![]() |
|
Plagegeister aller Art und deren Bekämpfung: exe Fehlermeldung bat=exe konnte nicht gefunden werdenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #5 |
| ![]() exe Fehlermeldung bat=exe konnte nicht gefunden werden zoek log hxxp://pastebin.com/1M0G6dtE Code:
ATTFilter <?xml version="1.0" encoding="UTF-16" ?> <mbam-log> <header> <date>2015/12/30 18:16:54 +0100</date> <logfile>mbam-log-2015-12-30 (18-16-42).xml</logfile> <isadmin>yes</isadmin> </header> <engine> <version>2.2.0.1024</version> <malware-database>v2015.12.30.04</malware-database> <rootkit-database>v2015.12.26.01</rootkit-database> <license>free</license> <file-protection>disabled</file-protection> <web-protection>disabled</web-protection> <self-protection>disabled</self-protection> </engine> <system> <hostname>ADMIN-PC</hostname> <ip>192.168.178.41</ip> <osversion>Windows 7 Service Pack 1</osversion> <arch>x64</arch> <username>papa</username> <filesys>NTFS</filesys> </system> <summary> <type>threat</type> <result>completed</result> <objects>447613</objects> <time>6818</time> <processes>0</processes> <modules>0</modules> <keys>77</keys> <values>61</values> <datas>2</datas> <folders>0</folders> <files>3</files> <sectors>0</sectors> </summary> <options> <memory>enabled</memory> <startup>enabled</startup> <filesystem>enabled</filesystem> <archives>enabled</archives> <rootkits>enabled</rootkits> <deeprootkit>disabled</deeprootkit> <heuristics>enabled</heuristics> <pup>enabled</pup> <pum>enabled</pum> </options> <items> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}</path><vendor>PUP.Optional.Babylon</vendor><action>success</action><hash>52eab4f7bccf9f97dcce50124fb3bd43</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}</path><vendor>PUP.Optional.QuickShare</vendor><action>success</action><hash>6ece713abdce6acc32521f49fb07c040</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}</path><vendor>PUP.Optional.QuickShare</vendor><action>success</action><hash>6ece713abdce6acc32521f49fb07c040</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{377E5D4D-77E5-476A-8716-7E70A9272DA0}</path><vendor>PUP.Optional.SearchResults</vendor><action>success</action><hash>a79579327813072f7188c99f679b837d</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{377E5D4D-77E5-476A-8716-7E70A9272DA0}</path><vendor>PUP.Optional.SearchResults</vendor><action>success</action><hash>a79579327813072f7188c99f679b837d</hash></key> <key><path>HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}</path><vendor>PUP.Optional.RocketFind</vendor><action>success</action><hash>fd3f0d9e117ae35337d28e3315eed42c</hash></key> <key><path>HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32LDR </path><vendor>PUP.Optional.Trovi</vendor><action>success</action><hash>6fcda00b57348aaca8c7c706da29f40c</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\FrEeSoFtOdAy</path><vendor>PUP.Optional.FreeSoftToday</vendor><action>success</action><hash>102c3279018a50e689c68028986b31cf</hash></key> <key><path>HKLM\SOFTWARE\WOW6432NODE\SwiftSearch_1.10.0.25</path><vendor>PUP.Optional.SwiftSearch</vendor><action>success</action><hash>5ae28922a8e3fa3cb4ea14b619ea4cb4</hash></key> <key><path>HKU\S-1-5-18\SOFTWARE\CinemaPlus-3.2cV17.08-nv-ie</path><vendor>PUP.Optional.CinemaPlus</vendor><action>success</action><hash>27156447cbc0d3635976316945bee41c</hash></key> <key><path>HKU\S-1-5-18\SOFTWARE\CinemaPlus-3.2cV18.08-nv-ie</path><vendor>PUP.Optional.CinemaPlus</vendor><action>success</action><hash>85b707a45b3072c4b817f5a514efb24e</hash></key> <key><path>HKU\S-1-5-18\SOFTWARE\iWebar-nv-ie</path><vendor>PUP.Optional.iWebar</vendor><action>success</action><hash>fd3f05a6f2999b9bb9aeac03d82b2dd3</hash></key> <key><path>HKU\S-1-5-18\SOFTWARE\Object Browser-nv-ie</path><vendor>PUP.Optional.ObjectBrowser</vendor><action>success</action><hash>f646aa01b9d21c1ab021487118eb58a8</hash></key> <key><path>HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\CinemaHd For Pro 2.4cV20.01</path><vendor>PUP.Optional.CinemaHDPro</vendor><action>success</action><hash>1c20fbb0a1eae94d1963d0ca5fa444bc</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\BabylonToolbar</path><vendor>PUP.Optional.BabylonToolBar</vendor><action>success</action><hash>33093675404b6bcb6a9f6d2824df758b</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\CinemaPlus-3.2cV17.08</path><vendor>PUP.Optional.CinemaPlus</vendor><action>success</action><hash>63d96d3e65260333f8d73e5c000335cb</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\CinemaPlus-3.2cV17.08-nv-ie</path><vendor>PUP.Optional.CinemaPlus</vendor><action>success</action><hash>92aa901b37548caa923d990157ac1ce4</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\CinemaPlus-3.2cV18.08-nv-ie</path><vendor>PUP.Optional.CinemaPlus</vendor><action>success</action><hash>6dcf8a212f5cbb7b606f2674d62dbe42</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\Com NotificationV09.08</path><vendor>PUP.Optional.ComNotification</vendor><action>success</action><hash>0636f1ba2e5d61d54b93c3d8c14205fb</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\delta LTD</path><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><hash>e25a5f4cccbfa492676b413226dd1de3</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\lollipop</path><vendor>PUP.Optional.CouponMarvel.AppFlsh</vendor><action>success</action><hash>2d0f5556ccbf73c3bee475997391e51b</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\Object Browser-nv-ie</path><vendor>PUP.Optional.ObjectBrowser</vendor><action>success</action><hash>fd3fa4072c5f3df9a62b6d4c778c37c9</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\RGMService</path><vendor>PUP.Optional.RGMUpdater</vendor><action>success</action><hash>16261794a9e2d6600acd12aee51eb14f</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\softonicToolbar</path><vendor>PUP.Optional.SofTonic</vendor><action>success</action><hash>b08c16958506ed49ee2abf08d42fc838</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\APPDATALOW\SOFTWARE\CinemaHd For Pro 2.4cV20.01</path><vendor>PUP.Optional.CinemaHDPro</vendor><action>success</action><hash>51eb88235c2fae88ff7defab23e08878</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\APPDATALOW\SOFTWARE\SmartWeb</path><vendor>PUP.Optional.SmartWeb</vendor><action>success</action><hash>e25a85260f7ca294f8c3b85c0cf828d8</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Com NotificationV09.08</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>bb811e8d0685072f0062c0e0bc475aa6</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\INSTALLPATH\STATUS</path><vendor>PUP.Optional.Komodia</vendor><action>success</action><hash>261648634e3d6bcb5a106cace32127d9</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15374A1B-3B4E-4006-BB66-1F637B46F82E}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>9aa2c3e8484341f58dd0247d23e037c9</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{17DDC48D-1A66-480C-9B8E-9B714F1935A6}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>1b216c3f9deedd59b8a49f020ff42ed2</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1970921A-D248-44AF-8C7F-D2664E6A2F25}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>3ffdc0eb5536db5b28357d24b64dcf31</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2356DA32-9FD2-4742-A25E-AC69784053A5}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>a7959c0faeddf6403f1d6c35e71c15eb</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{273EBC5E-64E6-476B-A22D-3D1428C74C30}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>97a5317a2a61c86e401d4e53e61d9769</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{286462C2-7BF3-41C1-88BF-2359D9E4A4DB}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>d5678f1cf39853e3401ceeb38281f40c</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2E10BB80-28B0-4D24-9F76-51FD204FF95E}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>201cfdae692240f63626a100dc2742be</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3C24C24E-9FD5-4A93-932B-B85DE180F0E8}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>97a51497c5c638fe322bc3de26dd2bd5</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3D895F01-7EDB-490C-B1FB-1B7F12766CF3}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>5ae292190f7c1e1833293f62c93ab749</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3EAAD757-71FA-4C15-A6FA-B73E46186145}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>b6861d8e3952bd79eb72574ad033bd43</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3F08E379-AFF7-4BBF-BDFA-B8937C47EB78}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>fd3f674432595bdbd984970a37cc9b65</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{519F6BB9-2DB4-42CE-A936-EFAFB19BA148}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>8cb0515a206bd4622537445d010218e8</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{52D59510-A29C-458C-9DBF-91C82466BB34}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>cb7105a6711a3ef8dd7fbee3887baa56</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57D4FBAF-6921-4963-9E54-A3E4B79A94D6}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>a09cbcefe8a33204213c1091e320758b</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5918A7A6-BC98-4C3A-867B-B38EE2A54FCC}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>8eaef4b73853d95dc399059c0af9c040</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{59D1C657-DC19-408A-A22F-AD14AC33996A}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>d963cae18ffcfd392d2ff4adbb488f71</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5EB24A3D-8004-47B1-A0DD-75319017EDEF}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>60dc5952dab1b4820e4f98091be811ef</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5ED854EF-23C4-4709-9291-F6F02478A182}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>e359416acbc0979f06572879e71c649c</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65B67FC0-8FFD-460B-B847-22208066E371}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>6bd1208b018a74c274e96a3721e2f50b</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E3C57D8-C17B-4B98-B089-7841E26D4DD8}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>dc60ecbf0487ff37a6b609987d8640c0</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{716EC7D7-BCCF-40AF-9946-C970212031D3}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>b9836a41533870c6d984aff206fd8d73</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{890154E3-3D21-454A-B4E2-58A6667E2974}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>fa42bfec9cefa393ce8eb3ee5aa98080</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F3336AD-795F-45BE-8523-D55A3815CBC2}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>4def15968ffce65034281e8355ae4db3</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92503C69-6683-4FEE-9A78-A0B03F718168}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>4af25952246755e1bf9d9c059d664fb1</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{94730CF4-BB07-4B5E-8813-494CB8E3ED3E}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>241803a8b0db211588d4efb204fff60a</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{94FAFE00-FBEA-492E-926E-E632DF93372E}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>a09c25865437e3531c41574ac53ed030</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9B877891-4AC5-45D8-9666-C46EF76E4593}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>6ece3c6f216ae45278e591103bc8728e</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A760C101-A907-460E-8FE8-77D04D65517E}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>6ad204a7cac1c86ebe9fd6cbc1422fd1</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A841DCA9-21C1-45C9-B7BC-D1AC14FA936C}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>f8446f3cd1ba91a5223b7f2239ca0ff1</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BD58425E-C098-42EB-9C44-3162FAFBCD92}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>e359e7c46d1e06307edf653cb053af51</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BF08E7F1-B6A4-4392-A21B-3F5EBE41B1BA}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>281405a64c3fbf7780dc307100035da3</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BF7DBB0D-E0DB-4224-9734-A542E52168EE}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>fb4118933457c175fb627928788ba15f</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3AD4456-5075-449F-AC1A-97FF71E8FEED}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>56e69912f19ab2845ffe980917ecfd03</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CFF8A748-9650-42C1-8F50-D227AA485483}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>0933d3d81873b97d025beeb331d27f81</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D3654625-D67F-4BED-BE97-A658ED5719A9}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>59e300ab127948ee2835f5ac2ad9817f</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D71D726A-25D4-413C-9D1F-33F94687B4A1}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>c07c109b77148fa747150f925ba81ce4</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D75FC188-CC7A-4680-8DF5-413670488D9D}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>06364962c5c6d165cb91e0c117ec9f61</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DA4495F9-532B-4CC6-BCD2-CA481A266EBC}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>dc608328098257dfed6fe3be7f84c739</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E5029C25-86EE-49B4-90C0-B09F985FEA54}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>b884c7e46e1d340281dca3fef60daf51</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7B57839-263A-4CB0-BA7C-BCC8296D8EE1}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>06361e8d5e2d8aac4617fba64db6a65a</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E93F98BE-D8A3-4AB7-A8AA-7EA31811C852}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>221ab7f4d8b3ff37e479aff2669dfe02</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EE2AFC1E-9DF1-4E94-AB39-97AA3247FE18}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>043806a5d4b7d6603a23901139ca8779</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F3FB491E-110B-4095-BBB3-6CF9FF9DD074}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>6bd1b9f2e9a24cea6fedd5ccd62df907</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB915A4A-E522-4C92-8956-E14B556A47B9}</path><vendor>PUP.Optional.CrossRider</vendor><action>success</action><hash>62da3e6d682337ff3824e2bf14ef15eb</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{334F2199-F4CB-4812-9288-DF31321AAE39}</path><vendor>PUP.Optional.SofTonic</vendor><action>success</action><hash>c07cf6b5c6c56accd43fc8ff2ed5dd23</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}</path><vendor>PUP.Optional.SearchResults</vendor><action>success</action><hash>390302a9434835015337f9ca9b68f20e</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MOZILLA\EXTENDS</path><vendor>PUP.Optional.DeskCut</vendor><action>success</action><hash>c874dad1acdf47ef9641adf54eb5e61a</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\PDFCONVERT</path><vendor>Trojan.Vonteera</vendor><action>success</action><hash>a597b9f25437c076a8877e954db7956b</hash></key> <key><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1003\SOFTWARE\INSTALLPATH\STATUS</path><vendor>PUP.Optional.Vitruvian</vendor><action>success</action><hash>8cb007a487042b0b0a70e731bf4543bd</hash></key> <value><path>HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}</path><valuename>URL</valuename><vendor>PUP.Optional.RocketFind</vendor><action>success</action><valuedata>hxxp://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_cmi_14_27_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtAzz0BtCyC0CyE0AtBtB0CtC0FtN0D0Tzu0SzytCyBtN1L2XzutBtFtBtCtFtCtCtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StBtAzy0AyDyByD0BtG0B0B0DyDtG0BtC0A0CtGyE0AtB0BtGtAtAtCtAyE0A0BtC0AyC0D0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0Azyzy0CzyyDyBtGyB0FtB0CtGyB0C0DtBtGyC0CtAzztGyCtCyDtAtByDyD0D0Czy0BtD2Q&cr=1199192875&ir=</valuedata><hash>fd3f0d9e117ae35337d28e3315eed42c</hash></value> <value><path>HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}</path><valuename>TopResultURLFallback</valuename><vendor>PUP.Optional.RocketFind</vendor><action>success</action><valuedata>hxxp://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_cmi_14_27_ie&cd=2XzuyEtN2Y1L1QzutDtDtBtAzz0BtCyC0CyE0AtBtB0CtC0FtN0D0Tzu0SzytCyBtN1L2XzutBtFtBtCtFtCtCtFtBtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StBtAzy0AyDyByD0BtG0B0B0DyDtG0BtC0A0CtGyE0AtB0BtGtAtAtCtAyE0A0BtC0AyC0D0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyB0Azyzy0CzyyDyBtGyB0FtB0CtGyB0C0DtBtGyC0CtAzztGyCtCyDtAtByDyD0D0Czy0BtD2Q&cr=1199192875&ir=</valuedata><hash>0537911a6d1ecb6b7198ac15689b08f8</hash></value> <value><path>HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\VC32Ldr </path><valuename>{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb</valuename><vendor>PUP.Optional.Trovi</vendor><action>success</action><valuedata>130662481488282232</valuedata><hash>6fcda00b57348aaca8c7c706da29f40c</hash></value> <value><path>HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SHAREDACCESS\PARAMETERS\FIREWALLPOLICY\FIREWALLRULES</path><valuename>{1CA9795D-8423-465C-919C-87918ED465B1}</valuename><vendor>PUP.Optional.MaxDriverUpdater</vendor><action>success</action><valuedata>v2.10|Action=Allow|Active=TRUE|Dir=In|App=C:\Program Files (x86)\Max Driver Updater\maxdu.exe|Name=MaxDriverUpdater|</valuedata><hash>fd3fa308d9b2eb4bac3e75974db7a35d</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\INSTALLPATH\STATUS</path><valuename>FlowsurfCB</valuename><vendor>PUP.Optional.Komodia</vendor><action>success</action><valuedata>Y</valuedata><hash>261648634e3d6bcb5a106cace32127d9</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{15374A1B-3B4E-4006-BB66-1F637B46F82E}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>9aa2c3e8484341f58dd0247d23e037c9</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{17DDC48D-1A66-480C-9B8E-9B714F1935A6}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>1b216c3f9deedd59b8a49f020ff42ed2</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{1970921A-D248-44AF-8C7F-D2664E6A2F25}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>3ffdc0eb5536db5b28357d24b64dcf31</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2356DA32-9FD2-4742-A25E-AC69784053A5}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>a7959c0faeddf6403f1d6c35e71c15eb</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{273EBC5E-64E6-476B-A22D-3D1428C74C30}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>97a5317a2a61c86e401d4e53e61d9769</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{286462C2-7BF3-41C1-88BF-2359D9E4A4DB}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>d5678f1cf39853e3401ceeb38281f40c</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{2E10BB80-28B0-4D24-9F76-51FD204FF95E}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>201cfdae692240f63626a100dc2742be</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3C24C24E-9FD5-4A93-932B-B85DE180F0E8}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>97a51497c5c638fe322bc3de26dd2bd5</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3D895F01-7EDB-490C-B1FB-1B7F12766CF3}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>5ae292190f7c1e1833293f62c93ab749</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3EAAD757-71FA-4C15-A6FA-B73E46186145}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>b6861d8e3952bd79eb72574ad033bd43</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3F08E379-AFF7-4BBF-BDFA-B8937C47EB78}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>fd3f674432595bdbd984970a37cc9b65</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{519F6BB9-2DB4-42CE-A936-EFAFB19BA148}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>8cb0515a206bd4622537445d010218e8</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{52D59510-A29C-458C-9DBF-91C82466BB34}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>cb7105a6711a3ef8dd7fbee3887baa56</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{57D4FBAF-6921-4963-9E54-A3E4B79A94D6}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>a09cbcefe8a33204213c1091e320758b</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5918A7A6-BC98-4C3A-867B-B38EE2A54FCC}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>8eaef4b73853d95dc399059c0af9c040</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{59D1C657-DC19-408A-A22F-AD14AC33996A}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>d963cae18ffcfd392d2ff4adbb488f71</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5EB24A3D-8004-47B1-A0DD-75319017EDEF}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>60dc5952dab1b4820e4f98091be811ef</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5ED854EF-23C4-4709-9291-F6F02478A182}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>e359416acbc0979f06572879e71c649c</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{65B67FC0-8FFD-460B-B847-22208066E371}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>6bd1208b018a74c274e96a3721e2f50b</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6E3C57D8-C17B-4B98-B089-7841E26D4DD8}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>dc60ecbf0487ff37a6b609987d8640c0</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{716EC7D7-BCCF-40AF-9946-C970212031D3}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>b9836a41533870c6d984aff206fd8d73</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{890154E3-3D21-454A-B4E2-58A6667E2974}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>fa42bfec9cefa393ce8eb3ee5aa98080</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8F3336AD-795F-45BE-8523-D55A3815CBC2}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>4def15968ffce65034281e8355ae4db3</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{92503C69-6683-4FEE-9A78-A0B03F718168}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>4af25952246755e1bf9d9c059d664fb1</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{94730CF4-BB07-4B5E-8813-494CB8E3ED3E}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>241803a8b0db211588d4efb204fff60a</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{94FAFE00-FBEA-492E-926E-E632DF93372E}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>a09c25865437e3531c41574ac53ed030</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{9B877891-4AC5-45D8-9666-C46EF76E4593}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>6ece3c6f216ae45278e591103bc8728e</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A760C101-A907-460E-8FE8-77D04D65517E}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>6ad204a7cac1c86ebe9fd6cbc1422fd1</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A841DCA9-21C1-45C9-B7BC-D1AC14FA936C}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>f8446f3cd1ba91a5223b7f2239ca0ff1</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BD58425E-C098-42EB-9C44-3162FAFBCD92}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>e359e7c46d1e06307edf653cb053af51</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BF08E7F1-B6A4-4392-A21B-3F5EBE41B1BA}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>281405a64c3fbf7780dc307100035da3</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{BF7DBB0D-E0DB-4224-9734-A542E52168EE}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>fb4118933457c175fb627928788ba15f</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C3AD4456-5075-449F-AC1A-97FF71E8FEED}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>56e69912f19ab2845ffe980917ecfd03</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CFF8A748-9650-42C1-8F50-D227AA485483}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>0933d3d81873b97d025beeb331d27f81</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D3654625-D67F-4BED-BE97-A658ED5719A9}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>59e300ab127948ee2835f5ac2ad9817f</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D71D726A-25D4-413C-9D1F-33F94687B4A1}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>c07c109b77148fa747150f925ba81ce4</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D75FC188-CC7A-4680-8DF5-413670488D9D}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>06364962c5c6d165cb91e0c117ec9f61</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{DA4495F9-532B-4CC6-BCD2-CA481A266EBC}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>dc608328098257dfed6fe3be7f84c739</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E5029C25-86EE-49B4-90C0-B09F985FEA54}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>b884c7e46e1d340281dca3fef60daf51</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E7B57839-263A-4CB0-BA7C-BCC8296D8EE1}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>06361e8d5e2d8aac4617fba64db6a65a</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E93F98BE-D8A3-4AB7-A8AA-7EA31811C852}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>221ab7f4d8b3ff37e479aff2669dfe02</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{EE2AFC1E-9DF1-4E94-AB39-97AA3247FE18}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-codedownloader.exe</valuedata><hash>043806a5d4b7d6603a23901139ca8779</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F3FB491E-110B-4095-BBB3-6CF9FF9DD074}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>6bd1b9f2e9a24cea6fedd5ccd62df907</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{FB915A4A-E522-4C92-8956-E14B556A47B9}</path><valuename>AppName</valuename><vendor>PUP.Optional.CrossRider</vendor><action>success</action><valuedata>a16f6bc1-875d-4ba4-8e10-93ccf48c93bc-2.exe-buttonutil.exe</valuedata><hash>62da3e6d682337ff3824e2bf14ef15eb</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION</path><valuename>wb.exe</valuename><vendor>PUP.Optional.WebBar</vendor><action>success</action><valuedata>11000</valuedata><hash>75c7d2d9711a1e18eee2090ce222b749</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}</path><valuename>URL</valuename><vendor>PUP.Optional.Delta.ShrtCln</vendor><action>success</action><valuedata>hxxp://www.delta-search.com/?q={searchTerms}&affID=119556&tt=120912_nocpc_3712_7&babsrc=SP_ss&mntrId=3a882c1f00000000000000238b16c4a2</valuedata><hash>231925861b700036ee9220681ae95ea2</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}</path><valuename>FaviconURL</valuename><vendor>PUP.Optional.Babylon</vendor><action>success</action><valuedata>search.babylon.com/favicon.ico</valuedata><hash>ec500c9f90fb2115956cbadb14efa858</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{334F2199-F4CB-4812-9288-DF31321AAE39}</path><valuename>URL</valuename><vendor>PUP.Optional.SofTonic</vendor><action>success</action><valuedata>hxxp://search.softonic.com/MOY00009/tb_v1?q={searchTerms}&SearchSource=4&cc=&r=51</valuedata><hash>c07cf6b5c6c56accd43fc8ff2ed5dd23</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{334F2199-F4CB-4812-9288-DF31321AAE39}</path><valuename>FaviconURL</valuename><vendor>PUP.Optional.SofTonic</vendor><action>success</action><valuedata>hxxp://search.softonic.com/favicon.ico</valuedata><hash>60dc9516f893e254848fd5f22cd7669a</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}</path><valuename>URL</valuename><vendor>PUP.Optional.SearchResults</vendor><action>success</action><valuedata>hxxp://dts.search-results.com/sr?src=ieb&gct=ds&appid=287&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=1808332700114030&q={searchTerms}</valuedata><hash>390302a9434835015337f9ca9b68f20e</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}</path><valuename>SuggestionsURL_JSON</valuename><vendor>PUP.Optional.SearchQu</vendor><action>success</action><valuedata>hxxp://www.searchqu.com/suggest.php?src=ieb&gct=ds&appid=287&systemid=406&apn_dtid=BND406&apn_ptnrs=AG6&o=APN10645&apn_uid=1808332700114030&qu={searchTerms}&ft=json</valuedata><hash>c775adfebad11125b2d3d1f27b88db25</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\MOZILLA\EXTENDS</path><valuename>appid</valuename><vendor>PUP.Optional.DeskCut</vendor><action>success</action><valuedata>deskCutv2@gmail.com</valuedata><hash>c874dad1acdf47ef9641adf54eb5e61a</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1000\SOFTWARE\PDFCONVERT</path><valuename>Uniq</valuename><vendor>Trojan.Vonteera</vendor><action>success</action><valuedata>{4845791F-74AC-4E94-B98A-11F56E5E735D}</valuedata><hash>a597b9f25437c076a8877e954db7956b</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1003\SOFTWARE\INSTALLPATH\STATUS</path><valuename>SwiftSearch</valuename><vendor>PUP.Optional.Vitruvian</vendor><action>success</action><valuedata>I</valuedata><hash>8cb007a487042b0b0a70e731bf4543bd</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1003\SOFTWARE\INSTALLPATH\STATUS</path><valuename>Groover</valuename><vendor>PUP.Optional.VBates</vendor><action>success</action><valuedata>N</valuedata><hash>300ca30884072d09a2d7041431d359a7</hash></value> <value><path>HKU\S-1-5-21-3133311992-1068475802-2353603175-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION</path><valuename>wb.exe</valuename><vendor>PUP.Optional.WebBar</vendor><action>success</action><valuedata>11000</valuedata><hash>0537387325665dd95977e72efa0a7d83</hash></value> <data><path>HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES</path><valuename>DefaultScope</valuename><vendor>PUP.Optional.Qone8</vendor><action>replaced</action><valuedata>{33BB0A4E-99AF-4226-BDF6-49120163DE86}</valuedata><baddata>{33BB0A4E-99AF-4226-BDF6-49120163DE86}</baddata><gooddata>{0633EE93-D776-472f-A0FF-E1416B8B2E3A}</gooddata><hash>300cbfec197250e68d15ff98ed17dc24</hash></data> <data><path>HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES</path><valuename>DefaultScope</valuename><vendor>PUP.Optional.Qone8</vendor><action>replaced</action><valuedata>{33BB0A4E-99AF-4226-BDF6-49120163DE86}</valuedata><baddata>{33BB0A4E-99AF-4226-BDF6-49120163DE86}</baddata><gooddata>{0633EE93-D776-472f-A0FF-E1416B8B2E3A}</gooddata><hash>78c476350f7cc76fc6dc3f58f80ce818</hash></data> <file><path>C:\Windows\Installer\580a7.msi</path><vendor>PUP.Optional.SnapDo</vendor><action>success</action><hash>102cf7b47318f640dd5564d068998d73</hash></file> <file><path>C:\Windows\Installer\580ac.msi</path><vendor>PUP.Optional.VeriStaff</vendor><action>success</action><hash>0a32d2d9d6b58bab4d76d4436e927b85</hash></file> <file><path>C:\Windows\System32\sei\pew\uvubb.dat</path><vendor>PUP.Optional.HijackHosts.Gen</vendor><action>success</action><hash>ed4f58533b501224da35e6db1aea8080</hash></file> </items> </mbam-log> Code:
ATTFilter <?xml version="1.0" encoding="UTF-8" ?> <logs> <record severity="debug" LoggingEventType="1" datetime="2015-12-30T18:16:25.191645+01:00" source="Manual" type="Update" username="SYSTEM" systemname="ADMIN-PC" fromVersion="2015.9.16.1" last_modified_tag="398539a2-f9b9-434e-b98e-f3c5b253bd45" name="Remediation Database" toVersion="2015.12.15.2"></record> <record severity="debug" LoggingEventType="1" datetime="2015-12-30T18:16:25.258647+01:00" source="Manual" type="Update" username="SYSTEM" systemname="ADMIN-PC" fromVersion="2015.9.18.1" last_modified_tag="f55b36a8-d3ba-4e45-b505-23d745104ba2" name="Rootkit Database" toVersion="2015.12.26.1"></record> <record severity="debug" LoggingEventType="1" datetime="2015-12-30T18:16:25.373650+01:00" source="Manual" type="Update" username="SYSTEM" systemname="ADMIN-PC" fromVersion="2015.9.22.3" last_modified_tag="0a85d34a-d9d1-45c5-a01a-8bf4434df521" name="Domain Database" toVersion="2015.12.30.5"></record> <record severity="debug" LoggingEventType="1" datetime="2015-12-30T18:16:25.478653+01:00" source="Manual" type="Update" username="SYSTEM" systemname="ADMIN-PC" fromVersion="2015.9.21.2" last_modified_tag="7db91fea-08bc-4688-aa98-cf295af50420" name="IP Database" toVersion="2015.12.25.1"></record> <record severity="debug" LoggingEventType="1" datetime="2015-12-30T18:16:53.863496+01:00" source="Manual" type="Update" username="SYSTEM" systemname="ADMIN-PC" fromVersion="2015.9.22.5" last_modified_tag="eba145e2-3faa-441d-80a9-c8776dc06b72" name="Malware Database" toVersion="2015.12.30.4"></record> <record severity="debug" scantype="threat" LoggingEventType="6" starttime="2015-12-30T18:16:54+01:00" datetime="2015-12-30T20:47:37.620088+01:00" source="Manual" type="Scan" username="SYSTEM" systemname="ADMIN-PC" last_modified_tag="32e3fc64-8ce1-4fce-93a5-7cdd633d3bab" duration="6818" malwaredetections="2" nonmalwaredetections="141" scanresult="completed"></record> <record severity="debug" LoggingEventType="4" datetime="2015-12-30T20:51:10.511491+01:00" source="Protection" type="Error" username="SYSTEM" systemname="ADMIN-PC" code="13" last_modified_tag="33dc6c0b-4370-416b-a35c-bfa5aa56dba2" message="IsLicensed"></record> <record severity="debug" LoggingEventType="2" datetime="2015-12-30T20:51:10.527091+01:00" source="Protection" type="Protection" username="SYSTEM" systemname="ADMIN-PC" last_modified_tag="fb177374-7d69-49e8-9948-df2e0035a054" result="Stopping" subtype="Malware Protection"></record> <record severity="debug" LoggingEventType="2" datetime="2015-12-30T20:51:10.527091+01:00" source="Protection" type="Protection" username="SYSTEM" systemname="ADMIN-PC" last_modified_tag="dab55378-a9d5-4f31-80cd-0fc22ca2362d" result="Stopped" subtype="Malware Protection"></record> </logs> |
Themen zu exe Fehlermeldung bat=exe konnte nicht gefunden werden |
administrator, adobe flash player, antivirus, avira, bonjour, ccsetup, chromium, defender, desktop, dnsapi.dll, dringend, exe, explorer, fehlermeldung, flash player, google, install.exe, installmanager.exe, mozilla, opera, ordner, prozesse, registry, scan, secur, software, svchost.exe, system, teredo, winlogon.exe, öffnet |