| 
 Und weiter gehts: 
GMER:   Code: 
 GMER 2.1.19357 - hxxp://www.gmer.netRootkit scan 2014-03-27 18:27:01
 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD10EARS-00Y5B1 rev.80.00A80 931,51GB
 Running: Gmer-19357.exe; Driver: C:\Users\Barbara\AppData\Local\Temp\uxtiyfob.sys
 
 
 ---- Kernel code sections - GMER 2.1 ----
 
 INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                                                        fffff800035f8000 16 bytes [8B, E3, 41, 5F, 41, 5E, 41, ...]
 INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 545                                                                                        fffff800035f8011 35 bytes {LEA ECX, [RSP+0x70]; CALL 0x3d64f}
 
 ---- User code sections - GMER 2.1 ----
 
 .text     C:\Windows\system32\wininit.exe[644] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\services.exe[704] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\winlogon.exe[796] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[888] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[988] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\atiesrxx.exe[140] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Windows\System32\svchost.exe[392] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007718eecd 1 byte [62]
 .text     C:\Windows\System32\svchost.exe[468] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[600] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[656] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[1180] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Program Files\AVAST Software\Avast\afwServ.exe[1496] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                             000000007521a2ba 1 byte [62]
 .text     C:\Windows\System32\spoolsv.exe[1868] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[1896] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe[2008] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112              000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[2020] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                  000000007521a2ba 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[1204] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[2044] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112  000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\AM\dtsslsrv.exe[2076] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                 000000007521a2ba 1 byte [62]
 .text     C:\DeltaCopy\DCServce.exe[2188] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                                     000000007521a2ba 1 byte [62]
 .text     C:\DeltaCopy\rsync.exe[2236] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                                        000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe[2260] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                       000000007521a2ba 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[2288] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Program Files\Lupinho.Net\HardlinkBackup\HardlinkBackup.Service.exe[2404] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                        000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\taskhost.exe[2544] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                              000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\inetsrv\inetinfo.exe[2920] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                      000000007718eecd 1 byte [62]
 .text     C:\Windows\Explorer.EXE[3000] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                                       000000007718eecd 1 byte [62]
 .text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2684] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                            000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2684] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                          0000000076cf1465 2 bytes [CF, 76]
 .text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe[2684] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                         0000000076cf14bb 2 bytes [CF, 76]
 .text     ...                                                                                                                                                       * 2
 .text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe[2812] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                              000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe[3096] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                     000000007521a2ba 1 byte [62]
 .text     C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3384] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                               000000007718eecd 1 byte [62]
 .text     C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe[3464] C:\Windows\syswow64\KERNEL32.dll!GetBinaryTypeW + 112           000000007521a2ba 1 byte [62]
 .text     C:\Program Files\Windows Sidebar\sidebar.exe[3492] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                  000000007718eecd 1 byte [62]
 .text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3620] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                     000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                   0000000076cf1465 2 bytes [CF, 76]
 .text     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe[3620] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                  0000000076cf14bb 2 bytes [CF, 76]
 .text     ...                                                                                                                                                       * 2
 .text     C:\Program Files\Lupinho.Net\HardlinkBackup\HardlinkBackupTray.exe[3628] C:\Windows\system32\KERNEL32.dll!GetBinaryTypeW + 189                            000000007718eecd 1 byte [62]
 .text     C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe[3676] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                          000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe[3796] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                              000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe[3796] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                            0000000076cf1465 2 bytes [CF, 76]
 .text     C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe[3796] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                           0000000076cf14bb 2 bytes [CF, 76]
 .text     ...                                                                                                                                                       * 2
 .text     C:\Program Files (x86)\Datacolor\Spyder3Elite\Utility\Spyder3Utility.exe[3844] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                      000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe[3948] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                    000000007521a2ba 1 byte [62]
 .text     C:\Program Files\AVAST Software\Avast\avastui.exe[3236] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                             000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[4040] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                              000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\iTunes\iTunesHelper.exe[3176] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Brother\Brmfcmon\BrMfimon.exe[3296] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                          000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe[4516] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                 000000007521a2ba 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[4608] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[4908] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe[4984] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                000000007521a2ba 1 byte [62]
 ?         C:\Windows\system32\mssprxy.dll [4984] entry point in ".rdata" section                                                                                    00000000622e71e6
 .text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5504] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112        000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69      0000000076cf1465 2 bytes [CF, 76]
 .text     C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE[5504] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155     0000000076cf14bb 2 bytes [CF, 76]
 .text     ...                                                                                                                                                       * 2
 .text     C:\Windows\system32\SearchIndexer.exe[5264] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                         000000007718eecd 1 byte [62]
 .text     C:\Program Files\iPod\bin\iPodService.exe[6096] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                     000000007718eecd 1 byte [62]
 .text     C:\Windows\system32\svchost.exe[6728] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Program Files\Windows Media Player\wmpnetwk.exe[6528] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189                                            000000007718eecd 1 byte [62]
 .text     C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe[1392] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112             000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe[3264] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                000000007521a2ba 1 byte [62]
 .text     C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5184] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                000000007521a2ba 1 byte [62]
 .text     C:\Windows\system32\AUDIODG.EXE[6164] C:\Windows\System32\kernel32.dll!GetBinaryTypeW + 189                                                               000000007718eecd 1 byte [62]
 .text     C:\Users\proworx\Desktop\Gmer-19357.exe[4092] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112                                                       000000007521a2ba 1 byte [62]
 
 ---- Threads - GMER 2.1 ----
 
 Thread    C:\Windows\System32\svchost.exe [6028:3348]                                                                                                               000007fee4a49688
 
 ---- EOF - GMER 2.1 ----
 Malwarebytes:   Code: 
 Malwarebytes Anti-Malwarewww.malwarebytes.org
 
 Scan Date: 26.03.2014
 Scan Time: 00:42:50
 Logfile: Malwarebytes_log.txt
 Administrator: Yes
 
 Version: 2.00.0.1000
 Malware Database: v2014.03.25.09
 Rootkit Database: v2014.03.18.01
 License: Trial
 Malware Protection: Enabled
 Malicious Website Protection: Enabled
 Chameleon: Disabled
 
 OS: Windows 7 Service Pack 1
 CPU: x64
 File System: NTFS
 User: Barbara
 
 Scan Type: Threat Scan
 Result: Completed
 Objects Scanned: 473223
 Time Elapsed: 26 min, 43 sec
 
 Memory: Enabled
 Startup: Enabled
 Filesystem: Enabled
 Archives: Enabled
 Rootkits: Disabled
 Shuriken: Enabled
 PUP: Enabled
 PUM: Enabled
 
 Processes: 0
 (No malicious items detected)
 
 Modules: 0
 (No malicious items detected)
 
 Registry Keys: 1
 PUP.Optional.SnapDo.A, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, Quarantined, [a9d458af7ffc24127cf76ef3a260ab55],
 
 Registry Values: 1
 PUP.Optional.SnapDo.A, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, SnapdoOCYB, Quarantined, [a9d458af7ffc24127cf76ef3a260ab55]
 
 Registry Data: 9
 PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[4c31ed1a3744c274eba78182709418e8]
 PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[a5d8798e83f8c373830e50b3788c8977]
 PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[f28b16f1750604322470e122c4406e92]
 PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[592416f1126977bf266f847f040044bc]
 PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[314c996e6c0fdf572b6790733fc51be5]
 PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013),Replaced,[e39abe49fe7d12242370fb08a95b857b]
 PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[e994df28166571c59ff207fc8a7ac53b]
 PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[57263acd4d2e082e1a7a08fbd92b52ae]
 PUP.Optional.Snapdo, HKU\S-1-5-21-768405528-1706932147-445367486-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013, Good: (hxxp://www.google.com), Bad: (hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013),Replaced,[afce7790502b83b3dbba0003c63e629e]
 
 Folders: 19
 PUP.Optional.OpenCandy, C:\Users\Barbara\AppData\Roaming\OpenCandy, Quarantined, [631a42c5f88395a19d806ede09f9639d],
 PUP.Optional.OpenCandy, C:\Users\Barbara\AppData\Roaming\OpenCandy\B4C79BD4279644F4A0111551124D3A10, Quarantined, [631a42c5f88395a19d806ede09f9639d],
 PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
 PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
 PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\FE30E2B520264DF8B6D59FEB193B05D1, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
 PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\CSS, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales\en, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales\es, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 
 Files: 96
 PUP.Optional.Linkury.A, C:\Users\Barbara\AppData\Roaming\OpenCandy\B4C79BD4279644F4A0111551124D3A10\Installer.exe, Quarantined, [6914c2453f3c6acc80a41cbebd46f10f],
 PUP.Optional.OpenCandy, C:\Users\proworx\Downloads\FreeFileSync_5.8_setup.exe, Quarantined, [681552b57605f244f62759ceb84c5ba5],
 PUP.Optional.WebSearch.A, C:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\ao5y6bz5.default\searchplugins\Web Search.xml, Quarantined, [6a134abdea91b086c77284d325ddd030],
 PUP.Optional.WebSearch.A, C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\aaqcgp11.default\searchplugins\Web Search.xml, Quarantined, [7c01ea1d8eed3df9a2978bcc877b847c],
 PUP.Optional.WebSearch.A, C:\Users\Konstantin\AppData\Roaming\Mozilla\Firefox\Profiles\65yiqvla.default\searchplugins\Web Search.xml, Quarantined, [4f2ebf48a1da7bbbc9707cdb52b0619f],
 PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A\3975.ico, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
 PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A\EBB77268-338F-4C6A-8590-AD88FED26F4A, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
 PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A\OCBrowserHelper_1.0.3.85.dll, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
 PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\F134FC2B51F8487E8BCEF1962409489A\setup_759.exe, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
 PUP.Optional.OpenCandy, C:\Users\proworx\AppData\Roaming\OpenCandy\FE30E2B520264DF8B6D59FEB193B05D1\TuneUpUtilities2013_2200213_de-DE.exe, Quarantined, [bebf6e991f5c3600ff1eae9e4bb732ce],
 PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\chLogic.exe, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
 PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\CT3244149.txt, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
 PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\dtime.csf, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
 PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\initData.json, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
 PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\manifest.json, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
 PUP.Optional.Conduit.A, C:\Users\proworx\AppData\Local\Temp\ct3244149\statisticsStub.exe, Quarantined, [ed903acd077458de0a8b95b7c63c08f8],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\bg.html, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\bg.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\GoogleChromeRemotePlugin.dll, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\manifest.json, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\options.htm, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\options.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\popup.html, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\popup.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\redirect.html, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\redirect.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\CSS\border.css, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\down.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\fb.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\fblike.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\gmail.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\google.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\googleplus.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\hide-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\left.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\maximize-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\mgsplusvideo.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\minimize-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\pinit.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\right.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\searchBox.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\show-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\twitter.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-1.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-2.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up-3.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\images\up.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\BackPageRemove.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\defaultBlockList.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\documentEvents.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\externalJS.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\FBImagePreview.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\InternalJS.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\jquery-1.9.0.min.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\PluginWrapper.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\publisherDefinitions.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\tabReload.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\JS\TopFrameJS.js, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\homePage.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\SnapDo.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\SnapDo128.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\SnapDo16.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\amfclgbdpgndipgoegfpkkgobahigbcl\1.4_0\PublisherImages\SnapDo48.png, Quarantined, [136ae126f685a98d0866ec63f11133cd],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\manifest.json, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\ajax.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\background.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\common.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\content.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\notifier.js, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\notify.css, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\back.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\bitty.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\close.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\logo-sm.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\tinyurl\images\logo.png, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales\en\messages.json, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.SnapDo.A, C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\eehfnepnmclpcobedfhlofbalebekkaj\1.4_0\_locales\es\messages.json, Quarantined, [c2bbde29c5b60e2850f97cd442c0837d],
 PUP.Optional.Snapdo.A, C:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\ao5y6bz5.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013");), Replaced,[59240403eb9081b5706c59d454b022de]
 PUP.Optional.Snapdo.A, C:\Users\Jakob\AppData\Roaming\Mozilla\Firefox\Profiles\ao5y6bz5.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&installDate=27/12/2013&q=");), Replaced,[720b92754338bf778755a08d1ce8d729]
 PUP.Optional.Snapdo.A, C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\aaqcgp11.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013");), Replaced,[88f5d334651688aea53756d722e2ed13]
 PUP.Optional.Snapdo.A, C:\Users\Judith\AppData\Roaming\Mozilla\Firefox\Profiles\aaqcgp11.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&installDate=27/12/2013&q=");), Replaced,[3746b750304b42f42ab2d459fa0ad32d]
 PUP.Optional.Snapdo.A, C:\Users\Konstantin\AppData\Roaming\Mozilla\Firefox\Profiles\65yiqvla.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=hp&installDate=27/12/2013");), Replaced,[7b0250b73447a294716b0924f11343bd]
 PUP.Optional.Snapdo.A, C:\Users\Konstantin\AppData\Roaming\Mozilla\Firefox\Profiles\65yiqvla.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&installDate=27/12/2013&q=");), Replaced,[dca1b255e19ada5cf9e3959861a302fe]
 PUP.Optional.Snapdo.A, C:\Users\proworx\AppData\Roaming\Mozilla\Firefox\Profiles\vsts9pc7.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=nt&installDate=27/12/2013");), Replaced,[671638cfbcbf95a1528a51dca26220e0]
 PUP.Optional.Snapdo.A, C:\Users\proworx\AppData\Roaming\Mozilla\Firefox\Profiles\vsts9pc7.default\prefs.js, Good: (), Bad: (user_pref("keyword.URL", "hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&installDate=27/12/2013&q=");), Replaced,[3d4032d58bf0ed499745220b39cbff01]
 
 Physical Sectors: 0
 (No malicious items detected)
 
 
 (end)
 AdwCleaner 1.Mal:   Code: 
 # AdwCleaner v3.022 - Bericht erstellt am 26/03/2014 um 12:43:08# Aktualisiert 13/03/2014 von Xplode
 # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
 # Benutzername : Barbara - PROWORX-PC
 # Gestartet von : C:\Users\Barbara\Downloads\adwcleaner.exe
 # Option : Löschen
 
 ***** [ Dienste ] *****
 
 
 ***** [ Dateien / Ordner ] *****
 
 Ordner Gelöscht : C:\Program Files (x86)\FreeRIP
 Ordner Gelöscht : C:\Program Files (x86)\software4u
 Ordner Gelöscht : C:\Users\proworx\AppData\Local\apn
 Ordner Gelöscht : C:\Users\proworx\AppData\Local\PackageAware
 Ordner Gelöscht : C:\Users\proworx\AppData\Local\Temp\AskSearch
 Ordner Gelöscht : C:\Users\proworx\AppData\Local\Temp\boost_interprocess
 Ordner Gelöscht : C:\Users\proworx\AppData\LocalLow\Conduit
 Ordner Gelöscht : C:\Users\Barbara\AppData\Roaming\software4u
 Ordner Gelöscht : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
 Ordner Gelöscht : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
 [!] Ordner Gelöscht : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
 [!] Ordner Gelöscht : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
 Datei Gelöscht : \END
 
 ***** [ Verknüpfungen ] *****
 
 
 ***** [ Registrierungsdatenbank ] *****
 
 Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\kfkcangbigakljkjeglcofaomihpejif
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
 Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
 Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{501451DE-5808-4599-B544-8BD0915B6B24}_is1
 
 ***** [ Browser ] *****
 
 -\\ Internet Explorer v11.0.9600.16521
 
 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
 Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
 
 -\\ Google Chrome v33.0.1750.154
 
 [ Datei : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
 [ Datei : C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 Gelöscht : homepage
 Gelöscht : icon_url
 Gelöscht : search_url
 Gelöscht : keyword
 
 [ Datei : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 Gelöscht : homepage
 Gelöscht : icon_url
 Gelöscht : search_url
 Gelöscht : keyword
 
 [ Datei : C:\Users\Konstantin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 Gelöscht : homepage
 Gelöscht : icon_url
 Gelöscht : search_url
 Gelöscht : keyword
 
 [ Datei : C:\Users\Jakob\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 Gelöscht : homepage
 Gelöscht : icon_url
 Gelöscht : search_url
 Gelöscht : keyword
 
 *************************
 
 AdwCleaner[R0].txt - [5285 octets] - [26/03/2014 12:32:45]
 AdwCleaner[S0].txt - [4690 octets] - [26/03/2014 12:43:08]
 
 ########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [4750 octets] ##########
 AdwCleaner 2.Mal:   Code: 
 # AdwCleaner v3.022 - Bericht erstellt am 26/03/2014 um 12:32:45# Aktualisiert 13/03/2014 von Xplode
 # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
 # Benutzername : Barbara - PROWORX-PC
 # Gestartet von : C:\Users\Barbara\Downloads\adwcleaner.exe
 # Option : Suchen
 
 ***** [ Dienste ] *****
 
 
 ***** [ Dateien / Ordner ] *****
 
 Datei Gefunden : \END
 Ordner Gefunden : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
 Ordner Gefunden : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
 Ordner Gefunden : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
 Ordner Gefunden : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
 Ordner Gefunden C:\Program Files (x86)\FreeRIP
 Ordner Gefunden C:\Program Files (x86)\software4u
 Ordner Gefunden C:\Users\Barbara\AppData\Roaming\software4u
 Ordner Gefunden C:\Users\proworx\AppData\Local\apn
 Ordner Gefunden C:\Users\proworx\AppData\Local\PackageAware
 Ordner Gefunden C:\Users\proworx\AppData\Local\Temp\AskSearch
 Ordner Gefunden C:\Users\proworx\AppData\Local\Temp\boost_interprocess
 Ordner Gefunden C:\Users\proworx\AppData\LocalLow\Conduit
 
 ***** [ Verknüpfungen ] *****
 
 
 ***** [ Registrierungsdatenbank ] *****
 
 Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
 Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
 Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
 Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\kfkcangbigakljkjeglcofaomihpejif
 Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\kfkcangbigakljkjeglcofaomihpejif
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
 Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{501451DE-5808-4599-B544-8BD0915B6B24}_is1
 Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
 Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
 Wert Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
 
 ***** [ Browser ] *****
 
 -\\ Internet Explorer v11.0.9600.16521
 
 Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] - hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013
 Einstellung Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default] - hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYBTU&co=AT&userid=b81a5864-4c22-9f83-8f58-75a990013416&searchtype=ds&q={searchTerms}&installDate=27/12/2013
 
 -\\ Google Chrome v33.0.1750.154
 
 [ Datei : C:\Users\proworx\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
 [ Datei : C:\Users\Judith\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 Gefunden : homepage
 Gefunden : icon_url
 Gefunden : search_url
 Gefunden : keyword
 
 [ Datei : C:\Users\Barbara\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 Gefunden : homepage
 Gefunden : icon_url
 Gefunden : search_url
 Gefunden : keyword
 
 [ Datei : C:\Users\Konstantin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 Gefunden : homepage
 Gefunden : icon_url
 Gefunden : search_url
 Gefunden : keyword
 
 [ Datei : C:\Users\Jakob\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 Gefunden : homepage
 Gefunden : icon_url
 Gefunden : search_url
 Gefunden : keyword
 
 *************************
 
 AdwCleaner[R0].txt - [5135 octets] - [26/03/2014 12:32:45]
 
 ########## EOF - \AdwCleaner\AdwCleaner[R0].txt - [5195 octets] ##########
 So, ich hoffe, du hast nun alles, was du brauchst!  
Liebe Grüße  
Barbara |