| arne_wiescha | 17.06.2014 21:00 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 17.06.2014
Suchlauf-Zeit: 21:00:54
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.17.10
Rootkit Datenbank: v2014.06.02.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Arne
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 288363
Verstrichene Zeit: 17 Min, 53 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, 1444, Löschen bei Neustart, [15796316354604326b7484d50af74fb1]
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe, 2252, Löschen bei Neustart, [c8c6a3d6364513234de205b2c43ede22]
Module: 2
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [9af484f5e8930234548f0d7b7c8534cc],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdate.dll, Löschen bei Neustart, [c3cb49306c0f82b4c81aabe6748e06fa],
Registrierungsschlüssel: 98
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, In Quarantäne, [15796316354604326b7484d50af74fb1],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [dab4db9ec7b4be78d11446f9f80a27d9],
PUP.Optional.CouponDownloader.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [dab4db9ec7b4be78d11446f9f80a27d9],
PUP.Optional.CouponDownloader.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [dab4db9ec7b4be78d11446f9f80a27d9],
PUP.Optional.CouponDownloader.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{10AD2C61-0898-4348-8600-14A342F22AC3}, In Quarantäne, [dab4db9ec7b4be78d11446f9f80a27d9],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [0b83f08990eb033319e5ef53f60c6b95],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [0b83f08990eb033319e5ef53f60c6b95],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [0b83f08990eb033319e5ef53f60c6b95],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [0b83f08990eb033319e5ef53f60c6b95],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [0b83f08990eb033319e5ef53f60c6b95],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [0b83f08990eb033319e5ef53f60c6b95],
PUP.Optional.SupTab.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [0b83f08990eb033319e5ef53f60c6b95],
PUP.Optional.SupTab.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [0b83f08990eb033319e5ef53f60c6b95],
PUP.Optional.SearchQu, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}, In Quarantäne, [9bf328513f3c4de90647f154f70b52ae],
PUP.Optional.DataMangr.A, HKLM\SOFTWARE\DataMngr, In Quarantäne, [e1ade495ec8f47ef44046a3c669ced13],
PUP.Optional.SupraSavings.A, HKLM\SOFTWARE\suprasavings, In Quarantäne, [2f5f84f5abd04fe7f6299521a75bb947],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickCtrl.9, In Quarantäne, [830bf58490eb96a01b174f680ff3619f],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine, In Quarantäne, [325c81f8f5865fd74ee4e1d6669c37c9],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0, In Quarantäne, [e3abc2b7ee8dc86ea290d1e615ede31d],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdate.Update3WebControl.3, In Quarantäne, [800ee29785f637ffa091bafd54ae738d],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync, In Quarantäne, [bad48cedd5a650e60b276d4a8d7557a9],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0, In Quarantäne, [028c7900601bc2747eb4516670926b95],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass, In Quarantäne, [eca25722413a52e4b280b8ff12f0837d],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass.1, In Quarantäne, [deb085f45724af872012a90ec43ecd33],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass, In Quarantäne, [8905babf26557fb7161c0fa82dd528d8],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass.1, In Quarantäne, [76186a0f512ac670e1517b3c6b97837d],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine, In Quarantäne, [4c42a8d1a5d653e33cf69b1cd42e629e],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0, In Quarantäne, [bbd37306f883c472171b52659e647e82],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine, In Quarantäne, [a9e5cdac79024fe7b87ae7d0738fa45c],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [682645344c2f94a271c1397e669cc53b],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [d2bc94e59ae1b185969cb8fff80a629e],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [1777b8c11269a393062c318643bfaa56],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc, In Quarantäne, [a4eafe7b3447e1557bb7f1c6f70b55ab],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [038b3f3a1a61de580f2306b155ad35cb],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher, In Quarantäne, [d3bb72073d3ea98dbc7617a0748e21df],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0, In Quarantäne, [6c22c4b585f672c45ad8d6e109f940c0],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService, In Quarantäne, [6925cfaa681339fd1919a90e29d95fa1],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0, In Quarantäne, [e0ae94e5b4c7a393d9591a9d31d1c63a],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine, In Quarantäne, [642a463319628ea82a08a3148280b54b],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0, In Quarantäne, [3757b5c4d6a58da98ca6a2152dd56f91],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback, In Quarantäne, [1579047523586bcb181a199eaa58a060],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [9cf23b3e9edd003663cf853206fcbd43],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc, In Quarantäne, [810d196068133bfbfd35199ed42ea858],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0, In Quarantäne, [16782a4f6f0cdd594be784333fc3837d],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [98f6a0d92f4c52e457c765818e7533cd],
PUP.Optional.SupraSavings.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\suprasavings, In Quarantäne, [f599da9f33486ec88dc8e0d313ef08f8],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\DealPlyLive, In Quarantäne, [602e2b4e29520b2b13af13c82ad98e72],
PUP.Optional.Qone8.A, HKLM\SOFTWARE\WOW6432NODE\qone8Software, In Quarantäne, [99f529506e0d2a0cf2d9865e0003ce32],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickCtrl.9, In Quarantäne, [f39bc5b493e888ae4ee4e0d7bb4748b8],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine, In Quarantäne, [eba3ee8b7803a49232002c8bd42ebf41],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.OneClickProcessLauncherMachine.1.0, In Quarantäne, [93fb76032b507bbb79b99f18b9497a86],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdate.Update3WebControl.3, In Quarantäne, [226cccad631851e538f9249353af9b65],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync, In Quarantäne, [2a645a1f36459d9986ac51669e64e020],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoCreateAsync.1.0, In Quarantäne, [107ec9b0c9b238fe141ed4e359a9c040],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass, In Quarantäne, [e6a86f0a94e7ff37d85a4c6b04fe6997],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreClass.1, In Quarantäne, [8b032653e497979fd65c66518b779c64],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass, In Quarantäne, [5c329ddc59224ee87cb66b4cfc06cd33],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CoreMachineClass.1, In Quarantäne, [e9a55e1b2c4f0b2bd75b5c5b4ab853ad],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine, In Quarantäne, [d6b89edbf289eb4b58dae6d14ab83dc3],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.CredentialDialogMachine.1.0, In Quarantäne, [523ce594afcc40f6af83f8bffd05fa06],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine, In Quarantäne, [c1cdbcbd8cef7abcc171e4d328daa65a],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachine.1.0, In Quarantäne, [cac4d8a1bbc08aacfb37c5f2986a8c74],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback, In Quarantäne, [e0aec4b54a31a195f53d00b7d72b01ff],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassMachineFallback.1.0, In Quarantäne, [bad45a1f05767fb7042ee2d511f1916f],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc, In Quarantäne, [365885f48cef44f266cc981f52b059a7],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.OnDemandCOMClassSvc.1.0, In Quarantäne, [711dee8b66159a9cd35f33844bb7cf31],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher, In Quarantäne, [820ce99014677fb77fb35c5b20e2f907],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.ProcessLauncher.1.0, In Quarantäne, [8a043d3cef8ce35384ae5f5852b022de],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService, In Quarantäne, [3e5093e61467fd390f235b5c59a9f60a],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3COMClassService.1.0, In Quarantäne, [e4aa36434437f83e49e915a27a88619f],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine, In Quarantäne, [91fdc1b815665bdb59d9a710887a5ea2],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachine.1.0, In Quarantäne, [dfaf7306f487eb4bf939d8df9969cc34],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback, In Quarantäne, [642ade9b205bd85ed0624b6c0101d927],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebMachineFallback.1.0, In Quarantäne, [1b73a2d7df9c74c21022892e8b7705fb],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc, In Quarantäne, [9bf374055922979f3bf7bef96a98a759],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\PriceMeterLiveUpdateUpdate.Update3WebSvc.1.0, In Quarantäne, [b6d8d4a51368ab8b9f93c1f6eb17d52b],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [1b7388f1ccaf5cda20fedd094bb8dd23],
PUP.Optional.AdPeak.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{E6B105B8-1F65-4428-9397-1DFD8A03B94D}, In Quarantäne, [91fd91e82853a591882cd6ce0af810f0],
PUP.Optional.PriceMeter.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pricemeterliveUpdate, In Quarantäne, [c8c6a3d6364513234de205b2c43ede22],
PUP.Optional.PriceMeter.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pricemeterliveUpdatem, In Quarantäne, [c8c6a3d6364513234de205b2c43ede22],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\PRICEMETERLIVEUPDATE.EXE, In Quarantäne, [c8c6a3d6364513234de205b2c43ede22],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\PRICEMETERLIVEUPDATE.EXE, In Quarantäne, [c8c6a3d6364513234de205b2c43ede22],
PUP.Optional.HDvidCodec.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HDvid-Codec V9.0, Löschen bei Neustart, [ddb1cdac582396a0d9c86a538b779f61],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, In Quarantäne, [4549bbbe1e5d39fd279118c37e8549b7],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Datamngr, In Quarantäne, [028cceab8cefb086ab906971a162f709],
PUP.Optional.SupraSavings.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupraSavings, In Quarantäne, [721cb7c266159e9855cbd1e518eaa759],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [622cccadc6b5a98d4791955956ade020],
PUP.Optional.SupraSavings.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Supra Savings, In Quarantäne, [94fa2752cbb0ff3774a0496c1be7758b],
PUP.Optional.SupraSavings.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\suprasavings, In Quarantäne, [9af4116837444de929f85462aa5825db],
PUP.Optional.Qone8, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [7a14ef8a6d0e023471acb630fa09eb15],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{89449F37-4AB2-46ED-A566-BB3A7797701B}, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{89449F37-4AB2-46ED-A566-BB3A7797701B}, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{89449F37-4AB2-46ED-A566-BB3A7797701B}, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F509ADC2-B40E-470F-A7B7-45191486B5CB}, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{F509ADC2-B40E-470F-A7B7-45191486B5CB}, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{F509ADC2-B40E-470F-A7B7-45191486B5CB}, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4211E851-747F-4470-923D-6EF683EE79CA}, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{74930D00-2198-46FE-B6BC-FEEC60C666C9}, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
Registrierungswerte: 2
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\wehm5197.default\extensions\quick_start@gmail.com, In Quarantäne, [f7973742f28995a171f655631ce69e62]
PUP.Optional.PriceMeter.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PriceMeterW, "C:\Users\Arne\AppData\Local\PriceMeter\pricemeterw.exe", In Quarantäne, [fc92d4a5b7c490a67f6cc1e69171bf41]
Registrierungsdaten: 10
PUP.Optional.Qone8, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX),Ersetzt,[1975aecbc6b51125cf6b5526dc283ec2]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX),Ersetzt,[c3cb1d5cb0cb5cdaeeb44c250ef66c94]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX),Ersetzt,[0f7fc6b3abd00e284b55b0c1669e837d]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[0a84205905766fc7d863691239cb47b9]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://start.qone8.com/?type=sc&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX),Ersetzt,[e2ac6712d3a89f9778c275069470e51b]
Hijack.StartPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX),Ersetzt,[9cf2710845369a9c9909b8b9986cba46]
Hijack.StartPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX),Ersetzt,[f49a423739422f070799cca5f70d2cd4]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[b7d73841b5c66bcb5edd5d1ed52f4db3]
PUP.Optional.Trovi.A, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M30CE3C2B-7295-4CC2-B5CC-58F7451C4AC7&SearchSource=55&CUI=&UM=5&UP=SP0C1F87EA-A712-4A30-B3C7-361A6AFC53C1&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M30CE3C2B-7295-4CC2-B5CC-58F7451C4AC7&SearchSource=55&CUI=&UM=5&UP=SP0C1F87EA-A712-4A30-B3C7-361A6AFC53C1&SSPV=),Ersetzt,[8d013049f388f04666b32b4647bd5fa1]
Hijack.StartPage, HKU\S-1-5-21-987069498-686747064-1925067437-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.qone8.com/?type=hp&ts=1400008299&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX),Ersetzt,[e5a902775e1d5dd90c97a0d1ac58cc34]
Ordner: 40
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
Adware.WhenU, C:\Program Files (x86)\VVSN, In Quarantäne, [d5b90e6b3c3f3afcdf29cfb3e51d827e],
PUP.Optional.OpenCandy, C:\Users\Arne\AppData\Roaming\OpenCandy, In Quarantäne, [bcd270093942171f9d5595f5976b9d63],
PUP.Optional.OpenCandy, C:\Users\Arne\AppData\Roaming\OpenCandy\3523768E03634FE4A9631354DDD8A4A2, In Quarantäne, [bcd270093942171f9d5595f5976b9d63],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, Löschen bei Neustart, [97f78dec94e73006822fa0ed8181f50b],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [97f78dec94e73006822fa0ed8181f50b],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate, Löschen bei Neustart, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\CrashReports, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update, Löschen bei Neustart, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0, Löschen bei Neustart, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Download, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Install, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Offline, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\Offline\{46AE1853-AEB3-48EA-A8B8-9D5EE0948CFC}, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.SupraSavings.A, C:\Program Files\suprasavings, In Quarantäne, [1a740277493273c36b1e197908faed13],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
Dateien: 170
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, Löschen bei Neustart, [15796316354604326b7484d50af74fb1],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [9af484f5e8930234548f0d7b7c8534cc],
PUP.Optional.CouponDownloader.A, C:\Program Files (x86)\SupraSavings\2rs3.dll, In Quarantäne, [dab4db9ec7b4be78d11446f9f80a27d9],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [0b83f08990eb033319e5ef53f60c6b95],
PUP.Optional.Conduit.A, C:\Users\Arne\AppData\Roaming\OpenCandy\3523768E03634FE4A9631354DDD8A4A2\sp-downloader.exe, In Quarantäne, [deb0c9b0d8a3d66036dfa17f05fcf60a],
PUP.Optional.SupTab.A, C:\Users\Arne\AppData\Roaming\SupTab\SupTab.dll, In Quarantäne, [721c611883f87db994c5b77e8878bf41],
PUP.Optional.OpenCandy, C:\$Recycle.Bin\S-1-5-21-987069498-686747064-1925067437-1000\$REG87QI.exe, In Quarantäne, [434b6415700b8fa70f5d029d996b25db],
PUP.Optional.OneClickDownloader.A, C:\$Recycle.Bin\S-1-5-21-987069498-686747064-1925067437-1000\$RK9OVOL.exe, In Quarantäne, [4b43b7c2c6b5ad89731d23f2818018e8],
PUP.Optional.AdPeak.A, C:\temp\InstallFilter64.msi, In Quarantäne, [e8a6255466150a2c48372c1138c8bb45],
PUP.Optional.SupraSavings.A, C:\temp\t.msi, In Quarantäne, [b6d8a1d845369b9b00d81e470202758b],
PUP.Optional.Conduit.A, C:\Users\Arne\AppData\Local\Temp\nsd54D8.exe, In Quarantäne, [3a5481f81962270fe88e0d78778afe02],
PUP.Optional.Conduit.A, C:\Users\Arne\AppData\Local\Temp\nsd81F3.exe, In Quarantäne, [4f3fa5d47ffcbb7b87ef5c2942bf8080],
PUP.Optional.Conduit.A, C:\Users\Arne\AppData\Local\Temp\nsd8686.exe, In Quarantäne, [3757abce5229082eb2c4661f03fe6e92],
PUP.Optional.Conduit.A, C:\Users\Arne\AppData\Local\Temp\nsi50B2.exe, In Quarantäne, [18764237740713239ed8e79ef70ac63a],
PUP.Optional.Conduit.A, C:\Users\Arne\AppData\Local\Temp\nsoD4B0.exe, In Quarantäne, [17775821c5b6c373adc97510ce3351af],
PUP.Optional.SkyTech.A, C:\Users\Arne\AppData\Local\Temp\fullpackage_temp1400008288\alilog.dll, In Quarantäne, [0d81631698e3af878e95de54f30d8b75],
PUP.Optional.V9.A, C:\Users\Arne\AppData\Local\Temp\fullpackage_temp1400008288\qSE.exe, In Quarantäne, [6c22f9801a6168ceabed4800f60ad62a],
PUP.Optional.Skytech.A, C:\Users\Arne\AppData\Local\Temp\fullpackage_temp1400008288\UninstallManager.exe, In Quarantäne, [9cf21b5ec0bbfc3a756ef296df22c63a],
PUP.Optional.IePluginService.A, C:\Users\Arne\AppData\Local\Temp\fullpackage_temp1400008288\tmp\SupTab.exe, In Quarantäne, [8c028aef81fa45f1bc23d8811de4e61a],
PUP.Optional.WpManager, C:\Users\Arne\AppData\Local\Temp\fullpackage_temp1400008288\tmp\wpm_v18.8.0.304.exe, In Quarantäne, [7e10a3d66c0f3afc7ad864007a87c13f],
PUP.Optional.Conduit.A, C:\Users\Arne\AppData\Local\Temp\nsy1FB3\SpSetup.exe, In Quarantäne, [216d2950e497241220562164ed147a86],
PUP.Optional.SupraSavings.A, C:\Windows\Installer\ae1a3b.msi, In Quarantäne, [eea06019e09bb3836c6cbbaa0ff57987],
PUP.Optional.Trovi.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\2labfhoj.default-1400697273758\searchplugins\trovi-search.xml, In Quarantäne, [94fa334699e223132b5a208b0af8a35d],
PUP.Optional.CrossRider.A, C:\Windows\Tasks\d0e20c83-1f7c-414d-b69a-6eb92bae8d6e-4.job, In Quarantäne, [afdf18617902ea4caea011a55fa335cb],
PUP.Optional.PriceMeter.A, C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineCore.job, In Quarantäne, [781680f9d7a487afb182e0d745bda25e],
PUP.Optional.PriceMeter.A, C:\Windows\Tasks\PriceMeterLiveUpdateUpdateTaskMachineUA.job, In Quarantäne, [602e9fda99e2999d43f0ad0a4db5669a],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [8a048dec9fdc979f968207ba14ee6b95],
PUP.Optional.Searchqu.A, C:\Users\Arne\AppData\Local\Temp\searchqutoolbar-manifest.xml, In Quarantäne, [5935b3c69fdc6dc9c7032ab0c043dd23],
PUP.Optional.Searchqu.A, C:\Users\Arne\AppData\Local\Temp\SetupDataMngr_Searchqu.exe, In Quarantäne, [cfbfabce97e48aac56756d6db74c9070],
PUP.Optional.Qone8.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\qone8.xml, In Quarantäne, [028c592085f660d69d2d588cd82b2ed2],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\PriceMeterLiveUpdate.exe, Löschen bei Neustart, [c8c6a3d6364513234de205b2c43ede22],
Adware.WhenU, C:\Program Files (x86)\VVSN\vvsn.cfg, In Quarantäne, [d5b90e6b3c3f3afcdf29cfb3e51d827e],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [97f78dec94e73006822fa0ed8181f50b],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_de.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_el.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_en-GB.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_en.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_es-419.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_es.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_et.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fa.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fi.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fil.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_fr.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_gu.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hi.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hr.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_hu.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_id.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_it.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_iw.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ja.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_kn.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ko.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_lt.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_lv.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ml.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_mr.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ms.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_nl.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_no.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pl.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pt-BR.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_pt-PT.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ro.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdate.dll, Löschen bei Neustart, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_am.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ar.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_bg.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_bn.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ca.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_cs.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sk.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sl.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sr.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sv.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_sw.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ta.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_te.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_th.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_tr.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_uk.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ur.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_vi.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_zh-CN.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_zh-TW.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\npGoogleUpdate3.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdate.exe, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateBroker.exe, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateHandler.exe, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateHelper.msi, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\PriceMeterLiveUpdateOnDemand.exe, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\psmachine.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\psuser.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_da.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_is.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.PriceMeter.A, C:\Program Files (x86)\PriceMeterLiveUpdate\Update\1.3.23.0\goopdateres_ru.dll, In Quarantäne, [c3cb49306c0f82b4c81aabe6748e06fa],
PUP.Optional.SupraSavings.A, C:\Program Files\suprasavings\uninstaller.exe, In Quarantäne, [1a740277493273c36b1e197908faed13],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\background.js, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\CustomActionInstall, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\CustomActionUninstall, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\icon128.png, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\icon16.png, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\icon32.png, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\icon48.png, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\icon64.png, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\icon8.png, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\iwalyk.js, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\manifest.json, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\marcopolo.js, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\Microsoft.Deployment.WindowsInstaller.dll, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\Microsoft.Deployment.WindowsInstaller.xml, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.SupraSavings.A, C:\Program Files (x86)\SupraSavings\SendJson.dll, In Quarantäne, [8a048bee25562b0b7f0a266c768cf808],
PUP.Optional.Trovi.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\2labfhoj.default-1400697273758\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M30CE3C2B-7295-4CC2-B5CC-58F7451C4AC7&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SP0C1F87EA-A712-4A30-B3C7-361A6AFC53C1");), Ersetzt,[503e40396a114ceaf0a4208807fd50b0]
PUP.Optional.Qone8.A, C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\2labfhoj.default-1400697273758\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://start.qone8.com/?type=hppp&ts=1401809665&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX");), Entfernung fehlgeschlagen,[08861e5b9fdc7fb796a534756f95916f]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.212 - Bericht erstellt am 17/06/2014 um 21:37:57
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Arne - ARNE-PC
# Gestartet von : C:\Users\Arne\Downloads\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\PriceMeterLiveUpdate
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar
Ordner Gelöscht : C:\Program Files (x86)\iLivid
Ordner Gelöscht : C:\Program Files\003
Ordner Gelöscht : C:\Users\Arne\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Arne\AppData\Local\Ilivid Player
Ordner Gelöscht : C:\Users\Arne\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Arne\AppData\Local\PriceMeterLiveUpdate
Ordner Gelöscht : C:\Users\Arne\AppData\Local\Temp\AskSearch
Ordner Gelöscht : C:\Users\Arne\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Arne\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Datei Gelöscht : C:\Users\Arne\AppData\Local\Temp\Searchqu.ini
Datei Gelöscht : C:\Windows\System32\Tasks\pricemeterdownloader
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\Desktop\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VVSN]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=3
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKCU\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\ilivid
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\Software\dt soft\daemon tools toolbar
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\2labfhoj.default-1400697273758\prefs.js ]
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M30CE3C2B-7295-4CC2-B5CC-58F7451C4AC7&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SP0C1F87EA-A712-4A3[...]
Zeile gelöscht : user_pref("browser.search.selectedEngine", "qone8");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://start.qone8.com/?type=hppp&ts=1401809665&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX");
*************************
AdwCleaner[R0].txt - [8955 octets] - [17/06/2014 21:30:37]
AdwCleaner[R1].txt - [9015 octets] - [17/06/2014 21:36:56]
AdwCleaner[S0].txt - [6976 octets] - [17/06/2014 21:37:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7036 octets] ########## Code:
# AdwCleaner v3.212 - Bericht erstellt am 17/06/2014 um 21:37:57
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Arne - ARNE-PC
# Gestartet von : C:\Users\Arne\Downloads\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\PriceMeterLiveUpdate
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar
Ordner Gelöscht : C:\Program Files (x86)\iLivid
Ordner Gelöscht : C:\Program Files\003
Ordner Gelöscht : C:\Users\Arne\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Arne\AppData\Local\Ilivid Player
Ordner Gelöscht : C:\Users\Arne\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Arne\AppData\Local\PriceMeterLiveUpdate
Ordner Gelöscht : C:\Users\Arne\AppData\Local\Temp\AskSearch
Ordner Gelöscht : C:\Users\Arne\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Arne\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\{800B5000-A755-47E1-992B-48A1C1357F07}
Datei Gelöscht : C:\Users\Arne\AppData\Local\Temp\Searchqu.ini
Datei Gelöscht : C:\Windows\System32\Tasks\pricemeterdownloader
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\Desktop\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
Verknüpfung Desinfiziert : C:\Users\Arne\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VVSN]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=3
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@tools.updatepm.com/PriceMeterLiveUpdate Update;version=9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4FC7-90CC-5EA0ABBE9EB8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKCU\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKCU\Software\ilivid
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKLM\Software\dt soft\daemon tools toolbar
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\2labfhoj.default-1400697273758\prefs.js ]
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=M30CE3C2B-7295-4CC2-B5CC-58F7451C4AC7&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SP0C1F87EA-A712-4A3[...]
Zeile gelöscht : user_pref("browser.search.selectedEngine", "qone8");
Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://start.qone8.com/?type=hppp&ts=1401809665&from=ild&uid=HitachiXHTS545050B9A300_091222PB4400Q7HLVKDAX");
*************************
AdwCleaner[R0].txt - [8955 octets] - [17/06/2014 21:30:37]
AdwCleaner[R1].txt - [9015 octets] - [17/06/2014 21:36:56]
AdwCleaner[S0].txt - [6976 octets] - [17/06/2014 21:37:57]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7036 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Arne on 17.06.2014 at 21:45:55,88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\EvilLyrics_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\EvilLyrics_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\EvilLyrics_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\EvilLyrics_RASMANCS
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0E279570-6E01-48EE-8740-AA804EEAFF50}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
~~~ FireFox
Emptied folder: C:\Users\Arne\AppData\Roaming\mozilla\firefox\profiles\2labfhoj.default-1400697273758\minidumps [8 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 17.06.2014 at 21:53:31,93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-06-2014
Ran by Arne (administrator) on ARNE-PC on 17-06-2014 21:58:03
Running from C:\Users\Arne\Downloads\Programme
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Windows\PLFSetI.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(AlcorMicro Co., Ltd.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Spotify Ltd) C:\Users\Arne\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Hidfind.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-29] (Realtek Semiconductor)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2009-12-28] ()
HKLM\...\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-11] (Egis Technology Inc.)
HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323072 2009-07-23] (AlcorMicro Co., Ltd.)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [823840 2009-09-30] (Acer Incorporated)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [295936 2009-05-21] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-03] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [WinampAgent] => "C:\Program Files (x86)\Winamp\winampa.exe"
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [85160 2009-06-17] (Elaborate Bytes AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-12-10] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-07-05] (Apple Inc.)
HKLM-x32\...\Run: [PlayMovie] => C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe [181480 2009-11-12] (Acer Corp.)
HKLM-x32\...\Run: [NeroFilterCheck] => C:\Windows\SysWOW64\NeroCheck.exe [155648 2001-07-09] (Ahead Software Gmbh)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1100368 2009-11-02] (Dritek System Inc.)
HKLM-x32\...\Run: [EgisTecLiveUpdate] => C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-04] (Egis Technology Inc.)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-09-25] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [ArcadeDeluxeAgent] => C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [419112 2009-10-29] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
HKU\S-1-5-21-987069498-686747064-1925067437-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2009-11-05] (Google Inc.)
HKU\S-1-5-21-987069498-686747064-1925067437-1000\...\Run: [Spotify Web Helper] => C:\Users\Arne\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-06-12] (Spotify Ltd)
HKU\S-1-5-21-987069498-686747064-1925067437-1000\...\Run: [RGSC] => C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
HKU\S-1-5-21-987069498-686747064-1925067437-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-987069498-686747064-1925067437-1000\...\MountPoints2: D - D:\install.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SkyUserDevmode-Update.lnk
ShortcutTarget: SkyUserDevmode-Update.lnk -> C:\DATEV\PROGRAMM\B0001401\UpdateDevmode.exe (DATEV eG)
==================== Internet (Whitelisted) ====================
ProxyServer: 172.16.10.1:8080
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE363
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg64.dll (Google Inc.)
BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Handler: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - No File
Handler-x32: http\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: ipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: msdaipp\0x00000001 - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp\oledb - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Arne\AppData\Roaming\Mozilla\Firefox\Profiles\2labfhoj.default-1400697273758
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-03] (Avira Operations GmbH & Co. KG)
S4 DATEV Update-Service; C:\DATEV\PROGRAMM\INSTALL\DvInesASDSvc.Exe [147040 2009-12-03] (DATEV eG)
S4 DatevPrintService; C:\DATEV\PROGRAMM\B0001442\PSNTSERV.EXE [77312 2008-11-24] (DATEV eG) [File not signed]
S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-11] (Egis Technology Inc.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2010-05-29] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [103736 2010-05-29] ()
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated) [File not signed]
==================== Drivers (Whitelisted) ====================
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2010-09-19] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2010-09-19] ()
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-17] (Malwarebytes Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-01-28] () [File not signed]
S2 SSPORT; C:\Windows\SysWOW64\Drivers\SSPORT.sys [11576 2009-07-29] (Samsung Electronics)
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl [146928 2009-11-12] (CyberLink Corp.)
S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [X]
U0 dmboot;
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-17 21:53 - 2014-06-17 21:53 - 00001425 _____ () C:\Users\Arne\Desktop\JRT.txt
2014-06-17 21:45 - 2014-06-17 21:45 - 01016261 _____ (Thisisu) C:\Users\Arne\Downloads\JRT.exe
2014-06-17 21:45 - 2014-06-17 21:45 - 00000000 ____D () C:\Windows\ERUNT
2014-06-17 21:30 - 2014-06-17 21:38 - 00000000 ____D () C:\AdwCleaner
2014-06-17 21:29 - 2014-06-17 21:30 - 01333465 _____ () C:\Users\Arne\Downloads\adwcleaner_3.212.exe
2014-06-17 21:28 - 2014-06-17 21:28 - 00052669 _____ () C:\Users\Arne\Desktop\mbam.txt
2014-06-17 20:58 - 2014-06-17 21:26 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-17 20:57 - 2014-06-17 20:57 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-17 20:57 - 2014-06-17 20:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-17 20:57 - 2014-06-17 20:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-17 20:57 - 2014-06-17 20:57 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-17 20:57 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-17 20:57 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-17 20:57 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-15 21:41 - 2014-06-15 21:41 - 00001228 _____ () C:\Users\Arne\Desktop\Revo Uninstaller.lnk
2014-06-15 21:41 - 2014-06-15 21:41 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-12 19:16 - 2014-06-12 19:16 - 00001747 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-06-12 19:16 - 2014-06-12 19:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-12 19:14 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 19:14 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 19:13 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 19:13 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 19:13 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 19:13 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 19:13 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-12 19:13 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 19:13 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-12 19:13 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 19:13 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 19:13 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-12 19:13 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-12 19:13 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-12 19:13 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-12 19:13 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-12 19:13 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 19:13 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 19:13 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 19:13 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-12 19:13 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 19:13 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 19:13 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 19:13 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-12 19:13 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 19:13 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-12 19:13 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-12 19:13 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-12 19:13 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 19:13 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-12 19:13 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-12 19:13 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-12 19:13 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 19:13 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-12 19:13 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-12 19:13 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-12 19:13 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 19:13 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-12 19:13 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-12 19:13 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-12 19:13 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-12 19:13 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-12 19:13 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-12 19:13 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 19:13 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-12 19:13 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-12 19:13 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-12 19:13 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 19:13 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-12 19:13 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 19:13 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-12 19:13 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-12 19:13 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-12 19:13 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-12 19:13 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 19:13 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 19:13 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 19:13 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 19:13 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 19:13 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 19:13 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 19:13 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-12 19:13 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-12 19:13 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-12 19:12 - 2014-06-12 19:15 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-12 19:12 - 2014-06-12 19:15 - 00000000 ____D () C:\Program Files\iTunes
2014-06-12 19:12 - 2014-06-12 19:15 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-12 19:12 - 2014-06-12 19:12 - 00000000 ____D () C:\Program Files\iPod
2014-06-12 19:12 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-12 19:12 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-04 18:53 - 2014-06-04 19:01 - 00038366 _____ () C:\Users\Arne\Downloads\Addition.txt
2014-06-04 18:51 - 2014-06-17 21:58 - 00000000 ____D () C:\FRST
2014-06-04 18:51 - 2014-06-04 19:01 - 00051351 _____ () C:\Users\Arne\Downloads\FRST.txt
2014-06-02 20:27 - 2014-06-15 21:27 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\DropboxMaster
==================== One Month Modified Files and Folders =======
2014-06-17 21:59 - 2010-01-19 19:33 - 00000000 ____D () C:\Users\Arne\AppData\Local\Temp
2014-06-17 21:58 - 2014-06-04 18:51 - 00000000 ____D () C:\FRST
2014-06-17 21:58 - 2010-01-28 21:18 - 00000000 ____D () C:\Users\Arne\Downloads\Programme
2014-06-17 21:53 - 2014-06-17 21:53 - 00001425 _____ () C:\Users\Arne\Desktop\JRT.txt
2014-06-17 21:47 - 2009-07-14 06:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-17 21:47 - 2009-07-14 06:45 - 00017600 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-17 21:45 - 2014-06-17 21:45 - 01016261 _____ (Thisisu) C:\Users\Arne\Downloads\JRT.exe
2014-06-17 21:45 - 2014-06-17 21:45 - 00000000 ____D () C:\Windows\ERUNT
2014-06-17 21:39 - 2009-11-05 05:19 - 01015236 _____ () C:\Windows\PFRO.log
2014-06-17 21:39 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-17 21:39 - 2009-07-14 06:51 - 00209196 _____ () C:\Windows\setupact.log
2014-06-17 21:38 - 2014-06-17 21:30 - 00000000 ____D () C:\AdwCleaner
2014-06-17 21:38 - 2013-04-08 18:30 - 00000997 _____ () C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-06-17 21:38 - 2012-04-06 14:44 - 00001025 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-17 21:38 - 2010-01-19 20:21 - 00001013 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-17 21:38 - 2010-01-19 19:34 - 00001110 _____ () C:\Users\Arne\Desktop\Internet Explorer.lnk
2014-06-17 21:38 - 2009-12-28 07:27 - 01419008 _____ () C:\Windows\WindowsUpdate.log
2014-06-17 21:30 - 2014-06-17 21:29 - 01333465 _____ () C:\Users\Arne\Downloads\adwcleaner_3.212.exe
2014-06-17 21:28 - 2014-06-17 21:28 - 00052669 _____ () C:\Users\Arne\Desktop\mbam.txt
2014-06-17 21:27 - 2013-12-11 20:48 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-17 21:26 - 2014-06-17 20:58 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-17 21:20 - 2009-07-14 07:37 - 00000000 ____D () C:\Windows\DigitalLocker
2014-06-17 21:19 - 2014-05-13 21:11 - 00000000 ____D () C:\temp
2014-06-17 20:57 - 2014-06-17 20:57 - 00001066 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-17 20:57 - 2014-06-17 20:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-17 20:57 - 2014-06-17 20:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-17 20:57 - 2014-06-17 20:57 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-17 19:03 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-17 17:33 - 2010-10-17 14:34 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{A21A538D-2940-46BA-AAB3-14AD5A76570F}
2014-06-15 22:10 - 2013-05-02 17:30 - 00000000 ___RD () C:\Users\Arne\Dropbox
2014-06-15 21:41 - 2014-06-15 21:41 - 00001228 _____ () C:\Users\Arne\Desktop\Revo Uninstaller.lnk
2014-06-15 21:41 - 2014-06-15 21:41 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-15 21:27 - 2014-06-02 20:27 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\DropboxMaster
2014-06-15 21:27 - 2013-05-02 17:26 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Dropbox
2014-06-12 22:05 - 2013-09-03 19:44 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 22:03 - 2010-12-13 11:36 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-12 22:03 - 2009-11-05 05:21 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-12 22:00 - 2014-05-12 21:19 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-12 19:27 - 2013-05-02 17:32 - 00000000 ____D () C:\Users\Arne\AppData\Local\Spotify
2014-06-12 19:27 - 2013-05-02 17:31 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Spotify
2014-06-12 19:16 - 2014-06-12 19:16 - 00001747 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-06-12 19:16 - 2014-06-12 19:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-12 19:15 - 2014-06-12 19:12 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-12 19:15 - 2014-06-12 19:12 - 00000000 ____D () C:\Program Files\iTunes
2014-06-12 19:15 - 2014-06-12 19:12 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-12 19:12 - 2014-06-12 19:12 - 00000000 ____D () C:\Program Files\iPod
2014-06-08 11:13 - 2014-06-12 19:12 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 19:12 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-04 19:01 - 2014-06-04 18:53 - 00038366 _____ () C:\Users\Arne\Downloads\Addition.txt
2014-06-04 19:01 - 2014-06-04 18:51 - 00051351 _____ () C:\Users\Arne\Downloads\FRST.txt
2014-06-03 17:39 - 2013-04-02 18:24 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-03 17:39 - 2013-04-02 18:24 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-02 20:27 - 2013-05-02 17:30 - 00001017 _____ () C:\Users\Arne\Desktop\Dropbox.lnk
2014-06-02 20:27 - 2013-05-02 17:27 - 00000000 ____D () C:\Users\Arne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-06-02 20:27 - 2010-05-15 19:00 - 00001030 _____ () C:\Windows\wininit.ini
2014-05-30 12:21 - 2014-06-12 19:13 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-12 19:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-12 19:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-12 19:13 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-12 19:13 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-12 19:13 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-12 19:13 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-12 19:13 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-12 19:13 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-12 19:13 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-12 19:13 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-12 19:13 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-12 19:13 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-12 19:13 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-12 19:13 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-12 19:13 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-12 19:13 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-12 19:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-12 19:13 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-12 19:13 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-12 19:13 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-12 19:13 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-12 19:13 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-12 19:13 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-12 19:13 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 19:13 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-12 19:13 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-12 19:13 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 19:13 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-12 19:13 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-12 19:13 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-12 19:13 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-12 19:13 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-12 19:13 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-12 19:13 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-12 19:13 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 19:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 19:13 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-12 19:13 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 19:13 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-12 19:13 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-12 19:13 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-12 19:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 19:13 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 19:13 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-12 19:13 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-12 19:13 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-12 19:13 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-12 19:13 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-12 19:13 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-12 19:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-12 19:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-21 20:11 - 2010-01-30 12:52 - 00000000 ____D () C:\Program Files (x86)\EvilLyrics
2014-05-21 20:10 - 2009-11-05 05:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer GameZone
2014-05-21 20:10 - 2009-11-05 05:32 - 00000000 ____D () C:\Program Files (x86)\Acer GameZone
2014-05-21 20:10 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-05-21 20:09 - 2009-12-28 07:31 - 00000000 ____D () C:\ProgramData\Temp
2014-05-19 19:36 - 2012-02-17 18:13 - 00211968 _____ () C:\Users\Arne\Documents\Haushalt + Generali.xls
Some content of TEMP:
====================
C:\Users\Arne\AppData\Local\Temp\02b673270b0b50a8d44ad649a71454c1.exe
C:\Users\Arne\AppData\Local\Temp\AskSLib.dll
C:\Users\Arne\AppData\Local\Temp\avgnt.exe
C:\Users\Arne\AppData\Local\Temp\BackupSetup.exe
C:\Users\Arne\AppData\Local\Temp\COMAP.EXE
C:\Users\Arne\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpt1kjje.dll
C:\Users\Arne\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Arne\AppData\Local\Temp\installhelper.dll
C:\Users\Arne\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe
C:\Users\Arne\AppData\Local\Temp\jre-6u29-windows-i586-iftw-rv.exe
C:\Users\Arne\AppData\Local\Temp\jre-7u5-windows-i586-iftw.exe
C:\Users\Arne\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\Arne\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe
C:\Users\Arne\AppData\Local\Temp\Quarantine.exe
C:\Users\Arne\AppData\Local\Temp\SearchWithGoogleUpdate.exe
C:\Users\Arne\AppData\Local\Temp\SHSetup.exe
C:\Users\Arne\AppData\Local\Temp\SRAssetsHelper.dll
C:\Users\Arne\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-17 18:54
==================== End Of Log ============================ --- --- ---
--- --- --- |