22 15:02 - 2014-03-15 20:39 - 00000298 _____ () C:\Windows\Tasks\RegClean Pro_DEFAULT.job
2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-22 14:53 - 2014-04-22 14:51 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iTunes
2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod
2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7}
2014-04-22 14:33 - 2014-03-15 20:39 - 00003120 _____ () C:\Windows\System32\Tasks\Advanced System Protector_startup
2014-04-22 14:31 - 2014-04-22 14:31 - 00000000 ____D () C:\ProgramData\Systweak
2014-04-22 14:29 - 2013-10-04 13:23 - 00000000 ____D () C:\Program Files (x86)\Lizardlink
2014-04-22 14:28 - 2013-10-04 13:57 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Systweak
2014-04-22 14:28 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-22 14:27 - 2014-03-23 00:42 - 00000000 ____D () C:\ProgramData\Free Download Manager
2014-04-22 14:27 - 2014-03-15 20:39 - 00000000 ____D () C:\Program Files (x86)\AppSafe
2014-04-22 14:27 - 2013-01-15 00:13 - 00000000 ____D () C:\Program Files (x86)\HP
2014-04-22 14:27 - 2013-01-10 19:57 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com
2014-04-22 14:27 - 2013-01-10 19:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-22 14:27 - 2012-08-22 09:28 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2014-04-22 14:27 - 2011-04-13 04:47 - 00000000 ____D () C:\Program Files (x86)\ASUS
2014-04-22 14:25 - 2014-03-15 20:38 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\SaveSense
2014-04-22 14:24 - 2011-04-13 04:49 - 00000000 ____D () C:\AsusVibeData
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList
2014-04-22 13:37 - 2014-03-23 00:41 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Free Download Manager
2014-04-22 10:58 - 2013-01-10 21:38 - 00000000 ____D () C:\Users\xyz\Documents\Outlook-Dateien
2014-04-18 14:20 - 2014-03-15 20:39 - 00000306 _____ () C:\Windows\Tasks\RegClean Pro_UPDATES.job
2014-04-16 12:07 - 2012-08-22 09:25 - 00002206 _____ () C:\Windows\system32\AutoRunFilter.ini
2014-04-16 11:48 - 2013-01-10 21:18 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-16 11:46 - 2013-08-15 03:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-16 11:38 - 2013-01-13 08:13 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97}
2014-04-03 19:15 - 2013-03-15 17:16 - 00004126 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-03 19:15 - 2013-03-15 17:16 - 00003874 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-03 19:14 - 2014-02-25 11:15 - 00002155 _____ () C:\Windows\epplauncher.mif
2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-03 09:51 - 2014-04-22 16:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-22 16:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-22 16:51 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 03:16 - 2014-04-13 12:00 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-13 12:00 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-27 20:09 - 2014-03-15 20:38 - 00000110 _____ () C:\Users\xyz\AppData\Roaming\WB.CFG

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.5928.dll


Some content of TEMP:
====================
C:\Users\xyz\AppData\Local\Temp\42663uninstall.exe
C:\Users\xyz\AppData\Local\Temp\BackupSetup.exe
C:\Users\xyz\AppData\Local\Temp\dlLogic.exe
C:\Users\xyz\AppData\Local\Temp\IrsoDLL.dll
C:\Users\xyz\AppData\Local\Temp\nsk2D6A.exe
C:\Users\xyz\AppData\Local\Temp\nsn4DC8.exe
C:\Users\xyz\AppData\Local\Temp\nsnC321.exe
C:\Users\xyz\AppData\Local\Temp\nst42A1.exe
C:\Users\xyz\AppData\Local\Temp\nsyCD6F.exe
C:\Users\xyz\AppData\Local\Temp\pcspeedmaxsetup.exe
C:\Users\xyz\AppData\Local\Temp\PureSyncInst.exe
C:\Users\xyz\AppData\Local\Temp\Quarantine.exe
C:\Users\xyz\AppData\Local\Temp\shelper.exe
C:\Users\xyz\AppData\Local\Temp\SPSetup.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-28 01:12

==================== End Of Log ============================
         
--- --- ---


Code:
ATTFilter
#Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2014
Ran by xyz at 2014-04-22 18:53:11
Running from C:\Users\xyz\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden
AMD APP SDK Runtime (Version: 2.5.775.2 - Advanced Micro Devices Inc.) Hidden
AMD AVIVO64 Codecs (Version: 11.7.0.10927 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{92015CBE-D397-C3EA-99FC-B03051DE69A4}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.)
AppCloudUpdater (HKCU\...\AppCloudUpdater) (Version:  - AppCloudUpdater) <==== ATTENTION
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
ccc-utility64 (Version: 2011.0927.2225.38375 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS)
HP Unified IO (Version: 1.0.1.95 - HP) Hidden
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
Lizardlink 1.0.0 (HKLM\...\Lizardlink) (Version: 1.0.0 - Lizardlink) <==== ATTENTION
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video easy HD (Version: 5.0.0.99 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
SavingsBull (HKLM\...\Level Quality Watcher) (Version: SavingsBull - SavingsBull) <==== ATTENTION
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.17.0 - Synaptics Incorporated)

==================== Restore Points  =========================

22-04-2014 09:03:06 Revo Uninstaller's restore point - Adobe Flash Player Packages
22-04-2014 09:08:22 Revo Uninstaller's restore point - AsusVibe2.0
22-04-2014 09:10:31 Revo Uninstaller's restore point - NewPlayer
22-04-2014 09:13:05 Revo Uninstaller's restore point - Optimizer Pro v3.2
22-04-2014 09:14:28 Revo Uninstaller's restore point - HQTotalS
22-04-2014 09:15:53 Revo Uninstaller's restore point - IePluginService12.27.0.3326
22-04-2014 09:17:02 Revo Uninstaller's restore point - InstantOn for NB
22-04-2014 09:20:20 Revo Uninstaller's restore point - Lollipop
22-04-2014 09:21:59 Revo Uninstaller's restore point - media enhance
22-04-2014 11:16:55 Revo Uninstaller's restore point - Re-markit
22-04-2014 11:18:38 Revo Uninstaller's restore point - PC Speed Maximizer v3.2
22-04-2014 11:19:57 Revo Uninstaller's restore point - Plants vs Zombies
22-04-2014 11:34:22 Revo Uninstaller's restore point - WPM17.8.0.3442
22-04-2014 11:35:41 Revo Uninstaller's restore point - ViddyHD
22-04-2014 11:37:27 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections
22-04-2014 11:39:22 Revo Uninstaller's restore point - VO Package
22-04-2014 12:10:15 Wiederherstellungsvorgang
22-04-2014 13:03:55 Revo Uninstaller's restore point - Advanced System Protector
22-04-2014 13:07:03 Revo Uninstaller's restore point - Adobe Flash Player Packages
22-04-2014 13:10:00 Revo Uninstaller's restore point - awesomehp uninstaller
22-04-2014 13:11:25 Revo Uninstaller's restore point - File Extractor
22-04-2014 13:13:59 Revo Uninstaller's restore point - DMUninstaller
22-04-2014 13:23:47 Revo Uninstaller's restore point - RegClean Pro
22-04-2014 13:25:57 Revo Uninstaller's restore point - Lollipop
22-04-2014 13:27:32 Revo Uninstaller's restore point - ViddyHD
22-04-2014 13:30:02 Revo Uninstaller's restore point - PC Speed Maximizer v3.2
22-04-2014 13:44:45 Revo Uninstaller's restore point - Search Protect
22-04-2014 13:49:20 Revo Uninstaller's restore point - SupTab
22-04-2014 13:50:55 Revo Uninstaller's restore point - Mysearchdial
22-04-2014 13:52:32 Revo Uninstaller's restore point - WPM17.8.0.3442
22-04-2014 13:59:32 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections
22-04-2014 14:00:35 Revo Uninstaller's restore point - Re-markit
22-04-2014 14:01:51 Revo Uninstaller's restore point - Optimizer Pro v3.2
22-04-2014 14:11:03 Revo Uninstaller's restore point - IePluginService12.27.0.3326
22-04-2014 14:14:36 Revo Uninstaller's restore point - media enhance
22-04-2014 14:20:06 Revo Uninstaller's restore point - VO Package
22-04-2014 14:27:49 Wiederherstellungsvorgang
22-04-2014 14:37:37 Revo Uninstaller's restore point - HQTotalS

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {05490B50-D0A0-4A3C-A560-6ACF63DE1E42} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - System32\Tasks\APSnotifierPP2 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {0A20B86B-C883-4B55-BE5F-6C5B88DFD956} - System32\Tasks\SaveSenseLiveUpdateTaskMachineUA => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-03-15] (SaveSense) <==== ATTENTION
Task: {0B4E379A-4C4A-428E-9BCF-A1135BBA3E4A} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2012-09-27] ()
Task: {1CCE7D51-38D1-4F66-B7AC-A43176E2120F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-09-30] (ASUSTeK Computer Inc.)
Task: {38487E62-185E-4E9B-9FDF-B0AE74EDB917} - System32\Tasks\media enhance-firefoxinstaller => C:\Program Files (x86)\media enhance\media enhance-firefoxinstaller.exe <==== ATTENTION
Task: {39ABEFFB-C815-47E0-BC07-1E39AE6B1848} - System32\Tasks\media enhance-enabler => C:\Program Files (x86)\media enhance\media enhance-enabler.exe <==== ATTENTION
Task: {3E2E8B1F-6878-402A-87AB-F2EF5FEBADCE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.)
Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - System32\Tasks\APSnotifierPP1 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {4C14D4FC-EFFF-4FC1-BA61-EEFA91392794} - System32\Tasks\USBChargerPlus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2011-09-20] (ASUSTek Computer Inc.)
Task: {664914DE-1357-4563-9C3A-4B18A6DF05C4} - System32\Tasks\AppCloudUpdater => C:\Users\xyz\AppData\Roaming\AppCloudUpdater\UpdateProc\UpdateTask.exe [2013-04-12] ()
Task: {7667AB67-F907-484F-AD77-C667D54EA421} - System32\Tasks\HQTotalS-enabler => C:\Program Files (x86)\HQTotalS\HQTotalS-enabler.exe <==== ATTENTION
Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe <==== ATTENTION
Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - System32\Tasks\MySearchDial => C:\Users\STEFAN~1\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: {89189C02-42C8-456D-B675-7D30954096D1} - System32\Tasks\HQTotalS-firefoxinstaller => C:\Program Files (x86)\HQTotalS\HQTotalS-firefoxinstaller.exe
Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: {8FFE3A4C-B16E-4461-A1BC-27379739F580} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22] (ASUS)
Task: {90187687-8307-4836-8AD5-B51C0E3B2F1D} - System32\Tasks\RegClean Pro_DEFAULT => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: {9A20F821-8371-4DDF-8F33-7CF248B5D231} - System32\Tasks\HQTotalS-updater => C:\Program Files (x86)\HQTotalS\HQTotalS-updater.exe
Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - System32\Tasks\APSnotifierPP3 => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe <==== ATTENTION
Task: {AC60D348-CF49-41C1-B4C3-F3EF599304C7} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: {ADEB5A5F-7925-4438-9D2C-28715C5EC582} - System32\Tasks\HQTotalS-codedownloader => C:\Program Files (x86)\HQTotalS\HQTotalS-codedownloader.exe
Task: {AF490895-86A7-4FE9-9CC6-9EC88297132C} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-11-22] (ASUS)
Task: {B1DB8257-AAA0-4F41-A154-DF52977CE8A6} - System32\Tasks\media enhance-updater => C:\Program Files (x86)\media enhance\media enhance-updater.exe <==== ATTENTION
Task: {C410E796-D92D-4AEB-A596-89D282D0DBF8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.)
Task: {CA006D69-ECF6-4442-9628-D9F300F1C356} - System32\Tasks\media enhance-chromeinstaller => C:\Program Files (x86)\media enhance\media enhance-chromeinstaller.exe <==== ATTENTION
Task: {E22A7D07-EABF-4E3F-B019-C6F7AB546AA0} - System32\Tasks\SaveSenseLiveUpdateTaskMachineCore => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [2014-03-15] (SaveSense) <==== ATTENTION
Task: {E96319AF-4D2F-4DB8-B780-3738A6F8F2E2} - System32\Tasks\HQTotalS-chromeinstaller => C:\Program Files (x86)\HQTotalS\HQTotalS-chromeinstaller.exe
Task: {EAD7D671-DBE5-4388-994E-8F508652131C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS)
Task: {EB32D426-01C9-4433-875C-580B292A89F0} - System32\Tasks\SaveSense => C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION
Task: {EDBAD762-5B95-4C13-9FA0-333BACA63683} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-14] (Adobe Systems Incorporated)
Task: {F9C0DFA3-7859-4C70-A44F-5E77F9E82EA7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {FC1EFF76-3919-4569-B62C-EABD3C0F34D0} - System32\Tasks\media enhance-codedownloader => C:\Program Files (x86)\media enhance\media enhance-codedownloader.exe <==== ATTENTION
Task: {FE3FBFF8-BA1D-4554-A7AA-BA0DCD11606F} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AppCloudUpdater.job => C:\Users\STEFAN~1\AppData\Roaming\APPCLO~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\APSnotifierPP1.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe
Task: C:\Windows\Tasks\APSnotifierPP2.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe
Task: C:\Windows\Tasks\APSnotifierPP3.job => C:\Program Files (x86)\AnyProtectEx\AnyProtect.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HQTotalS-chromeinstaller.job => C:\Program Files (x86)\HQTotalS\HQTotalS-chromeinstaller.exe
Task: C:\Windows\Tasks\HQTotalS-codedownloader.job => C:\Program Files (x86)\HQTotalS\HQTotalS-codedownloader.exe
Task: C:\Windows\Tasks\HQTotalS-enabler.job => C:\Program Files (x86)\HQTotalS\HQTotalS-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\HQTotalS-firefoxinstaller.job => C:\Program Files (x86)\HQTotalS\HQTotalS-firefoxinstaller.exe
Task: C:\Windows\Tasks\HQTotalS-updater.job => C:\Program Files (x86)\HQTotalS\HQTotalS-updater.exe
Task: C:\Windows\Tasks\media enhance-chromeinstaller.job => C:\Program Files (x86)\media enhance\media enhance-chromeinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\media enhance-codedownloader.job => C:\Program Files (x86)\media enhance\media enhance-codedownloader.exe <==== ATTENTION
Task: C:\Windows\Tasks\media enhance-enabler.job => C:\Program Files (x86)\media enhance\media enhance-enabler.exe <==== ATTENTION
Task: C:\Windows\Tasks\media enhance-firefoxinstaller.job => C:\Program Files (x86)\media enhance\media enhance-firefoxinstaller.exe <==== ATTENTION
Task: C:\Windows\Tasks\media enhance-updater.job => C:\Program Files (x86)\media enhance\media enhance-updater.exe <==== ATTENTION
Task: C:\Windows\Tasks\MySearchDial.job => C:\Users\STEFAN~1\AppData\Roaming\MYSEAR~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_DEFAULT.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe <==== ATTENTION
Task: C:\Windows\Tasks\SaveSense.job => C:\Users\STEFAN~1\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION
Task: C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job => C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe <==== ATTENTION

==================== Loaded Modules (whitelisted) =============

2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2014-01-27 22:45 - 2014-01-27 22:45 - 00710976 _____ () C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe
2013-09-28 06:29 - 2014-04-22 15:09 - 00350496 _____ () C:\Program Files (x86)\Lizardlink\updateLizardlink.exe
2011-10-13 08:19 - 2011-07-21 12:59 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll
2013-10-07 09:14 - 2014-04-22 14:36 - 00350496 _____ () C:\Program Files (x86)\Lizardlink\bin\utilLizardlink.exe
2014-03-22 14:11 - 2014-03-22 14:11 - 00287008 _____ () C:\Program Files (x86)\Lizardlink\bin\FilterApp_C64.exe
2014-04-13 11:28 - 2014-04-17 22:22 - 00095520 _____ () C:\Program Files (x86)\Lizardlink\bin\Lizardlink.BrowserAdapter.exe
2013-07-01 15:58 - 2013-07-01 15:58 - 00598848 _____ () C:\Program Files (x86)\Zula Games\BackgroundHost.exe
2011-09-30 02:06 - 2011-09-30 02:06 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
2011-11-22 16:09 - 2011-11-22 16:09 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-09-13 22:33 - 2011-09-13 22:33 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll
2013-09-05 01:14 - 2013-09-05 01:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-07-01 15:58 - 2013-07-01 15:58 - 00334144 _____ () C:\Program Files (x86)\Zula Games\ButtonSite.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:AD022376

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (04/22/2014 03:38:16 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399
Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.16521, Zeitstempel: 0x53115050
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00008a95
ID des fehlerhaften Prozesses: 0xfc8
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3

Error: (04/22/2014 02:56:46 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399
Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.16521, Zeitstempel: 0x53115050
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00008a95
ID des fehlerhaften Prozesses: 0x12ec
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3

Error: (04/22/2014 02:56:15 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: IEXPLORE.EXE, Version: 11.0.9600.16521, Zeitstempel: 0x53114399
Name des fehlerhaften Moduls: jscript9.dll, Version: 11.0.9600.16521, Zeitstempel: 0x53115050
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00008a95
ID des fehlerhaften Prozesses: 0x15a0
Startzeit der fehlerhaften Anwendung: 0xIEXPLORE.EXE0
Pfad der fehlerhaften Anwendung: IEXPLORE.EXE1
Pfad des fehlerhaften Moduls: IEXPLORE.EXE2
Berichtskennung: IEXPLORE.EXE3

Error: (04/22/2014 02:20:59 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x8ec
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3

Error: (04/22/2014 02:20:47 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x1610
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3

Error: (04/22/2014 02:20:40 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x1488
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3

Error: (04/22/2014 02:20:28 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x1294
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3

Error: (04/22/2014 02:20:22 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: explorer.exe, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x1760
Startzeit der fehlerhaften Anwendung: 0xexplorer.exe0
Pfad der fehlerhaften Anwendung: explorer.exe1
Pfad des fehlerhaften Moduls: explorer.exe2
Berichtskennung: explorer.exe3

Error: (04/22/2014 02:20:16 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x1644
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3

Error: (04/22/2014 02:20:07 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d672ee4
Name des fehlerhaften Moduls: ASUSWSShellExt64.dll, Version: 1.1.0.27, Zeitstempel: 0x4c7f631d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x00000000000051da
ID des fehlerhaften Prozesses: 0x1564
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3


System errors:
=============
Error: (04/22/2014 05:06:41 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Optimizer Pro Crash Monitor erreicht.

Error: (04/22/2014 05:05:30 PM) (Source: ACPI) (User: )
Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft.

Error: (04/22/2014 04:33:13 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Optimizer Pro Crash Monitor erreicht.

Error: (04/22/2014 04:32:02 PM) (Source: ACPI) (User: )
Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft.

Error: (04/22/2014 04:29:17 PM) (Source: DCOM) (User: )
Description: {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}

Error: (04/22/2014 04:25:29 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Optimizer Pro Crash Monitor erreicht.

Error: (04/22/2014 04:05:05 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Optimizer Pro Crash Monitor erreicht.

Error: (04/22/2014 04:03:45 PM) (Source: ACPI) (User: )
Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft.

Error: (04/22/2014 03:47:21 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.

Error: (04/22/2014 03:47:21 PM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.


Microsoft Office Sessions:
=========================
Error: (04/22/2014 03:38:16 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.1652153114399jscript9.dll11.0.9600.1652153115050c000000500008a95fc801cf5e301007beccC:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll5b80c3c3-ca23-11e3-88dd-c860000435f6

Error: (04/22/2014 02:56:46 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.1652153114399jscript9.dll11.0.9600.1652153115050c000000500008a9512ec01cf5e2a40ee0e83C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll8f5e6a71-ca1d-11e3-a5ec-c860000435f6

Error: (04/22/2014 02:56:15 PM) (Source: Application Error)(User: )
Description: IEXPLORE.EXE11.0.9600.1652153114399jscript9.dll11.0.9600.1652153115050c000000500008a9515a001cf5e2a2e7dc5c3C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXEC:\Windows\SysWOW64\jscript9.dll7c914c07-ca1d-11e3-a5ec-c860000435f6

Error: (04/22/2014 02:20:59 PM) (Source: Application Error)(User: )
Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da8ec01cf5e254eaece06C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll8f6a7da0-ca18-11e3-8ac2-c860000435f6

Error: (04/22/2014 02:20:47 PM) (Source: Application Error)(User: )
Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da161001cf5e254a383982C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll887f7dd4-ca18-11e3-8ac2-c860000435f6

Error: (04/22/2014 02:20:40 PM) (Source: Application Error)(User: )
Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da148801cf5e2545d24ea0C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll83ff63d0-ca18-11e3-8ac2-c860000435f6

Error: (04/22/2014 02:20:28 PM) (Source: Application Error)(User: )
Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da129401cf5e253e5fa065C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll7cb2cb98-ca18-11e3-8ac2-c860000435f6

Error: (04/22/2014 02:20:22 PM) (Source: Application Error)(User: )
Description: explorer.exe6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da176001cf5e253ab5c239C:\Windows\explorer.exeC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll790db02d-ca18-11e3-8ac2-c860000435f6

Error: (04/22/2014 02:20:16 PM) (Source: Application Error)(User: )
Description: Explorer.EXE6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da164401cf5e2537619597C:\Windows\Explorer.EXEC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll75c0a7ac-ca18-11e3-8ac2-c860000435f6

Error: (04/22/2014 02:20:07 PM) (Source: Application Error)(User: )
Description: Explorer.EXE6.1.7601.175674d672ee4ASUSWSShellExt64.dll1.1.0.274c7f631dc000000500000000000051da156401cf5e25324b84e1C:\Windows\Explorer.EXEC:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll70aa96f6-ca18-11e3-8ac2-c860000435f6


==================== Memory info =========================== 

Percentage of memory in use: 35%
Total physical RAM: 6048.05 MB
Available physical RAM: 3905.56 MB
Total Pagefile: 12094.28 MB
Available Pagefile: 9360.5 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:195.35 GB) (Free:126.65 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Data) (Fixed) (Total:245.41 GB) (Free:210.98 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 496B9619)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=195 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=245 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
Code:
ATTFilter
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-22 20:07:15
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.01.0 465,76GB
Running: Gmer-19357.exe; Driver: C:\Users\STEFAN~1\AppData\Local\Temp\uxlyypob.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                               fffff800031f8000 45 bytes [00, 00, 0A, 02, 4D, 50, 72, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575                               fffff800031f802f 17 bytes [00, 30, E0, E7, 0B, 80, FA, ...]

---- Registry - GMER 2.1 ----

Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e                      
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet)  

---- EOF - GMER 2.1 ----
         
__________________
Gruß
Volker

Geändert von caiphi (22.04.2014 um 20:44 Uhr) Grund: Ergänzung Gmer.log, malwarebytes. log passte nicht mehr rein

Alt 22.04.2014, 20:25   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



hi,

So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.





Revo Uninstaller - Download - Filepony
Damit alles deinstallieren was Du in der Additional.txt findest mit dem Zusatz <== ATTENTION

Mit Revo auch Moderat die Reste entfernen lassen.




Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________

__________________

Alt 23.04.2014, 08:08   #3
caiphi
 
Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Beitrag

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Vielen Dank für die schnelle Antwort
Den Revo Uninstaller habe ich schon arbeiten lassen bis er nicht mehr konnte. Bei der Deinstallation des VO Package ist er kaputt gegangen. Er hat fast alle der 60 installierten Programme verloren. Er zeigt mir nur noch zwei installierte Programme an, der Rest des Rechners scheint unbeeinträchtigt. Eine Neuinstallation änderte daran nichts. Die normale Deinstallation von Windows funktioniert. Ich habe aber inzwischen alles Deinstalliert, was mit suspekt erschien.
Hier die Logs von mbam, adwcleaner, JRT und FRST

Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 22.04.2014
Suchlauf-Zeit: 23:44:20
Logdatei: mbam_2.txt
Administrator: Ja

Version: 2.00.1.1004
Malware Datenbank: v2014.04.22.07
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: xyz

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 255140
Verstrichene Zeit: 25 Min, 50 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 1
PUP.Optional.Savingsbull, C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe, 2324, Löschen bei Neustart, [d22e20e042bea65aed383cca8084847c]

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 187
PUP.Optional.Savingsbull, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Level Quality Watcher, In Quarantäne, [d22e20e042bea65aed383cca8084847c], 
PUP.Optional.SaveSense.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\savesenselive, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], 
PUP.Optional.SaveSense.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\savesenselivem, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SAVESENSELIVE.EXE, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SAVESENSELIVE.EXE, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\APPID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A2D3FB7A-6873-45E8-AF96-57092D721828}, In Quarantäne, [aa56e81817e92ad6a7c5e831669cc23e], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\APPID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}, In Quarantäne, [2fd129d725db1ce40896ca83c33fcd33], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}, In Quarantäne, [2fd129d725db1ce40896ca83c33fcd33], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{4A36AF02-3E2F-47DD-A102-784D22E8C2B8}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B71BC738-1C95-4784-B6AF-5B0964B895D9}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B71BC738-1C95-4784-B6AF-5B0964B895D9}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{4A36AF02-3E2F-47DD-A102-784D22E8C2B8}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], 
PUP.Optional.ValueApps.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], 
PUP.Optional.ValueApps.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{93DBF2BB-A2B3-4683-A92E-57E60751F346}, In Quarantäne, [6898629edd232dd37df532e705fdf30d], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A9337080-7CBF-4E3E-80C1-3867BEDD88E0}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{886634B3-7045-443A-A52B-E83AD1A90391}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\TYPELIB\{115D21BE-07D8-44B8-871E-EAFE1C1A6F10}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{115D21BE-07D8-44B8-871E-EAFE1C1A6F10}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\Zula Games.Tool.1, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\Zula Games.Tool, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.Tool, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.Tool.1, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\Zula Games.ScriptHostObject.1, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\CLASSES\Zula Games.ScriptHostObject, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.ScriptHostObject, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A9337080-7CBF-4E3E-80C1-3867BEDD88E0}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.ScriptHostObject.1, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A9337080-7CBF-4E3E-80C1-3867BEDD88E0}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ZuluGames, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A9337080-7CBF-4E3E-80C1-3867BEDD88E0}, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F63AAEDC-3602-49EF-AA45-262380A98980}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C9A54DFE-051F-49C5-9FC7-ECB81DC6C69F}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8050556E-4AD3-40BD-B338-7DBB0D5C10C8}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9011F634-B91C-400D-8CA2-E9E9A1FCC725}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E171D5FB-6763-4100-87CD-5F918979FBEA}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8050556E-4AD3-40BD-B338-7DBB0D5C10C8}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9011F634-B91C-400D-8CA2-E9E9A1FCC725}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E171D5FB-6763-4100-87CD-5F918979FBEA}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.ValueApps.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C9A54DFE-051F-49C5-9FC7-ECB81DC6C69F}, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.SaveSense.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{71E129FF-6C2A-4984-818C-7E2C998B8D99}, In Quarantäne, [2dd333cdbf41936d2863d44345bd19e7], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{71E129FF-6C2A-4984-818C-7E2C998B8D99}, In Quarantäne, [2dd333cdbf41936d2863d44345bd19e7], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{219046AE-358F-4CF1-B1FD-2B4DE83642A8}, In Quarantäne, [c63a22deaa562bd5480dbc91e2200af6], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{11577C71-9E04-4A42-ACC5-9C7F240BF4FE}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2D017725-74A0-4513-913D-2939ADF6D0F3}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{458BD324-E5D0-412C-954D-EDFD69A59ED9}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9ADA5C62-B227-45A9-9D77-E5609A43E943}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B5445928-B77D-474B-84F6-6F1323CA5701}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{BE6C7021-0352-4A7E-8A5B-46126353049E}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D94BA844-0355-4F02-97F2-6856CD94FE66}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{2D017725-74A0-4513-913D-2939ADF6D0F3}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{458BD324-E5D0-412C-954D-EDFD69A59ED9}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{806ED5AF-3ED0-454C-BE4E-6644DD7BEDD1}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9275FE6D-8F84-4CA5-97E7-DD3AFD5E4BDE}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9ADA5C62-B227-45A9-9D77-E5609A43E943}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A37DD83A-DABA-4EF0-98AA-CDDA88839172}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A70CA55D-8EE5-4997-8BC3-B341E36ACBBA}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B5445928-B77D-474B-84F6-6F1323CA5701}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BE6C7021-0352-4A7E-8A5B-46126353049E}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D2AA22AE-2103-4D78-9C0D-46DE64EE0ED7}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D94BA844-0355-4F02-97F2-6856CD94FE66}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DFBED68E-BBF6-454A-940F-C84C7E7B4CE6}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{F4F96034-2761-4BAF-B906-E4B59E5D50EA}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FE42F7F2-D931-40CD-ACE7-7B47383ACE25}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{11577C71-9E04-4A42-ACC5-9C7F240BF4FE}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{2A16BB3D-56EA-472B-A8E8-7BB49ABDB37D}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{2A16BB3D-56EA-472B-A8E8-7BB49ABDB37D}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D2C54F93-A898-437F-AE89-7BDD918954A5}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{1B0DA3F5-D96D-483D-8BEF-224BA1B67620}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{1B0DA3F5-D96D-483D-8BEF-224BA1B67620}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\Zula Games.Navbar.1, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\Zula Games.Navbar, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.Navbar, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.Navbar.1, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\CLSID\{D2C54F93-A898-437F-AE89-7BDD918954A5}, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.OneClickCtrl.9, In Quarantäne, [7a867d83718fe11f09799c0a72918878], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine, In Quarantäne, [e21e966a867a8977b8cad1d519ea6b95], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine.1.0, In Quarantäne, [3dc3fc0421dfa15f9be7d9cd0ef5a858], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLive.Update3WebControl.3, In Quarantäne, [867ae31d847cb24e88fa1c8a010251af], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync, In Quarantäne, [a45c837da9579769dea47e28d82b41bf], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync.1.0, In Quarantäne, [2bd5ea16a45c39c78ef4fea8be45ef11], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreClass, In Quarantäne, [6d93c9378f71659b275b6d39b54ebe42], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreClass.1, In Quarantäne, [e8186f91c7395da388fa268037ccba46], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass, In Quarantäne, [629ecc34e020c04085fd5551d72ce719], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass.1, In Quarantäne, [768ab84845bbee12077ba204867de020], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine, In Quarantäne, [3ac61ee2d729ab552e54c2e4b251fa06], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine.1.0, In Quarantäne, [56aacb3514ec38c86e14970f31d20ef2], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine, In Quarantäne, [e21e0df3689837c9daa8a006d72cb14f], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [619fea1629d741bf4f33584e8b78768a], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [a55bce3259a77888f48e1690df2410f0], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [a25eab55e21ed62ae69cb2f46e9551af], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher, In Quarantäne, [e719ae52a25e5fa13f43d4d261a2e51b], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher.1.0, In Quarantäne, [da26b050b050a95700829e0842c1cb35], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService, In Quarantäne, [1ae623dda15f946cc6bc505662a14cb4], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [1be5c13fec1422de275bedb92ed505fb], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine, In Quarantäne, [09f7f709936dab559ae80d9961a27987], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine.1.0, In Quarantäne, [a957ed13e41cc040ed9505a19073f907], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback, In Quarantäne, [857b97691de3a55b3949d8ceb251c13f], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [f20ef010b84834ccc6bc9b0b0bf89c64], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc, In Quarantäne, [cd332fd15da39b65add5c0e642c16e92], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [c43c08f85da39c645131d0d649bab848], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\Zula Games.BackgroundHostObject, In Quarantäne, [0000748cd22e05fbc04bb1ee689bbe42], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\CLASSES\Zula Games.BackgroundHostObject.1, In Quarantäne, [d0300ff11fe1ce320dfea5fa6b9854ac], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\CLASSES\APPID\SaveSenseLive.exe, In Quarantäne, [b44c9b65ce323dc38ff28e1806fd41bf], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [5aa6639d8e72748c79f7f67ef70b1ee2], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [f60a37c997694bb520502e4645bd728e], 
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [46ba8977a15f13ed69eee8bbec1714ec], 
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\awesomehpSoftware, In Quarantäne, [52aea759ae5268987db767172dd57f81], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\SaveSenseLive, In Quarantäne, [5ea2946c44bca65a8dfafaac37cca858], 
PUP.Optional.SavingsBull.A, HKLM\SOFTWARE\WOW6432NODE\SavingsbullFilter, In Quarantäne, [02fec937ba46e61ac2674a3326dc936d], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLive.OneClickCtrl.9, In Quarantäne, [dd2367995ba56997d4ae4d59748f58a8], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine, In Quarantäne, [c43cba46ba46857b483a980e58ab58a8], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLive.OneClickProcessLauncherMachine.1.0, In Quarantäne, [aa5639c7b947a060dda5f1b5f80bf60a], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLive.Update3WebControl.3, In Quarantäne, [6d93f709f80804fcf78bdaccbe4533cd], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync, In Quarantäne, [5ea221df847ce21e275b83238e75c23e], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoCreateAsync.1.0, In Quarantäne, [ed133ec2738dc13f4d35f0b6689bb44c], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreClass, In Quarantäne, [3cc4e31d57a9f40cc1c19c0aa75c837d], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreClass.1, In Quarantäne, [4fb1c739a060b64ae59d9115a261c43c], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass, In Quarantäne, [f709639d6d9316eaf78b2e78a06352ae], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CoreMachineClass.1, In Quarantäne, [b749827e639db0501969555159aa6b95], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine, In Quarantäne, [9967d62aee1257a990f2d9cdf2112ad6], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.CredentialDialogMachine.1.0, In Quarantäne, [936da957a060718f255dedb9bb48dc24], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine, In Quarantäne, [6a966f9113edc838582abee820e3a858], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [ca3613ed27d955ababd74165bd46a759], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [2ad67b855da3d72988fa2c7ae91ac838], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [fe021de3ab556f915f2396107b88cd33], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher, In Quarantäne, [20e0916f54ac41bff0926343f310ec14], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.ProcessLauncher.1.0, In Quarantäne, [c63a4eb2be42ac549ae84066956e728e], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService, In Quarantäne, [679935cb33cd7a86fe846a3c20e311ef], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3COMClassService.1.0, In Quarantäne, [32cef808629e8b75eb97149213f0cc34], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine, In Quarantäne, [1ee2956b23dd847ce999bfe749ba966a], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebMachine.1.0, In Quarantäne, [7789ec14d12f6d931e640b9b20e3c937], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback, In Quarantäne, [53ad54ac5ba5649c265c6145fd06827e], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [7789f40c1ee27d83c7bb673f3bc8847c], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc, In Quarantäne, [52ae0ff1649c1ae6364c0d99946f738d], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\SaveSenseLiveUpdate.Update3WebSvc.1.0, In Quarantäne, [1be50000d82898681270aff7ff0425db], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.BackgroundHostObject, In Quarantäne, [e51b0df304fc3bc532d99c039172659b], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Zula Games.BackgroundHostObject.1, In Quarantäne, [45bbea16e31d38c8a9624a55679cd12f], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\SaveSenseLive.exe, In Quarantäne, [768a6c9435cbed13661bb1f57390c13f], 
PUP.Optional.Zulagames.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\gflandjopdloblmlcoiidmncpinmmacn, In Quarantäne, [996715eb7c840cf4f715a4fbd1322fd1], 
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pelmeidfhdlhlbjimpabfcbnnojbboma, In Quarantäne, [b947956b2fd11be5fa13a1d4867c48b8], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [28d8fb059d63ca3675fb78fcd032dc24], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [57a930d0eb15659b2b457400ec16bc44], 
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [1de350b026da9a66f95ef9aa946fc53b], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.updaterss.com/SaveSenseLive Update;version=3, In Quarantäne, [25db2ad65fa1847c275e95117d860ff1], 
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.updaterss.com/SaveSenseLive Update;version=9, In Quarantäne, [31cf926e738d6e92166f2b7bbc47d729], 
PUP.Optional.HQTotalS.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQTotalS, In Quarantäne, [47b9946c67997b85ab5e8aebdc2613ed], 
PUP.Optional.MediaEnhance.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\media enhance, In Quarantäne, [5ca4ac54f60a5ba5c36a1d5b11f131cf], 
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\mysearchdial, In Quarantäne, [728e7888f010bf41d1be4751798aa858], 
PUP.Optional.SaveSense.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SaveSenseLive, In Quarantäne, [b0505ba57789e51bd5af089e2dd6a957], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [44bce11fff0153ad0817cce0a45f02fe], 
PUP.Optional.HQTotalS.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQTotalS, In Quarantäne, [49b748b8e020718f3ccd7afb19e9c040], 
PUP.Optional.MediaEnhance.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\media enhance, In Quarantäne, [0ef22fd160a0956b121bafc912f009f7], 
PUP.Optional.SavingsBull.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Savings Bull, In Quarantäne, [f9079f6113edda265fc7bfbe8082e41c], 
PUP.Optional.ValueApps.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\ValueApps, In Quarantäne, [1be514ec639dcb353997ea97ee144db3], 
PUP.Optional.AlexaTB.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DISTROMATIC\Toolbars, In Quarantäne, [c937b44c1de39f61d9489c021ae9a65a], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [639d58a8718fda262d2cb5cc9171d62a], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [3bc531cf3ec252ae276480177192c53b], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, In Quarantäne, [7d83a15f817f58a840310272b74bd030], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\27058, In Quarantäne, [b54bd32d3fc1b0508be6bcb8738f0000], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\freeven, In Quarantäne, [0000fd039e62d828dcfc393e12f0748c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\HQplustotalS, In Quarantäne, [df2117e918e825db09d6195b43bfc23e], 
PUP.Optional.Qone8, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [eb15b14f6c94ea16e076adf6d62d56aa], 
PUP.Optional.AdvancedSystemProtector.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\Advanced System Protector, In Quarantäne, [ac548e72867ab14fa79d3e5f649f8a76], 
PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A18D16ED-27B2-4B83-B70C-15E73F099546}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A18D16ED-27B2-4B83-B70C-15E73F099546}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{A18D16ED-27B2-4B83-B70C-15E73F099546}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{998745A3-2AE4-488D-8092-B98FB20A00C2}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C1424421-D274-491E-9D47-11C8D8CB5F9A}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SavingsBull.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Level Quality Watcher, In Quarantäne, [ae52a957f40cd42c8e151b490ef4c838], 

Registrierungswerte: 3
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{3004627E-F8E9-4E8B-909D-316753CBA923}, In Quarantäne, [22def50bcc3414ec0b4966e738cab749], 
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{3004627E-F8E9-4E8B-909D-316753CBA923}, mysearchdial Toolbar, In Quarantäne, [22def50bcc3414ec0b4966e738cab749]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0X2O1C0R2R1R, In Quarantäne, [3bc531cf3ec252ae276480177192c53b]

Registrierungsdaten: 17
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[54accd3387797987a8776ab8ad57fe02]
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}),Ersetzt,[e7195ca46c94e21e69b8ce54956f857b]
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[52aec93700003dc34cd0f82a4cb817e9]
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[02fe43bd52ae15eb25fee63cae56bd43]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[aa56c23e3fc1659b3ca284a7b1533ec2]
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[07f930d0f40c33cdec335fc329db41bf]
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\ABOUTURLS|Tabs, hxxp://start.mysearchdial.com/?f=2&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0C0EyBtA0E0DtA0EzzzztN0D0Tzu0CyBzztAtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=923418304&ir=, Gut: (www.google.com), Schlecht: (hxxp://start.mysearchdial.com/?f=2&a=irmsd0202ch&cd=2XzuyEtN2Y1L1Qzu0EtD0Bzy0AyD0C0EyBtA0E0DtA0EzzzztN0D0Tzu0CyBzztAtN1L2XzutBtFtBtFtCyDtFtCyCtAtCtN1L1CzutBtAtDtC1N1R&cr=923418304&ir=),Ersetzt,[788822de4cb457a941b773aea064916f]
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}),Ersetzt,[26da60a0907016ea68b956cc26de748c]
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[7090ee121fe1aa5668b471b1c63ec838]
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[58a8cd33d030cf311b086cb61aeafd03]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[16ea58a85aa65aa69a44cf5cc1435ca4]
PUP.Optional.Snapdo, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[857b2dd32cd4b05060ee65c6d1339f61]
PUP.Optional.Awesomehp.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.awesomehp.com/?type=hp&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359),Ersetzt,[7c847e82fb0510f0e13c78aa46be8e72]
PUP.Optional.Snapdo, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[946ce21e1ae6cc34a9a43bf0d72dc23e]
PUP.Optional.Snapdo, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[c23ea65adf21d52b54fc41ea16eebf41]
PUP.Optional.Snapdo, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[8b75956bcd335ea2ff52c66525df867a]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-889188840-3397074576-2393254512-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_[[PubID]]_CH&co=DE&userid=39eec5b9-baae-4939-3604-11f52ce5653b&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[6e920cf4e21ec937ae394fd21ce8e818]

Ordner: 60
Adware.InstallBrain, C:\ProgramData\IBUpdaterService, In Quarantäne, [5ea27b85ba469f61cf8198d9f50e12ee], 
PUP.Optional.Zulagames.A, C:\Users\xyz\AppData\Roaming\zulagames, In Quarantäne, [7789e21e8a764db3dd2ca9f621e2db25], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\mz, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced System Protector, In Quarantäne, [946c3ac6d52b15ebada97be5d52d6a96], 
PUP.Optional.AdvancedSystemProtector.A, C:\Users\xyz\AppData\Roaming\Systweak\Advanced System Protector, In Quarantäne, [22de2ed20ff1e41c1f378dd309f90ef2], 
PUP.Optional.MySearchDial.A, C:\Users\xyz\AppData\Roaming\mysearchdial, In Quarantäne, [13ed36cae719639d72fbabb545bdf808], 
PUP.Optional.FileScout.A, C:\Users\xyz\AppData\Roaming\File Scout, In Quarantäne, [52aed729bb454bb5138099c7a062c63a], 
PUP.Optional.RegCleanerPro.A, C:\Users\xyz\AppData\Roaming\Systweak\RegClean Pro, In Quarantäne, [ad53c0406b95e21e9b5e5808bc462bd5], 
PUP.Optional.Conduit.A, C:\ProgramData\Conduit\IE, In Quarantäne, [7090cb35639d2fd115f2bfa2ce34dd23], 
PUP.Optional.MySearchDial.A, C:\Program Files (x86)\Mysearchdial, In Quarantäne, [e0208779659bcb3500d898c9b250b050], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\CrashReports, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Download, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Install, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Offline, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\Offline\{912F06AE-3B00-48A0-98A9-F26EC1DDCB2E}, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive, In Quarantäne, [817fcd33fb057d838c610160b44e03fd], 
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update, In Quarantäne, [817fcd33fb057d838c610160b44e03fd], 
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update\Log, In Quarantäne, [817fcd33fb057d838c610160b44e03fd], 
PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], 
PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], 
PUP.Optional.SaveSense.A, C:\Users\xyz\AppData\Local\SaveSenseLive, In Quarantäne, [689824dcdb255ba519d94d14ea186997], 
PUP.Optional.SaveSense.A, C:\Users\xyz\AppData\Local\SaveSenseLive\CrashReports, In Quarantäne, [689824dcdb255ba519d94d14ea186997], 
PUP.Optional.Conduit, C:\Users\xyz\AppData\Local\TBHostSupport, In Quarantäne, [4db3ee12639dda264aaed78a1be714ec], 
PUP.Optional.Adpeak, C:\Program Files\Level Quality Watcher\v1.01, Löschen bei Neustart, [a75920e0e818fa06b2adfa68936f936d], 
PUP.Optional.ValueAppsplugin.A, C:\Program Files (x86)\Conduit\ValueApps, In Quarantäne, [ed1357a9b24e7e8279feb3af26dc17e9], 
PUP.Optional.ValueAppsplugin.A, C:\Program Files (x86)\Conduit\ValueApps\IE, In Quarantäne, [ed1357a9b24e7e8279feb3af26dc17e9], 
PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], 
PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], 
PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\64, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\userCode, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\actions, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\popupResource, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.SavingsBull.A, C:\Program Files\SavingsBull, In Quarantäne, [ae52a957f40cd42c8e151b490ef4c838], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\userCode, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\actions, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\popupResource, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0, In Quarantäne, [2bd5c937e21e4eb2da161d4a14ee20e0], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_deghekbbihbapplmbffglehkdhkeibbm_0, In Quarantäne, [06fa13ed49b7ec14a488600842c06f91], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], 

Dateien: 310
PUP.Optional.Savingsbull, C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher64.exe, Löschen bei Neustart, [d22e20e042bea65aed383cca8084847c], 
PUP.Optional.SaveSense.A, C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe, In Quarantäne, [48b8aa56c53bd030adeb2820ad54a55b], 
PUP.Optional.ValueApps.A, C:\Program Files (x86)\Conduit\ValueApps\IE\ValueAppsLoader.dll, In Quarantäne, [6898629edd232dd37df532e705fdf30d], 
PUP.Optional.ZuluGames, C:\Program Files (x86)\Zula Games\ScriptHost.dll, In Quarantäne, [2ad638c870909e623b9581cb29d9ae52], 
PUP.Optional.ValueApps.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\MonPrx.dll, In Quarantäne, [956b6e92748cb44c80a65bbf3fc3a25e], 
PUP.Optional.ViddyHD.A, C:\Users\xyz\AppData\Roaming\532d8d0bcd6da1a357004531\532d8d0bcd6da1a357004531.exe, In Quarantäne, [ab5503fd669a06fa7840162d9d6433cd], 
PUP.Optional.SearchProtect.A, C:\Users\xyz\AppData\Local\Temp\nsk2D6A.exe, In Quarantäne, [867a21df16ea5ca4c7e30f15748db44c], 
PUP.Optional.Conduit.A, C:\Users\xyz\AppData\Local\Conduit\CT3312331\appbarioDEAutoUpdateHelper.exe, In Quarantäne, [59a7a06026da47b9c265a47a659bed13], 
PUP.Optional.SmartBar, C:\Windows\Installer\MSI1C54.tmp, In Quarantäne, [36cac43c37c99868c94afa349070f907], 
PUP.Optional.SmartBar.A, C:\Windows\Installer\242a0866.msi, In Quarantäne, [c63a5ca4c83832ce82519394c73949b7], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_deghekbbihbapplmbffglehkdhkeibbm_0.localstorage, In Quarantäne, [c838ab55827ecc346d939dd6a85a6c94], 
PUP.Optional.QuickStart.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv3.crx, In Quarantäne, [7888d52bb24e857be443462d19e9669a], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0.localstorage, In Quarantäne, [7c84a65a32ce5ea2aca3f0833fc35fa1], 
PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-chromeinstaller.job, In Quarantäne, [32cec43cd927e11f0404db9ad0323bc5], 
PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-codedownloader.job, In Quarantäne, [40c006faec1424dc6a9e8de85ea48b75], 
PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-enabler.job, In Quarantäne, [36ca1ee2aa5658a80800453032d0817f], 
PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-firefoxinstaller.job, In Quarantäne, [f60aac54639d5ea238d08aeb0ef4867a], 
PUP.Optional.HQTotalS.A, C:\Windows\Tasks\HQTotalS-updater.job, In Quarantäne, [ea16e11f986856aac543bdb83fc323dd], 
PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-chromeinstaller.job, In Quarantäne, [b24e30d0649ca15f4fdd572140c2ea16], 
PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-codedownloader.job, In Quarantäne, [a759748cdc243bc5cf5d1b5dbe44d927], 
PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-enabler.job, In Quarantäne, [dc2410f024dce61abc70a7d125ddfe02], 
PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-firefoxinstaller.job, In Quarantäne, [79870ff1dc243bc5e9433e3ac43e4cb4], 
PUP.Optional.MediaEnhance.A, C:\Windows\Tasks\media enhance-updater.job, In Quarantäne, [7c84d030aa561ee230fc4d2b31d1de22], 
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [4bb5a35da25ee11fb95a0378cd35ae52], 
PUP.Optional.RegCleanerPro.J, C:\Windows\Tasks\RegClean Pro_UPDATES.job, In Quarantäne, [db2513ed9f612bd5ffba186b04fe24dc], 
Adware.InstallBrain, C:\ProgramData\IBUpdaterService\repository.xml, In Quarantäne, [5ea27b85ba469f61cf8198d9f50e12ee], 
PUP.Optional.RegCleanPro.A, C:\Windows\Tasks\RegClean Pro_DEFAULT.job, In Quarantäne, [887830d0956b31cfd250c1d5ce35f20e], 
PUP.Optional.SpeedAnalysis2.A, C:\Users\xyz\AppData\Roaming\speedanalysis.ico, In Quarantäne, [a060c13fe719c13f85fed9bf758ea55b], 
PUP.Optional.Zulagames.A, C:\Users\xyz\AppData\Roaming\zulagames\zulagames.crx, In Quarantäne, [7789e21e8a764db3dd2ca9f621e2db25], 
PUP.Optional.Zulagames.A, C:\Users\xyz\AppData\Roaming\zulagames\icon.ico, In Quarantäne, [7789e21e8a764db3dd2ca9f621e2db25], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\background.html, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon128.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\AddonsFramework.Typelib.dll, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\BackgroundHost.exe, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\BackgroundHost64.exe, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\BackgroundHostPS.dll, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\bg.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\ButtonSite.dll, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\ButtonSite64.dll, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\config.xml, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\content.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon16.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon18.ico, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon18.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon24.ico, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon24.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon32.ico, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon32.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\icon48.png, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\jquery-1.9.1.min.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\json2.min.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\uninstall.exe, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\updater.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\updaterWrapper.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\zulagames.rdf, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\mz\background.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.Zulagames.A, C:\Program Files (x86)\Zula Games\mz\content.js, In Quarantäne, [1fe1738da9577c84b05a702f689b8779], 
PUP.Optional.FunMoods.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage, In Quarantäne, [0bf579879c64cd337946edb3c241946c], 
PUP.Optional.SaveSense, C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job, In Quarantäne, [1fe1c43cdf21778985bba7ff867d0ff1], 
PUP.Optional.SaveSense, C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job, In Quarantäne, [916fe41cb54b89773d03c0e608fbc838], 
PUP.Optional.AdvancedSystemProtector.A, C:\Users\xyz\AppData\Roaming\Systweak\Advanced System Protector\Settings.db, In Quarantäne, [22de2ed20ff1e41c1f378dd309f90ef2], 
PUP.Optional.FileScout.A, C:\Users\xyz\AppData\Roaming\File Scout\uninst.exe, In Quarantäne, [52aed729bb454bb5138099c7a062c63a], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_de.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_el.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_en-GB.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_en.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_es-419.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_es.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_et.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fa.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fi.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fil.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_fr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_gu.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_hi.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_hr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_hu.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_id.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_it.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_iw.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ja.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_kn.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ko.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_lt.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_lv.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ml.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_mr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ms.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_nl.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_no.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_pl.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_pt-BR.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_pt-PT.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ro.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdate.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_am.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ar.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_bg.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_bn.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ca.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_cs.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sk.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sl.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sv.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_sw.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ta.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_te.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_th.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_tr.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_uk.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ur.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_vi.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_zh-CN.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_zh-TW.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\npGoogleUpdate3.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psmachine.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\psuser.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveBroker.exe, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHandler.exe, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveHelper.msi, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLiveOnDemand.exe, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_da.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_is.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\goopdateres_ru.dll, In Quarantäne, [b34d4eb29c64639dca22cc95b052619f], 
PUP.Optional.SaveSense, C:\ProgramData\SaveSenseLive\Update\Log\SaveSenseLive.log, In Quarantäne, [817fcd33fb057d838c610160b44e03fd], 
PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\config.dat, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], 
PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\info.dat, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], 
PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\STTL.DAT, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], 
PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\TTL.DAT, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], 
PUP.Optional.SaveSense, C:\Users\xyz\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe, In Quarantäne, [7a863dc319e760a0e806a5bca75bbe42], 
PUP.Optional.Conduit, C:\Users\xyz\AppData\Local\TBHostSupport\TBHostSupport.dll, In Quarantäne, [4db3ee12639dda264aaed78a1be714ec], 
PUP.Optional.Conduit, C:\Users\xyz\AppData\Local\TBHostSupport\TBHostSupport_0.dll, In Quarantäne, [4db3ee12639dda264aaed78a1be714ec], 
PUP.Optional.Adpeak, C:\Program Files\Level Quality Watcher\v1.01\levelqualitywatcher32.exe, In Quarantäne, [a75920e0e818fa06b2adfa68936f936d], 
PUP.Optional.ValueAppsplugin.A, C:\Program Files (x86)\Conduit\ValueApps\IE\uninstaller.exe, In Quarantäne, [ed1357a9b24e7e8279feb3af26dc17e9], 
PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\settings.json, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], 
PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\ValueApps.exe, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], 
PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\64\settings.json, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], 
PUP.Optional.ValueAppsplugin.A, C:\Users\xyz\AppData\Local\Conduit\ValueApps\IE\64\tmpresp.tmp, In Quarantäne, [52aeb64aa15f946c6e0bf17135cda759], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\background.html, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\chromeCoreFilesIndex.txt, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\crossriderManifest.json, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\manifest.json, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\popup.html, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\manifest.xml, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins.json, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\102_dealply_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\103_intext_5_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\104_jollywallet_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\13_CrossriderAppUtils.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\14_CrossriderUtils.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\155_ibario_pops_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\177_crossriderDashboard.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\17_jQuery.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\182_openUrl.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\183_tabsWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\184_noproblemppc_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\190_pops_5_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\191_ciuvo_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\195_icm_convertmedia_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\19_CHAppAPIWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\1_base.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\207_dbWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\21_debug.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\220_icm_base_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\226_set_campaign_id_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\22_resources.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\230_revizer_ws_dynamic_b2b_2_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\233_revizer_p_dynamic_b2b_2_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\246_setup.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\28_initializer.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\47_resources_background.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\4_jquery_1_7_1.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\64_appApiMessage.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\72_appApiValidation.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\78_CrossriderInfo.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\7_hooks.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\80_CHPopupAppAPI.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\91_monetizationLoader.js.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\93_superfish_no_coupons_m.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\97_resourceApiWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\plugins\9_search_engine_hook.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\userCode\background.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\extensionData\userCode\extension.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\icon128.png, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\icon16.png, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\icon48.png, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\icons\actions\1.png, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\background.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\main.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\platformVersion.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\chrome.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\cookie.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\message.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\monitor.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\pageAction.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\api\pageActionBG.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\app_api.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\bg_app_api.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\consts.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\cookie_store.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\crossriderAPI.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\delegate.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\events.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\extensionDataStore.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\installer.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\logFile.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\logging.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\onBGDocumentLoad.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\reports.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\storageWrapper.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\updateManager.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\util.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\xhr.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\popupResource\newPopup.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lekgiimbfodefdaoofhlckefjbgpeilo\1.26.77_0\js\lib\popupResource\popup.js, In Quarantäne, [9f61b14f2bd5cf31e3e4f172ee1447b9], 
PUP.Optional.SavingsBull.A, C:\Program Files\SavingsBull\uninstaller.exe, In Quarantäne, [ae52a957f40cd42c8e151b490ef4c838], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\background.html, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\chromeCoreFilesIndex.txt, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\crossriderManifest.json, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\manifest.json, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\popup.html, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\manifest.xml, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins.json, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\1.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\102.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\103.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\104.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\119.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\13.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\14.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\17.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\177.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\179.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\180.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\182.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\183.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\19.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\191.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\207.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\21.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\22.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\223.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\231.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\232.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\242.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\246.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\28.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\4.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\47.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\64.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\72.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\78.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\80.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\91.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\93.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\plugins\97.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\userCode\background.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\extensionData\userCode\extension.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\icon128.png, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\icon16.png, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\icon48.png, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\icons\actions\1.png, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\background.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\main.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\platformVersion.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\chrome.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\cookie.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\message.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\monitor.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\pageAction.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\api\pageActionBG.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\app_api.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\bg_app_api.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\consts.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\cookie_store.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\crossriderAPI.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\delegate.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\events.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\extensionDataStore.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\installer.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\logFile.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\logging.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\onBGDocumentLoad.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\reports.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\storageWrapper.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\updateManager.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\util.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\xhr.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\popupResource\newPopup.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\deghekbbihbapplmbffglehkdhkeibbm\1.26.34_0\js\lib\popupResource\popup.js, In Quarantäne, [8080837daf51dc2400ea89dd3ec458a8], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_lekgiimbfodefdaoofhlckefjbgpeilo_0\15, In Quarantäne, [2bd5c937e21e4eb2da161d4a14ee20e0], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000041.ldb, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000043.ldb, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\000098.log, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\CURRENT, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\LOCK, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\LOG, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\LOG.old, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lekgiimbfodefdaoofhlckefjbgpeilo\MANIFEST-000096, In Quarantäne, [a8588f71669a966ad3299bcc6e9447b9], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_deghekbbihbapplmbffglehkdhkeibbm_0\14, In Quarantäne, [06fa13ed49b7ec14a488600842c06f91], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\000041.ldb, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\000043.ldb, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\000098.log, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\CURRENT, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\LOCK, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\LOG, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\LOG.old, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], 
PUP.Optional.CrossRider.A, C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\deghekbbihbapplmbffglehkdhkeibbm\MANIFEST-000096, In Quarantäne, [1fe101fffb05a06095a4353332d030d0], 

Physische Sektoren: 0
(No malicious items detected)


(end)
         
Code:
ATTFilter
# AdwCleaner v3.201 - Bericht erstellt am 22/04/2014 um 23:58:48
# Aktualisiert 22/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : xyz - STEFANIE
# Gestartet von : C:\Users\xyz\Downloads\adwcleaner (1).exe
# Option : Suchen

***** [ Dienste ] *****

Dienst Gefunden : 70e6ca8c

***** [ Dateien / Ordner ] *****

Datei Gefunden : \END
Datei Gefunden : C:\END
Datei Gefunden : C:\Users\xyz\AppData\Roaming\aps.uninstall.scan.results
Datei Gefunden : C:\Users\xyz\Desktop\AppSafe.lnk
Datei Gefunden : C:\Windows\System32\Tasks\Advanced System Protector_startup
Datei Gefunden : C:\Windows\System32\Tasks\APSnotifierPP1
Datei Gefunden : C:\Windows\System32\Tasks\APSnotifierPP2
Datei Gefunden : C:\Windows\System32\Tasks\APSnotifierPP3
Datei Gefunden : C:\Windows\System32\Tasks\MySearchDial
Datei Gefunden : C:\Windows\System32\Tasks\RegClean Pro
Datei Gefunden : C:\Windows\System32\Tasks\SaveSense
Datei Gefunden : C:\Windows\Tasks\APSnotifierPP1.job
Datei Gefunden : C:\Windows\Tasks\APSnotifierPP2.job
Datei Gefunden : C:\Windows\Tasks\APSnotifierPP3.job
Datei Gefunden : C:\Windows\Tasks\MySearchDial.job
Datei Gefunden : C:\Windows\Tasks\SaveSense.job
Ordner Gefunden : C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp
Ordner Gefunden C:\Program Files (x86)\Advanced System Protector
Ordner Gefunden C:\Program Files (x86)\appbarioDE
Ordner Gefunden C:\Program Files (x86)\AppSafe
Ordner Gefunden C:\Program Files (x86)\Conduit
Ordner Gefunden C:\Program Files (x86)\MyPC Backup
Ordner Gefunden C:\Program Files (x86)\Optimizer Pro
Ordner Gefunden C:\Program Files (x86)\PC Speed Maximizer
Ordner Gefunden C:\Program Files (x86)\SupTab
Ordner Gefunden C:\Program Files\Level Quality Watcher
Ordner Gefunden C:\ProgramData\Activeris
Ordner Gefunden C:\ProgramData\Conduit
Ordner Gefunden C:\ProgramData\Partner
Ordner Gefunden C:\ProgramData\Systweak
Ordner Gefunden C:\Users\xyz\AppData\Local\Conduit
Ordner Gefunden C:\Users\xyz\AppData\Local\NativeMessaging
Ordner Gefunden C:\Users\xyz\AppData\Local\Tuguu_SL
Ordner Gefunden C:\Users\xyz\AppData\Local\WhiteListing
Ordner Gefunden C:\Users\xyz\AppData\LocalLow\appbarioDE
Ordner Gefunden C:\Users\xyz\AppData\LocalLow\Conduit
Ordner Gefunden C:\Users\xyz\AppData\Roaming\AppCloudUpdater
Ordner Gefunden C:\Users\xyz\AppData\Roaming\AppSafe
Ordner Gefunden C:\Users\xyz\AppData\Roaming\PerformerSoft
Ordner Gefunden C:\Users\xyz\AppData\Roaming\SearchProtect
Ordner Gefunden C:\Users\xyz\AppData\Roaming\SpeedAnalysis2
Ordner Gefunden C:\Users\xyz\AppData\Roaming\SupTab
Ordner Gefunden C:\Users\xyz\AppData\Roaming\Systweak
Ordner Gefunden C:\Users\xyz\AppData\Roaming\viddyhd
Ordner Gefunden C:\Users\xyz\Documents\Optimizer Pro

***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****

Daten Gefunden : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~2\optimi~1\optpro~1.dll
Daten Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\OPTIMI~1\OPTPRO~2.DLL
Schlüssel Gefunden : HKCU\Software\Alexa Internet
Schlüssel Gefunden : HKCU\Software\AnyProtect
Schlüssel Gefunden : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\appbarioDE
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gefunden : HKCU\Software\AppSafe
Schlüssel Gefunden : HKCU\Software\Conduit
Schlüssel Gefunden : HKCU\Software\distromatic
Schlüssel Gefunden : HKCU\Software\installedbrowserextensions
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{525BA996-1CE4-4677-91C5-9FC4EAD2D245}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{525BA996-1CE4-4677-91C5-9FC4EAD2D245}
Schlüssel Gefunden : HKCU\Software\Optimizer Pro
Schlüssel Gefunden : HKCU\Software\pc speed maximizer
Schlüssel Gefunden : HKCU\Software\performersoft llc
Schlüssel Gefunden : HKCU\Software\systweak
Schlüssel Gefunden : [x64] HKCU\Software\Alexa Internet
Schlüssel Gefunden : [x64] HKCU\Software\AnyProtect
Schlüssel Gefunden : [x64] HKCU\Software\AppSafe
Schlüssel Gefunden : [x64] HKCU\Software\Conduit
Schlüssel Gefunden : [x64] HKCU\Software\distromatic
Schlüssel Gefunden : [x64] HKCU\Software\installedbrowserextensions
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gefunden : [x64] HKCU\Software\Optimizer Pro
Schlüssel Gefunden : [x64] HKCU\Software\pc speed maximizer
Schlüssel Gefunden : [x64] HKCU\Software\performersoft llc
Schlüssel Gefunden : [x64] HKCU\Software\systweak
Schlüssel Gefunden : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gefunden : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gefunden : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gefunden : HKLM\Software\appbarioDE
Schlüssel Gefunden : HKLM\Software\AppSafe
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{525BA996-1CE4-4677-91C5-9FC4EAD2D245}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gefunden : HKLM\Software\Conduit
Schlüssel Gefunden : HKLM\Software\installedbrowserextensions
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4C180B6-0C26-4E0F-B4B9-1D7EF346F3D5}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASAPI32
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\speedupmypc_RASMANCS
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{525BA996-1CE4-4677-91C5-9FC4EAD2D245}
Schlüssel Gefunden : HKLM\Software\supWPM
Schlüssel Gefunden : HKLM\Software\systweak
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\installedbrowserextensions
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}
Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [speedanalysis02@SpeedAnalysis.com]
Wert Gefunden : HKCU\Software\Mozilla\Firefox\Extensions [zulagames@ZulaGames.com]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{525BA996-1CE4-4677-91C5-9FC4EAD2D245}]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{525BA996-1CE4-4677-91C5-9FC4EAD2D245}]
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [speedanalysis02@SpeedAnalysis.com]
Wert Gefunden : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [zulagames@ZulaGames.com]
Wert Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{318A227B-5E9F-45BD-8999-7F8F10CA4CF5}]

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16521

Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}
Einstellung Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page] - hxxp://www.awesomehp.com/web/?type=ds&ts=1394987874&from=tugs&uid=WDCXWD5000BPVT-80HXZT3_WD-WXR1A81A6359A6359&q={searchTerms}

-\\ Google Chrome v34.0.1847.116

[ Datei : C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Gefunden [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gefunden [Extension] : deghekbbihbapplmbffglehkdhkeibbm
Gefunden [Extension] : dgjkhjdcljddbedokogakmmdjgnbeanf
Gefunden [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gefunden [Extension] : gflandjopdloblmlcoiidmncpinmmacn
Gefunden [Extension] : jainjonnknhmbbkibcbmhihbopigapdm
Gefunden [Extension] : lekgiimbfodefdaoofhlckefjbgpeilo
Gefunden [Extension] : ombmmloebnfnpehgjnmkcgoegfachobp
Gefunden [Extension] : pelmeidfhdlhlbjimpabfcbnnojbboma

*************************

AdwCleaner[R0].txt - [26531 octets] - [22/04/2014 16:56:01]
AdwCleaner[R1].txt - [10510 octets] - [22/04/2014 23:58:48]

########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [10571 octets] ##########
         
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by xyz on 23.04.2014 at  2:58:02,62
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{F816170D-C994-4B74-B9A4-234C3838C9EB}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{10F02070-5C8C-4E0B-9D76-ED5DEC00A416}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DCBF59AF-92DF-4CD7-A341-6F448E532676}



~~~ Files



~~~ Folders



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.04.2014 at  3:13:30,56
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
FRST passte nicht mehr rein. Den schicke ich hinterher
Bin gespannt wie es aussieht!!
__________________
__________________

Alt 23.04.2014, 08:12   #4
caiphi
 
Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Hier die FRST Log Datei und die Addition.txt



FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014
Ran by xyz (administrator) on STEFANIE on 23-04-2014 07:39:23
Running from C:\Users\xyz\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Jumping Bytes) C:\Program Files (x86)\PureSync\PureSyncTray.exe
(ASUS) C:\Windows\AsScrPro.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-09-19] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2816808 2011-07-21] (Synaptics Incorporated)
HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [98088 2011-07-21] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-22] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [PureSync] => C:\Program Files (x86)\PureSync\PureSyncTray.exe [906928 2013-12-20] (Jumping Bytes)
HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [6277912 2014-03-18] (Piriform Ltd)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
SearchScopes: HKCU - URL hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3319116&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP5C705B91-74C4-49A1-A0D9-25AFC5B7A96E&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {433C345D-C1DE-4AE3-9E63-DFA494815841} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {7F1A9171-10E2-4C11-A42A-253499CDF7C5} URL = hxxp://dict.leo.org/ende?lp=ende&lang=de&searchLoc=0&cmpType=relaxed&sectHdr=on&spellToler=on&chinese=both&pinyin=diacritic&search={searchTerms}&relink=on
SearchScopes: HKCU - {C177248B-A9BC-4AF0-99CC-32A2CE37D81E} URL = hxxp://www.dict.cc/?s={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF Extension: Widget context - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2014-04-22]

Chrome: 
=======
CHR HomePage: 
CHR StartupUrls: "hxxp://www.google.de/"]},"sync_promo":{"show_on_first_run_allowed":false},"translate_accepted_count":{"en":0,"nl":0,"und":0},"translate_blocked_languages":["de"],"translate_denied_count":{"en":39,"nl":3,"und":4},"translate_whitelists":{},"webkit":{"webprefs":{"allow_running_insecure_content"
CHR Extension: (YouTube) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-15]
CHR Extension: (Google Search) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-15]
CHR Extension: (Google Wallet) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-22]
CHR Extension: (No Name) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp [2014-04-22]
CHR Extension: (Gmail) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-15]
CHR HKCU\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24]
CHR HKLM-x32\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24]

==================== Services (Whitelisted) =================

R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [16768 2011-09-20] (ASUSTek Computer Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61120 2014-03-22] (StdLib)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-23 07:39 - 2014-04-23 07:39 - 00012857 _____ () C:\Users\xyz\Downloads\FRST.txt
2014-04-23 02:58 - 2014-04-23 02:58 - 00000000 ____D () C:\Windows\ERUNT
2014-04-23 00:53 - 2014-04-23 04:05 - 00014744 _____ () C:\Windows\WindowsUpdate.log
2014-04-23 00:00 - 2014-04-23 00:00 - 01016261 _____ (Thisisu) C:\Users\xyz\Downloads\JRT.exe
2014-04-22 23:57 - 2014-04-22 23:58 - 01345435 _____ () C:\Users\xyz\Downloads\adwcleaner (1).exe
2014-04-22 23:14 - 2014-04-22 23:14 - 00003284 _____ () C:\Windows\System32\Tasks\{324FD7F0-E2EE-4055-8CE7-EB756A000476}
2014-04-22 23:08 - 2014-04-22 23:08 - 00001266 _____ () C:\Users\xyz\Desktop\Revo Uninstaller.lnk
2014-04-22 23:07 - 2014-04-22 23:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\xyz\Downloads\revosetup.exe
2014-04-22 22:58 - 2014-04-22 23:48 - 00000274 _____ () C:\Windows\Tasks\AppSafe.job
2014-04-22 22:58 - 2014-04-22 23:04 - 00003010 _____ () C:\Windows\System32\Tasks\AppSafe
2014-04-22 19:54 - 2014-04-23 07:38 - 00000000 ____D () C:\Users\xyz\Desktop\log Dateien
2014-04-22 18:54 - 2014-04-22 18:54 - 00380416 _____ () C:\Users\xyz\Downloads\Gmer-19357.exe
2014-04-22 18:51 - 2014-04-23 07:39 - 00000000 ____D () C:\FRST
2014-04-22 18:51 - 2014-04-22 18:51 - 02061312 _____ (Farbar) C:\Users\xyz\Downloads\FRST64.exe
2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable
2014-04-22 18:47 - 2014-04-22 18:47 - 00050477 _____ () C:\Users\xyz\Downloads\Defogger.exe
2014-04-22 16:55 - 2014-04-23 02:55 - 00000000 ____D () C:\AdwCleaner
2014-04-22 16:54 - 2014-04-22 16:54 - 01335637 _____ () C:\Users\xyz\Downloads\adwcleaner.exe
2014-04-22 16:51 - 2014-04-22 23:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-22 16:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-22 16:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-22 16:51 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-22 14:51 - 2014-04-22 14:53 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files\iTunes
2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod
2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7}
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList
2014-04-13 12:00 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-13 12:00 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-13 12:00 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-13 12:00 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-13 11:59 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-13 11:59 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-13 11:59 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-13 11:59 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-13 11:59 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-13 11:59 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-13 11:59 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-13 11:59 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-13 11:59 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-13 11:59 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-13 11:59 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-13 11:59 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97}

==================== One Month Modified Files and Folders =======

2014-04-23 07:39 - 2014-04-23 07:39 - 00012857 _____ () C:\Users\xyz\Downloads\FRST.txt
2014-04-23 07:39 - 2014-04-22 18:51 - 00000000 ____D () C:\FRST
2014-04-23 07:38 - 2014-04-22 19:54 - 00000000 ____D () C:\Users\xyz\Desktop\log Dateien
2014-04-23 07:25 - 2014-04-23 00:53 - 00014744 _____ () C:\Windows\WindowsUpdate.log
2014-04-23 07:20 - 2013-03-15 17:16 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-23 06:53 - 2013-03-15 17:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-23 04:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-23 02:58 - 2014-04-23 02:58 - 00000000 ____D () C:\Windows\ERUNT
2014-04-23 02:55 - 2014-04-22 16:55 - 00000000 ____D () C:\AdwCleaner
2014-04-23 00:58 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-23 00:58 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-23 00:50 - 2013-03-15 17:16 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-23 00:50 - 2013-01-10 19:09 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe
2014-04-23 00:50 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-23 00:00 - 2014-04-23 00:00 - 01016261 _____ (Thisisu) C:\Users\xyz\Downloads\JRT.exe
2014-04-22 23:58 - 2014-04-22 23:57 - 01345435 _____ () C:\Users\xyz\Downloads\adwcleaner (1).exe
2014-04-22 23:51 - 2014-04-22 16:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-22 23:48 - 2014-04-22 22:58 - 00000274 _____ () C:\Windows\Tasks\AppSafe.job
2014-04-22 23:45 - 2014-03-22 15:16 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\532d8d0bcd6da1a357004531
2014-04-22 23:14 - 2014-04-22 23:14 - 00003284 _____ () C:\Windows\System32\Tasks\{324FD7F0-E2EE-4055-8CE7-EB756A000476}
2014-04-22 23:08 - 2014-04-22 23:08 - 00001266 _____ () C:\Users\xyz\Desktop\Revo Uninstaller.lnk
2014-04-22 23:08 - 2013-01-10 19:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-22 23:07 - 2014-04-22 23:07 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\xyz\Downloads\revosetup.exe
2014-04-22 23:04 - 2014-04-22 22:58 - 00003010 _____ () C:\Windows\System32\Tasks\AppSafe
2014-04-22 22:55 - 2012-08-22 09:25 - 00002224 _____ () C:\Windows\system32\AutoRunFilter.ini
2014-04-22 21:01 - 2013-03-23 17:29 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-04-22 21:01 - 2013-01-10 19:56 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-22 18:54 - 2014-04-22 18:54 - 00380416 _____ () C:\Users\xyz\Downloads\Gmer-19357.exe
2014-04-22 18:51 - 2014-04-22 18:51 - 02061312 _____ (Farbar) C:\Users\xyz\Downloads\FRST64.exe
2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable
2014-04-22 18:48 - 2013-01-10 19:09 - 00000000 ____D () C:\Users\xyz
2014-04-22 18:47 - 2014-04-22 18:47 - 00050477 _____ () C:\Users\xyz\Downloads\Defogger.exe
2014-04-22 17:07 - 2009-07-14 04:34 - 00000678 _____ () C:\Windows\win.ini
2014-04-22 16:54 - 2014-04-22 16:54 - 01335637 _____ () C:\Users\xyz\Downloads\adwcleaner.exe
2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-22 16:45 - 2014-03-22 15:23 - 54485192 _____ () C:\Windows\system32\SavingsBullFilterService.log
2014-04-22 16:31 - 2012-08-22 09:25 - 00000000 ____D () C:\ProgramData\P4G
2014-04-22 16:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-04-22 16:01 - 2014-03-16 18:37 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-04-22 15:24 - 2011-02-19 06:24 - 00710852 _____ () C:\Windows\system32\perfh007.dat
2014-04-22 15:24 - 2011-02-19 06:24 - 00153300 _____ () C:\Windows\system32\perfc007.dat
2014-04-22 15:24 - 2009-07-14 07:13 - 01650460 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-22 14:53 - 2014-04-22 14:51 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iTunes
2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod
2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7}
2014-04-22 14:28 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-22 14:27 - 2014-03-23 00:42 - 00000000 ____D () C:\ProgramData\Free Download Manager
2014-04-22 14:27 - 2013-01-15 00:13 - 00000000 ____D () C:\Program Files (x86)\HP
2014-04-22 14:27 - 2013-01-10 19:57 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com
2014-04-22 14:27 - 2012-08-22 09:28 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2014-04-22 14:27 - 2011-04-13 04:47 - 00000000 ____D () C:\Program Files (x86)\ASUS
2014-04-22 14:24 - 2011-04-13 04:49 - 00000000 ____D () C:\AsusVibeData
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList
2014-04-22 13:37 - 2014-03-23 00:41 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Free Download Manager
2014-04-22 10:58 - 2013-01-10 21:38 - 00000000 ____D () C:\Users\xyz\Documents\Outlook-Dateien
2014-04-16 11:48 - 2013-01-10 21:18 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-16 11:46 - 2013-08-15 03:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-16 11:38 - 2013-01-13 08:13 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97}
2014-04-03 19:15 - 2013-03-15 17:16 - 00004126 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-03 19:15 - 2013-03-15 17:16 - 00003874 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-03 19:14 - 2014-02-25 11:15 - 00002155 _____ () C:\Windows\epplauncher.mif
2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-03 09:51 - 2014-04-22 16:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-22 16:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-22 16:51 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 03:16 - 2014-04-13 12:00 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-13 12:00 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-27 20:09 - 2014-03-15 20:38 - 00000110 _____ () C:\Users\xyz\AppData\Roaming\WB.CFG

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.5928.dll


Some content of TEMP:
====================
C:\Users\xyz\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-23 04:15

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2014
Ran by xyz at 2014-04-23 08:48:54
Running from C:\Users\xyz\Desktop\log Dateien
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden
AMD APP SDK Runtime (Version: 2.5.775.2 - Advanced Micro Devices Inc.) Hidden
AMD AVIVO64 Codecs (Version: 11.7.0.10927 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{92015CBE-D397-C3EA-99FC-B03051DE69A4}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
ccc-utility64 (Version: 2011.0927.2225.38375 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS)
HP Unified IO (Version: 1.0.1.95 - HP) Hidden
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
MAGIX Video easy HD (Version: 5.0.0.99 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.17.0 - Synaptics Incorporated)

==================== Restore Points  =========================

22-04-2014 09:03:06 Revo Uninstaller's restore point - Adobe Flash Player Packages
22-04-2014 09:08:22 Revo Uninstaller's restore point - AsusVibe2.0
22-04-2014 09:10:31 Revo Uninstaller's restore point - NewPlayer
22-04-2014 09:13:05 Revo Uninstaller's restore point - Optimizer Pro v3.2
22-04-2014 09:14:28 Revo Uninstaller's restore point - HQTotalS
22-04-2014 09:15:53 Revo Uninstaller's restore point - IePluginService12.27.0.3326
22-04-2014 09:17:02 Revo Uninstaller's restore point - InstantOn for NB
22-04-2014 09:20:20 Revo Uninstaller's restore point - Lollipop
22-04-2014 09:21:59 Revo Uninstaller's restore point - media enhance
22-04-2014 11:16:55 Revo Uninstaller's restore point - Re-markit
22-04-2014 11:18:38 Revo Uninstaller's restore point - PC Speed Maximizer v3.2
22-04-2014 11:19:57 Revo Uninstaller's restore point - Plants vs Zombies
22-04-2014 11:34:22 Revo Uninstaller's restore point - WPM17.8.0.3442
22-04-2014 11:35:41 Revo Uninstaller's restore point - ViddyHD
22-04-2014 11:37:27 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections
22-04-2014 11:39:22 Revo Uninstaller's restore point - VO Package
22-04-2014 12:10:15 Wiederherstellungsvorgang
22-04-2014 13:03:55 Revo Uninstaller's restore point - Advanced System Protector
22-04-2014 13:07:03 Revo Uninstaller's restore point - Adobe Flash Player Packages
22-04-2014 13:10:00 Revo Uninstaller's restore point - awesomehp uninstaller
22-04-2014 13:11:25 Revo Uninstaller's restore point - File Extractor
22-04-2014 13:13:59 Revo Uninstaller's restore point - DMUninstaller
22-04-2014 13:23:47 Revo Uninstaller's restore point - RegClean Pro
22-04-2014 13:25:57 Revo Uninstaller's restore point - Lollipop
22-04-2014 13:27:32 Revo Uninstaller's restore point - ViddyHD
22-04-2014 13:30:02 Revo Uninstaller's restore point - PC Speed Maximizer v3.2
22-04-2014 13:44:45 Revo Uninstaller's restore point - Search Protect
22-04-2014 13:49:20 Revo Uninstaller's restore point - SupTab
22-04-2014 13:50:55 Revo Uninstaller's restore point - Mysearchdial
22-04-2014 13:52:32 Revo Uninstaller's restore point - WPM17.8.0.3442
22-04-2014 13:59:32 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections
22-04-2014 14:00:35 Revo Uninstaller's restore point - Re-markit
22-04-2014 14:01:51 Revo Uninstaller's restore point - Optimizer Pro v3.2
22-04-2014 14:11:03 Revo Uninstaller's restore point - IePluginService12.27.0.3326
22-04-2014 14:14:36 Revo Uninstaller's restore point - media enhance
22-04-2014 14:20:06 Revo Uninstaller's restore point - VO Package
22-04-2014 14:27:49 Wiederherstellungsvorgang
22-04-2014 14:37:37 Revo Uninstaller's restore point - HQTotalS
22-04-2014 21:08:31 Revo Uninstaller's restore point - AppCloudUpdater

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {05490B50-D0A0-4A3C-A560-6ACF63DE1E42} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - \APSnotifierPP2 No Task File <==== ATTENTION
Task: {0B4E379A-4C4A-428E-9BCF-A1135BBA3E4A} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2012-09-27] ()
Task: {1CCE7D51-38D1-4F66-B7AC-A43176E2120F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-09-30] (ASUSTeK Computer Inc.)
Task: {3E2E8B1F-6878-402A-87AB-F2EF5FEBADCE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.)
Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - \APSnotifierPP1 No Task File <==== ATTENTION
Task: {4C14D4FC-EFFF-4FC1-BA61-EEFA91392794} - System32\Tasks\USBChargerPlus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2011-09-20] (ASUSTek Computer Inc.)
Task: {5CDD33CE-1114-4D15-A601-881F87353200} - System32\Tasks\AppSafe => C:\Program Files (x86)\AppSafe\AppSafe.exe
Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - \Advanced System Protector_startup No Task File <==== ATTENTION
Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - \MySearchDial No Task File <==== ATTENTION
Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - \RegClean Pro No Task File <==== ATTENTION
Task: {8FFE3A4C-B16E-4461-A1BC-27379739F580} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22] (ASUS)
Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - \APSnotifierPP3 No Task File <==== ATTENTION
Task: {AF490895-86A7-4FE9-9CC6-9EC88297132C} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-11-22] (ASUS)
Task: {C410E796-D92D-4AEB-A596-89D282D0DBF8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.)
Task: {EAD7D671-DBE5-4388-994E-8F508652131C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS)
Task: {EB32D426-01C9-4433-875C-580B292A89F0} - \SaveSense No Task File <==== ATTENTION
Task: {EDBAD762-5B95-4C13-9FA0-333BACA63683} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-03-14] (Adobe Systems Incorporated)
Task: {F9C0DFA3-7859-4C70-A44F-5E77F9E82EA7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {FE3FBFF8-BA1D-4554-A7AA-BA0DCD11606F} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AppSafe.job => C:\Program Files (x86)\AppSafe\AppSafe.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2011-10-13 08:19 - 2011-07-21 12:59 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-09-30 02:06 - 2011-09-30 02:06 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
2011-11-22 16:09 - 2011-11-22 16:09 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2011-09-13 22:33 - 2011-09-13 22:33 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:AD022376

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============
Error: (04/23/2014 07:36:58 AM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Microsoft Office Sessions:
=========================

==================== Memory info =========================== 

Percentage of memory in use: 28%
Total physical RAM: 6048.05 MB
Available physical RAM: 4294.69 MB
Total Pagefile: 12094.28 MB
Available Pagefile: 10146.46 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:195.35 GB) (Free:127.96 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Data) (Fixed) (Total:245.41 GB) (Free:210.98 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 496B9619)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=195 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=245 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
Hoffe das ist besser , als sie gepackt zu schicken.
__________________
Gruß
Volker

Geändert von caiphi (23.04.2014 um 08:58 Uhr) Grund: Addition.txt ergänzt

Alt 23.04.2014, 15:20   #5
schrauber
/// the machine
/// TB-Ausbilder
 

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 23.04.2014, 18:37   #6
caiphi
 
Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Lächeln

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Eset Scan ist durchgelaufen. Hat keine Threads gefunden. Bei der Deinstallation ist leider auch der Logfile mit gelöscht worden. Reicht Dir die Info, daß nichts gefunden wurde, oder soll ich nochmal laufen lassen (hat ca. 1,5 h gebraucht) Den Logfile des securitychecks hab ich hier
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.82  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Microsoft Security Essentials   
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:````````` 
 Secunia PSI (3.0.0.9016)   
 Adobe Flash Player 13.0.0.182  
 Google Chrome 33.0.1750.154  
 Google Chrome 34.0.1847.116  
 Google Chrome Plugins...  
````````Process Check: objlist.exe by Laurent````````  
 Microsoft Security Essentials msseces.exe 
 Windows Defender MSMpEng.exe 
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
FRST

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014
Ran by xyz (administrator) on STEFANIE on 23-04-2014 18:38:13
Running from C:\Users\xyz\Desktop\log Dateien
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\Common Files\InstantOn\InsOnWMI.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(ASUS) C:\Windows\AsScrPro.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Jumping Bytes) C:\Program Files (x86)\PureSync\PureSyncTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(ASUS) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSI_TRAY.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2278504 2011-09-19] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2816808 2011-07-21] (Synaptics Incorporated)
HKLM\...\Run: [SynAsusAcpi] => C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe [98088 2011-07-21] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\ASUS Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5716608 2011-07-22] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2317312 2011-09-13] (ASUS)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [PureSync] => C:\Program Files (x86)\PureSync\PureSyncTray.exe [906928 2013-12-20] (Jumping Bytes)
HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-889188840-3397074576-2393254512-1000\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [6277912 2014-03-18] (Piriform Ltd)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
SearchScopes: HKCU - URL hxxp://www.trovigo.com/Results.aspx?gd=&ctid=CT3319116&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=5&UP=SP5C705B91-74C4-49A1-A0D9-25AFC5B7A96E&q={searchTerms}&SSPV=
SearchScopes: HKCU - SuggestionsURL_JSON hxxp://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}
SearchScopes: HKCU - {433C345D-C1DE-4AE3-9E63-DFA494815841} URL = hxxp://suche.web.de/search/web/?su={searchTerms}&mc=searchplugin@suche@msie.suche@web&origin=searchplugin
SearchScopes: HKCU - {7F1A9171-10E2-4C11-A42A-253499CDF7C5} URL = hxxp://dict.leo.org/ende?lp=ende&lang=de&searchLoc=0&cmpType=relaxed&sectHdr=on&spellToler=on&chinese=both&pinyin=diacritic&search={searchTerms}&relink=on
SearchScopes: HKCU - {C177248B-A9BC-4AF0-99CC-32A2CE37D81E} URL = hxxp://www.dict.cc/?s={searchTerms}
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF Extension: Widget context - C:\Users\xyz\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2014-04-22]

Chrome: 
=======
CHR HomePage: 
CHR StartupUrls: "hxxp://www.google.de/"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll ()
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Zeon Plus) - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Extension: (YouTube) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-15]
CHR Extension: (Google-Suche) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-15]
CHR Extension: (Google Wallet) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-22]
CHR Extension: (Google Mail) - C:\Users\xyz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-15]
CHR HKCU\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24]
CHR HKLM-x32\...\Chrome\Extension: [kdneagjiboclldmglpjofpeipkbollcf] - C:\Users\xyz\AppData\Local\CRE\kdneagjiboclldmglpjofpeipkbollcf.crx [2013-09-24]

==================== Services (Whitelisted) =================

R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)

==================== Drivers (Whitelisted) ====================

R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [16768 2011-09-20] (ASUSTek Computer Inc.)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
R1 wStLib64; C:\Windows\System32\drivers\wStLib64.sys [61120 2014-03-22] (StdLib)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-04-23 18:24 - 2014-04-23 18:24 - 17932464 _____ (Adobe Systems Incorporated) C:\Users\xyz\Downloads\flashplayer13_install_win_pi.exe
2014-04-23 18:19 - 2014-04-23 18:19 - 00000000 ____D () C:\Users\xyz\AppData\Local\Secunia PSI
2014-04-23 18:19 - 2014-04-23 18:19 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-04-23 15:38 - 2014-04-23 15:38 - 00855379 _____ () C:\Users\xyz\Downloads\SecurityCheck.exe
2014-04-23 15:25 - 2014-04-23 15:25 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-04-23 15:24 - 2014-04-23 15:24 - 02347384 _____ (ESET) C:\Users\xyz\Downloads\esetsmartinstaller_enu.exe
2014-04-23 02:58 - 2014-04-23 02:58 - 00000000 ____D () C:\Windows\ERUNT
2014-04-23 00:53 - 2014-04-23 18:21 - 00089985 _____ () C:\Windows\WindowsUpdate.log
2014-04-22 23:14 - 2014-04-22 23:14 - 00003284 _____ () C:\Windows\System32\Tasks\{324FD7F0-E2EE-4055-8CE7-EB756A000476}
2014-04-22 23:08 - 2014-04-22 23:08 - 00001266 _____ () C:\Users\xyz\Desktop\Revo Uninstaller.lnk
2014-04-22 22:58 - 2014-04-22 23:48 - 00000274 _____ () C:\Windows\Tasks\AppSafe.job
2014-04-22 22:58 - 2014-04-22 23:04 - 00003010 _____ () C:\Windows\System32\Tasks\AppSafe
2014-04-22 19:54 - 2014-04-23 18:38 - 00000000 ____D () C:\Users\xyz\Desktop\log Dateien
2014-04-22 18:51 - 2014-04-23 18:38 - 00000000 ____D () C:\FRST
2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable
2014-04-22 16:55 - 2014-04-23 02:55 - 00000000 ____D () C:\AdwCleaner
2014-04-22 16:51 - 2014-04-23 09:04 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-22 16:51 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-22 16:51 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-22 16:51 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-22 14:51 - 2014-04-22 14:53 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files\iTunes
2014-04-22 14:51 - 2014-04-22 14:52 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod
2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7}
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList
2014-04-13 12:00 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-13 12:00 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-13 12:00 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-13 12:00 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-13 11:59 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-13 11:59 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-13 11:59 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-13 11:59 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-13 11:59 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-13 11:59 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-13 11:59 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-13 11:59 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-13 11:59 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-13 11:59 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-13 11:59 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-13 11:59 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-13 11:59 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97}

==================== One Month Modified Files and Folders =======

2014-04-23 18:38 - 2014-04-22 19:54 - 00000000 ____D () C:\Users\xyz\Desktop\log Dateien
2014-04-23 18:38 - 2014-04-22 18:51 - 00000000 ____D () C:\FRST
2014-04-23 18:27 - 2013-06-20 15:25 - 00000000 ____D () C:\Users\xyz\AppData\Local\Adobe
2014-04-23 18:27 - 2013-03-15 17:16 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-23 18:27 - 2013-03-15 17:16 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-23 18:27 - 2013-01-27 17:18 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-23 18:27 - 2013-01-27 17:18 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-23 18:24 - 2014-04-23 18:24 - 17932464 _____ (Adobe Systems Incorporated) C:\Users\xyz\Downloads\flashplayer13_install_win_pi.exe
2014-04-23 18:21 - 2014-04-23 00:53 - 00089985 _____ () C:\Windows\WindowsUpdate.log
2014-04-23 18:20 - 2013-03-15 17:16 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-23 18:19 - 2014-04-23 18:19 - 00000000 ____D () C:\Users\xyz\AppData\Local\Secunia PSI
2014-04-23 18:19 - 2014-04-23 18:19 - 00000000 ____D () C:\Program Files (x86)\Secunia
2014-04-23 15:38 - 2014-04-23 15:38 - 00855379 _____ () C:\Users\xyz\Downloads\SecurityCheck.exe
2014-04-23 15:25 - 2014-04-23 15:25 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-04-23 15:24 - 2014-04-23 15:24 - 02347384 _____ (ESET) C:\Users\xyz\Downloads\esetsmartinstaller_enu.exe
2014-04-23 10:44 - 2014-01-11 20:00 - 00000000 ____D () C:\Program Files (x86)\MAGIX
2014-04-23 10:38 - 2013-01-10 21:38 - 00000000 ____D () C:\Users\xyz\Documents\Outlook-Dateien
2014-04-23 10:17 - 2011-04-13 04:49 - 00000000 ____D () C:\AsusVibeData
2014-04-23 09:32 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-23 09:32 - 2009-07-14 06:45 - 00018512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-23 09:25 - 2013-03-15 17:16 - 00001126 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-23 09:25 - 2013-01-10 19:09 - 00045056 _____ () C:\Windows\SysWOW64\acovcnt.exe
2014-04-23 09:24 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-23 09:04 - 2014-04-22 16:51 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-23 04:23 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-23 02:58 - 2014-04-23 02:58 - 00000000 ____D () C:\Windows\ERUNT
2014-04-23 02:55 - 2014-04-22 16:55 - 00000000 ____D () C:\AdwCleaner
2014-04-22 23:48 - 2014-04-22 22:58 - 00000274 _____ () C:\Windows\Tasks\AppSafe.job
2014-04-22 23:45 - 2014-03-22 15:16 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\532d8d0bcd6da1a357004531
2014-04-22 23:14 - 2014-04-22 23:14 - 00003284 _____ () C:\Windows\System32\Tasks\{324FD7F0-E2EE-4055-8CE7-EB756A000476}
2014-04-22 23:08 - 2014-04-22 23:08 - 00001266 _____ () C:\Users\xyz\Desktop\Revo Uninstaller.lnk
2014-04-22 23:08 - 2013-01-10 19:43 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-22 23:04 - 2014-04-22 22:58 - 00003010 _____ () C:\Windows\System32\Tasks\AppSafe
2014-04-22 22:55 - 2012-08-22 09:25 - 00002224 _____ () C:\Windows\system32\AutoRunFilter.ini
2014-04-22 21:01 - 2013-03-23 17:29 - 00000824 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-04-22 21:01 - 2013-01-10 19:56 - 00000000 ____D () C:\Program Files\CCleaner
2014-04-22 18:48 - 2014-04-22 18:48 - 00000000 _____ () C:\Users\xyz\defogger_reenable
2014-04-22 18:48 - 2013-01-10 19:09 - 00000000 ____D () C:\Users\xyz
2014-04-22 17:07 - 2009-07-14 04:34 - 00000678 _____ () C:\Windows\win.ini
2014-04-22 16:51 - 2014-04-22 16:51 - 00001104 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 16:51 - 2014-04-22 16:51 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-04-22 16:45 - 2014-03-22 15:23 - 54485192 _____ () C:\Windows\system32\SavingsBullFilterService.log
2014-04-22 16:31 - 2012-08-22 09:25 - 00000000 ____D () C:\ProgramData\P4G
2014-04-22 16:31 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-04-22 16:01 - 2014-03-16 18:37 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-04-22 15:59 - 2014-04-22 15:59 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-04-22 15:24 - 2011-02-19 06:24 - 00710852 _____ () C:\Windows\system32\perfh007.dat
2014-04-22 15:24 - 2011-02-19 06:24 - 00153300 _____ () C:\Windows\system32\perfc007.dat
2014-04-22 15:24 - 2009-07-14 07:13 - 01650460 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-22 14:53 - 2014-04-22 14:53 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-04-22 14:53 - 2014-04-22 14:51 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iTunes
2014-04-22 14:52 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-04-22 14:51 - 2014-04-22 14:51 - 00000000 ____D () C:\Program Files\iPod
2014-04-22 14:37 - 2014-04-22 14:37 - 00003164 _____ () C:\Windows\System32\Tasks\{6D147765-04A9-4B11-8DAB-DFD9058D64E7}
2014-04-22 14:28 - 2009-07-14 07:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-22 14:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-22 14:27 - 2014-03-23 00:42 - 00000000 ____D () C:\ProgramData\Free Download Manager
2014-04-22 14:27 - 2013-01-15 00:13 - 00000000 ____D () C:\Program Files (x86)\HP
2014-04-22 14:27 - 2013-01-10 19:57 - 00000000 ____D () C:\Program Files (x86)\FileHippo.com
2014-04-22 14:27 - 2012-08-22 09:28 - 00000000 ____D () C:\Program Files (x86)\CyberLink
2014-04-22 14:27 - 2011-04-13 04:47 - 00000000 ____D () C:\Program Files (x86)\ASUS
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieUserList
2014-04-22 14:00 - 2014-04-22 14:00 - 00000000 __SHD () C:\Users\xyz\AppData\Local\EmieSiteList
2014-04-22 13:37 - 2014-03-23 00:41 - 00000000 ____D () C:\Users\xyz\AppData\Roaming\Free Download Manager
2014-04-16 11:48 - 2013-01-10 21:18 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-16 11:46 - 2013-08-15 03:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-16 11:38 - 2013-01-13 08:13 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 ____H () C:\Users\xyz\AppData\Local\BIT3BF6.tmp
2014-04-03 19:34 - 2014-04-03 19:34 - 00000000 _____ () C:\Users\xyz\AppData\Local\{063736C8-CF9F-4B83-BC4A-8A2DDAAB7F97}
2014-04-03 19:15 - 2013-03-15 17:16 - 00004126 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-03 19:15 - 2013-03-15 17:16 - 00003874 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-03 19:14 - 2014-02-25 11:15 - 00002155 _____ () C:\Windows\epplauncher.mif
2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-03 19:14 - 2014-02-25 11:15 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-04-03 09:51 - 2014-04-22 16:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-22 16:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-22 16:51 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 03:16 - 2014-04-13 12:00 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-13 12:00 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-13 12:00 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-27 20:09 - 2014-03-15 20:38 - 00000110 _____ () C:\Users\xyz\AppData\Roaming\WB.CFG

Files to move or delete:
====================
C:\Users\Public\AlexaNSISPlugin.5928.dll


Some content of TEMP:
====================
C:\Users\xyz\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-04-23 04:15

==================== End Of Log ============================
         
--- --- ---

--- --- ---


Addition:

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-04-2014
Ran by xyz at 2014-04-23 18:39:17
Running from C:\Users\xyz\Desktop\log Dateien
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Microsoft Security Essentials (Enabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

64 Bit HP CIO Components Installer (Version: 7.2.4 - Hewlett-Packard) Hidden
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.182 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\{28ADCCAD-3C23-44A1-A93F-47AA176F7AD7}) (Version: 13.0.0.182 - Adobe Systems Incorporated)
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.182 - Adobe Systems Incorporated)
AMD APP SDK Runtime (Version: 2.5.775.2 - Advanced Micro Devices Inc.) Hidden
AMD AVIVO64 Codecs (Version: 11.7.0.10927 - Advanced Micro Devices, Inc.) Hidden
AMD Catalyst Install Manager (HKLM\...\{92015CBE-D397-C3EA-99FC-B03051DE69A4}) (Version: 3.0.847.0 - Advanced Micro Devices, Inc.)
Apple Mobile Device Support (HKLM\...\{787136D2-F0F8-4625-AA3F-72D7795AC842}) (Version: 7.1.1.3 - Apple Inc.)
ASUS Power4Gear Hybrid (HKLM\...\{33B98264-A889-4913-A0CA-C364A75032B3}) (Version: 1.1.45 - ASUS)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
ccc-utility64 (Version: 2011.0927.2225.38375 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.10 - ASUS)
HP Unified IO (Version: 1.0.1.95 - HP) Hidden
iCloud (HKLM\...\{81E20D41-C277-4526-934D-F2380AF91B78}) (Version: 3.1.0.40 - Apple Inc.)
iTunes (HKLM\...\{B8BA155B-1E75-405F-9CB4-8A99615D09DC}) (Version: 11.1.5.5 - Apple Inc.)
MAGIX Speed burnR (MSI) (Version: 7.0.2.6 - MAGIX AG) Hidden
Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Security Client (Version: 4.5.0216.0 - Microsoft Corporation) Hidden
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.5.216.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Secunia PSI (3.0.0.9016) (HKLM-x32\...\Secunia PSI) (Version: 3.0.0.9016 - Secunia)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.17.0 - Synaptics Incorporated)

==================== Restore Points  =========================

22-04-2014 11:37:27 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections
22-04-2014 11:39:22 Revo Uninstaller's restore point - VO Package
22-04-2014 12:10:15 Wiederherstellungsvorgang
22-04-2014 13:03:55 Revo Uninstaller's restore point - Advanced System Protector
22-04-2014 13:07:03 Revo Uninstaller's restore point - Adobe Flash Player Packages
22-04-2014 13:10:00 Revo Uninstaller's restore point - awesomehp uninstaller
22-04-2014 13:11:25 Revo Uninstaller's restore point - File Extractor
22-04-2014 13:13:59 Revo Uninstaller's restore point - DMUninstaller
22-04-2014 13:23:47 Revo Uninstaller's restore point - RegClean Pro
22-04-2014 13:25:57 Revo Uninstaller's restore point - Lollipop
22-04-2014 13:27:32 Revo Uninstaller's restore point - ViddyHD
22-04-2014 13:30:02 Revo Uninstaller's restore point - PC Speed Maximizer v3.2
22-04-2014 13:44:45 Revo Uninstaller's restore point - Search Protect
22-04-2014 13:49:20 Revo Uninstaller's restore point - SupTab
22-04-2014 13:50:55 Revo Uninstaller's restore point - Mysearchdial
22-04-2014 13:52:32 Revo Uninstaller's restore point - WPM17.8.0.3442
22-04-2014 13:59:32 Revo Uninstaller's restore point - Windows Live Mesh ActiveX Control for Remote Connections
22-04-2014 14:00:35 Revo Uninstaller's restore point - Re-markit
22-04-2014 14:01:51 Revo Uninstaller's restore point - Optimizer Pro v3.2
22-04-2014 14:11:03 Revo Uninstaller's restore point - IePluginService12.27.0.3326
22-04-2014 14:14:36 Revo Uninstaller's restore point - media enhance
22-04-2014 14:20:06 Revo Uninstaller's restore point - VO Package
22-04-2014 14:27:49 Wiederherstellungsvorgang
22-04-2014 14:37:37 Revo Uninstaller's restore point - HQTotalS
22-04-2014 21:08:31 Revo Uninstaller's restore point - AppCloudUpdater
23-04-2014 08:53:27 Windows Update

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {05490B50-D0A0-4A3C-A560-6ACF63DE1E42} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - \APSnotifierPP2 No Task File <==== ATTENTION
Task: {0B4E379A-4C4A-428E-9BCF-A1135BBA3E4A} - System32\Tasks\AsusVibeSchedule => C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe [2012-09-27] ()
Task: {1CCE7D51-38D1-4F66-B7AC-A43176E2120F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-09-30] (ASUSTeK Computer Inc.)
Task: {3E2E8B1F-6878-402A-87AB-F2EF5FEBADCE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.)
Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - \APSnotifierPP1 No Task File <==== ATTENTION
Task: {4C14D4FC-EFFF-4FC1-BA61-EEFA91392794} - System32\Tasks\USBChargerPlus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2011-09-20] (ASUSTek Computer Inc.)
Task: {5CDD33CE-1114-4D15-A601-881F87353200} - System32\Tasks\AppSafe => C:\Program Files (x86)\AppSafe\AppSafe.exe
Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - \Advanced System Protector_startup No Task File <==== ATTENTION
Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - \MySearchDial No Task File <==== ATTENTION
Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - \RegClean Pro No Task File <==== ATTENTION
Task: {8FFE3A4C-B16E-4461-A1BC-27379739F580} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2011-07-22] (ASUS)
Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - \APSnotifierPP3 No Task File <==== ATTENTION
Task: {AF490895-86A7-4FE9-9CC6-9EC88297132C} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2011-11-22] (ASUS)
Task: {C410E796-D92D-4AEB-A596-89D282D0DBF8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-03-15] (Google Inc.)
Task: {EAD7D671-DBE5-4388-994E-8F508652131C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2011-06-01] (ASUS)
Task: {EB32D426-01C9-4433-875C-580B292A89F0} - \SaveSense No Task File <==== ATTENTION
Task: {EDBAD762-5B95-4C13-9FA0-333BACA63683} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-23] (Adobe Systems Incorporated)
Task: {F9C0DFA3-7859-4C70-A44F-5E77F9E82EA7} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {FE3FBFF8-BA1D-4554-A7AA-BA0DCD11606F} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AppSafe.job => C:\Program Files (x86)\AppSafe\AppSafe.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2009-03-02 04:08 - 2009-03-02 04:08 - 00003584 _____ () C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\LogicNP.PropSheetExtensionHelper_x64.dll
2011-10-13 08:19 - 2011-07-21 12:59 - 00057640 _____ () C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll
2014-01-20 14:17 - 2014-01-20 14:17 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-01-20 14:16 - 2014-01-20 14:16 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2011-09-30 02:06 - 2011-09-30 02:06 - 00208384 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\alvupdt.dll
2011-11-22 16:09 - 2011-11-22 16:09 - 00009216 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2009-11-02 23:20 - 2009-11-02 23:20 - 00619816 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2009-11-02 23:23 - 2009-11-02 23:23 - 00013096 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
2011-09-13 22:33 - 2011-09-13 22:33 - 01163264 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\acAuth.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\Temp:AD022376

==================== Safe Mode (whitelisted) ===================


==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (04/23/2014 03:37:43 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/23/2014 03:35:06 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/23/2014 03:35:02 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/23/2014 03:35:02 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/23/2014 03:30:56 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/23/2014 03:30:50 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/23/2014 03:30:50 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/23/2014 03:25:09 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/23/2014 03:25:04 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error: (04/23/2014 03:25:04 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in
Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3.
Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit
einer anderen, bereits aktiven Komponentenversion.
In Konflikt stehende Komponenten:.
Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.


System errors:
=============
Error: (04/23/2014 05:45:01 PM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "ANGELIKA-PC",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{82D77809-3722-435C-8930-AADF27772196}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (04/23/2014 04:33:57 PM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "ANGELIKA-PC",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{82D77809-3722-435C-8930-AADF27772196}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (04/23/2014 11:02:28 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.

Error: (04/23/2014 10:53:04 AM) (Source: Schannel) (User: NT-AUTORITÄT)
Description: Es wurde eine schwerwiegende Warnung generiert: 40. Der interne Fehlerstatus lautet: 252.

Error: (04/23/2014 09:43:04 AM) (Source: bowser) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "ANGELIKA-PC",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{82D77809-3722-435C-8930-AADF27772196}-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (04/23/2014 09:24:13 AM) (Source: ACPI) (User: )
Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft.

Error: (04/23/2014 07:36:58 AM) (Source: DCOM) (User: )
Description: {995C996E-D918-4A8C-A302-45719A6F4EA7}


Microsoft Office Sessions:
=========================
Error: (04/23/2014 03:37:43 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Program Files (x86)\ESET\ESET Online Scanner\ESETSmartInstaller.exe

Error: (04/23/2014 03:35:06 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe

Error: (04/23/2014 03:35:02 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe

Error: (04/23/2014 03:35:02 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe

Error: (04/23/2014 03:30:56 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe

Error: (04/23/2014 03:30:50 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe

Error: (04/23/2014 03:30:50 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe

Error: (04/23/2014 03:25:09 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe

Error: (04/23/2014 03:25:04 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe

Error: (04/23/2014 03:25:04 PM) (Source: SideBySide)(User: )
Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\xyz\Downloads\esetsmartinstaller_enu.exe


==================== Memory info =========================== 

Percentage of memory in use: 31%
Total physical RAM: 6048.05 MB
Available physical RAM: 4151.73 MB
Total Pagefile: 12094.28 MB
Available Pagefile: 9947.68 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:195.35 GB) (Free:129.91 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (Data) (Fixed) (Total:245.41 GB) (Free:210.98 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 496B9619)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=195 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=245 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
Wie komme ich an die in der Addition im Task Bereich noch mit Attention markierten Tasks heran??
Weiterhin werden mir im Revo Uninstaller und auch in der Systemsteuerung nicht mehr alle installierten Programme angezeigt. Dies ist bei der Deinstallation des VO Package passiert!! Hast Du dafür ne Lösung??
__________________
--> Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung

Geändert von caiphi (23.04.2014 um 18:49 Uhr) Grund: Ergänzung FRST Logs

Alt 24.04.2014, 09:25   #7
caiphi
 
Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Beitrag

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Hab den Eset Scan wiederholt und das Logfile beigefügt...
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=bbb357d2aacdc443828761659e627366
# engine=18006
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-24 07:14:41
# local_time=2014-04-24 09:14:41 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776574 100 94 5012213 149953531 0 0
# scanned=162048
# found=0
# cleaned=0
# scan_time=4916
         
__________________
Gruß
Volker

Alt 24.04.2014, 20:48   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Reicht mir

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - \APSnotifierPP2 No Task File <==== ATTENTION
Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - \APSnotifierPP1 No Task File <==== ATTENTION
Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - \Advanced System Protector_startup No Task File <==== ATTENTION
Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - \MySearchDial No Task File <==== ATTENTION
Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - \RegClean Pro No Task File <==== ATTENTION
Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - \APSnotifierPP3 No Task File <==== ATTENTION
Task: {EB32D426-01C9-4433-875C-580B292A89F0} - \SaveSense No Task File <==== ATTENTION
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.





Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 25.04.2014, 10:19   #9
caiphi
 
Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Hallo Schrauber,
habe den FRST laufen lassen:
Code:
ATTFilter
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 24-04-2014
Ran by Stefanie Regener at 2014-04-24 23:24:38 Run:1
Running from C:\Users\Stefanie Regener\Desktop\log Dateien
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
Task: {06A4AD28-DDF9-47AA-BB59-AD0885D3F010} - \APSnotifierPP2 No Task File <==== ATTENTION
Task: {3E4D962A-67BC-47D3-9033-FD169C1B86FB} - \APSnotifierPP1 No Task File <==== ATTENTION
Task: {79A29FDB-3782-4B22-90CC-59A2098B7214} - \Advanced System Protector_startup No Task File <==== ATTENTION
Task: {7D7887FB-D125-4066-9E7A-3A47325E9106} - \MySearchDial No Task File <==== ATTENTION
Task: {8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} - \RegClean Pro No Task File <==== ATTENTION
Task: {A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} - \APSnotifierPP3 No Task File <==== ATTENTION
Task: {EB32D426-01C9-4433-875C-580B292A89F0} - \SaveSense No Task File <==== ATTENTION

*****************

C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{06A4AD28-DDF9-47AA-BB59-AD0885D3F010} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{06A4AD28-DDF9-47AA-BB59-AD0885D3F010} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP2 => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{3E4D962A-67BC-47D3-9033-FD169C1B86FB} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3E4D962A-67BC-47D3-9033-FD169C1B86FB} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP1 => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{79A29FDB-3782-4B22-90CC-59A2098B7214} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79A29FDB-3782-4B22-90CC-59A2098B7214} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Advanced System Protector_startup => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7D7887FB-D125-4066-9E7A-3A47325E9106} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D7887FB-D125-4066-9E7A-3A47325E9106} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MySearchDial => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CD4FCDE-D96B-41C8-871C-FEF71D3EC3DF} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RegClean Pro => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4B9C94B-66F8-4B78-A3E2-800FA7B7B5A0} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\APSnotifierPP3 => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EB32D426-01C9-4433-875C-580B292A89F0} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB32D426-01C9-4433-875C-580B292A89F0} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSense => Key deleted successfully.


The system needed a reboot. 

==== End of Fixlog ====
         
Das Script scheint soweit funktioniert zu haben.
Kannst Du noch was zum Revo Uninstaller sagen (s.o)
Melde mich nach der abschließenden Bereinigung nochmal!!

Hallo Schrauber,
ich habe jetzt alle Anweisung befolgt. Ich denke der Rechner ist wieder sauber. Die von Dir gegebenen Empfehlungen habe ich an den Benutzer des Laptops weitergegeben.

Den defekten Revo Uninstaller, der nur noch 4 Programme anzeigte, obwohl ca. 60 vorhanden sind, habe ich zweimal neu installiert, was nichts geändert hat, also habe ich ihn deinstalliert gelassen. Du hast für dieses Problem auch keine Erklärung oder Lösung?? Die Programme sind mit der Deinstallation vom VO Package verschwunden, egal ob ich es mit dem Uninstaller oder mit der Systemsteuerung deinstalliert habe.

Falls Du für dieses Problem keine Idee hast, ist der Fall damit abgeschlossen und ich (und meine Tochter) sind Dir sehr dankbar für die kompetente und schnelle Hilfe. Euer Trojaner Board ist eine ausgezeichnete Einrichtung und ich habe Hochachtung vor Eurem Tun, Eurer Begeisterung und Euren Fähigkeiten sowie auch der Konsequenz, mit denen ihr auf selbstverschuldetes Leid (crackz, illegale Software etc.) reagiert.

Vielen , vielen Dank!!
__________________
Gruß
Volker

Alt 25.04.2014, 20:11   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Sind die Programme nur in der Liste von Revo weg oder auch in der Windows Ansicht der installierten Programme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 26.04.2014, 20:39   #11
caiphi
 
Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Hallo Schrauber,
danke , dass Du Dich noch mal meldest;-))

Im CCleaner sind alle Programme angezeigt, im Systemordner ca 3/4 aller Programme und im Revo nur 4 Programme...Direkt nach der Deinstallation sind alle Programme bis auf zwei verschwunden. Alles was danach installiert wurde erschien auch im Revo! Bisher habe ich nur ein unwichtiges Programm von Aus entdeckt was auch nicht funktioniert. Alles andere incl. MS Office funktioniert.

Hast Du ne Idee??
__________________
Gruß
Volker

Alt 27.04.2014, 19:16   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Ja, die Adware VO Package hat die Uninstall Liste zerschossen. Da haben mitlerweile mehr Leute das Problem, wir wussten nur nie welche Adware es genau ist. Jetz weiß ich es und kann versuchen das zu beheben. Im Moment ist es nur leider so das wir das nicht mehr ändern können, aber der CCleaner zeigt ja alle an. Also nur Kosmetik.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 30.04.2014, 00:34   #13
caiphi
 
Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Dann lass ich den Revo deinstalliert. Danke für Deine kompetente Hilfe. Gute Arbeit!! ...und sehr nett!!
__________________
Gruß
Volker

Alt 01.05.2014, 01:09   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Standard

Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung
4d36e972-e325-11ce-bfc1-08002be10318, adware entfernen, adware.installbrain, browsefox, browserumleitung, device driver, eigenleben, focus, free download, optimizerpro, pup.optional.alexatb.a, pup.optional.awesomehp.a, pup.optional.conduit, pup.optional.conduit.a, pup.optional.crossrider.a, pup.optional.filescout.a, pup.optional.hqtotals.a, pup.optional.installcore.a, pup.optional.mediaenhance.a, pup.optional.mysearchdial.a, pup.optional.qone8, pup.optional.quickstart.a, pup.optional.regcleanerpro.a, pup.optional.savesense, pup.optional.savesense.a, pup.optional.savingsbull, pup.optional.savingsbull.a, pup.optional.snapdo, pup.optional.snapdo.a, pup.optional.valueapps.a, pup.optional.zulagames.a, pup.optional.zulugames, qone8, quickstart, subtab, teredo, vo package



Ähnliche Themen: Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung


  1. Windows 8.1: Startseite im Browser wird auf Yahoo umgeleitet, Webseiten blenden Werbung von Strong Signal ein
    Log-Analyse und Auswertung - 08.06.2015 (9)
  2. Firefox Startseite wird geändert und Avira Echtzeitscan findet laufend etwas
    Log-Analyse und Auswertung - 31.05.2015 (11)
  3. Browser wird auf Seiten mit Werbung umgeleitet
    Plagegeister aller Art und deren Bekämpfung - 03.01.2015 (15)
  4. Windows 8.1 : Webseiten werden im IE auf Werbung umgeleitet, es sei ein veralteter Browser erkannt, obwohl aktuell
    Mülltonne - 26.10.2014 (0)
  5. Windows 7: Internet Explorer startet automatisch Werbung/ Webseiten werden auf Werbung umgeleitet
    Log-Analyse und Auswertung - 27.07.2014 (7)
  6. Windows 7: Leerlauf Scan im BitDefender wird immer wieder ausgeschaltet und Browser Startseite "google" wird geändert
    Log-Analyse und Auswertung - 20.05.2014 (13)
  7. Windows 8 - Web Browser wird umgeleitet auf http://feed.helperbar.com/?publisher=YahooOC&dpid=YahooOC&co=DE&
    Log-Analyse und Auswertung - 09.05.2014 (7)
  8. Windows 7: Webseiten werden auf Werbung umgeleitet, veralteter Browser erkannt obwohl aktuell wie auch flashplayer, spybot search mit Virus
    Log-Analyse und Auswertung - 11.12.2013 (16)
  9. Internet Game, Passwort wird immer geändert
    Log-Analyse und Auswertung - 23.10.2013 (17)
  10. Windows 7: Startseite wird ständig geändert
    Log-Analyse und Auswertung - 14.10.2013 (2)
  11. Ständig aggressive Werbung und Pop-Ups
    Plagegeister aller Art und deren Bekämpfung - 30.09.2013 (9)
  12. Browser hat immer script akamaihd.net, Google Suche wird umgeleitet
    Plagegeister aller Art und deren Bekämpfung - 26.02.2013 (34)
  13. Google wird umgeleitet, Browser extrem langsam, Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 27.05.2012 (7)
  14. Browser öffnen willkürlich Tabs, Links werden geändert
    Plagegeister aller Art und deren Bekämpfung - 09.07.2010 (14)
  15. Dateikiller -Ein Zeichen wird geändert
    Plagegeister aller Art und deren Bekämpfung - 21.11.2008 (1)
  16. Browser stürzt ab und wird gelegentlich umgeleitet
    Log-Analyse und Auswertung - 23.09.2007 (4)

Zum Thema Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung - Der Windows 7 Rechner meiner Tochter ist Adware und anderer Malware verseucht. Beim Scan mit Malwarbytes wurde folgendes gefunden: mysearchdial, savingsbull, lizardlink, savesense, browsefox, valueapps, zulagames, crossrider, Qone8, awesomehlp, dealply, - Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung...
Archiv
Du betrachtest: Suchmaschineneinträge geändert, Browser wird umgeleitet auf aggressive Werbung auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.