BlackSite | 22.06.2014 10:11 | MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.06.2014
Suchlauf-Zeit: 10:49:55
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.22.01
Rootkit Datenbank: v2014.06.20.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Max
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 272931
Verstrichene Zeit: 3 Min, 59 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 6
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, 1356, Löschen bei Neustart, [17624f2c413a8aacb8ca3426f30e7090]
PUP.Optional.WindowsUpdateService.A, C:\Program Files (x86)\Security Updates Service\winupdsvc.exe, 2348, Löschen bei Neustart, [9edb2a51700b83b3cd8724258a76a55b]
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\updateHypeNet.exe, 2516, Löschen bei Neustart, [5d1c05765a2178bea9b20e56c8397c84]
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\utilHypeNet.exe, 2824, Löschen bei Neustart, [6c0d245732493bfb0556560ef60be21e]
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\HypeNet.BrowserAdapter.exe, 5928, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac]
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\HypeNet.PurBrowse64.exe, 5076, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac]
Module: 3
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\HypeNetBAApp.dll, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\{b1ce3ece-1927-4e6e-b064-2f9628964a7a}.dll, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\{b1ce3ece-1927-4e6e-b064-2f9628964a7a}.dll, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac],
Registrierungsschlüssel: 32
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginService, In Quarantäne, [17624f2c413a8aacb8ca3426f30e7090],
PUP.Optional.WindowsUpdateService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Security Updates Service, In Quarantäne, [9edb2a51700b83b3cd8724258a76a55b],
PUP.Optional.HypeNet.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update HypeNet, In Quarantäne, [5d1c05765a2178bea9b20e56c8397c84],
PUP.Optional.HypeNet.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util HypeNet, In Quarantäne, [6c0d245732493bfb0556560ef60be21e],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [750487f488f3ba7c53579edd010160a0],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [750487f488f3ba7c53579edd010160a0],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [96e3d0ab7803e056edb0ab9b10f2728e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [96e3d0ab7803e056edb0ab9b10f2728e],
PUP.Optional.GetNow.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}, In Quarantäne, [9adfbac159229f970f958bbd56ac11ef],
PUP.Optional.GetNow.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{237FDFDB-3722-470E-8BA8-90196DABE967}, In Quarantäne, [9adfbac159229f970f958bbd56ac11ef],
PUP.Optional.GetNow.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{237FDFDB-3722-470E-8BA8-90196DABE967}, In Quarantäne, [9adfbac159229f970f958bbd56ac11ef],
PUP.Optional.GetNow.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{F126C9FC-9299-40F2-BD42-C59023AD1E7F}, In Quarantäne, [9adfbac159229f970f958bbd56ac11ef],
PUP.Optional.WowSearch.A, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9bb2c1cc-4a7d-4cd5-bce9-0ca5f9ff8391}, Löschen bei Neustart, [40398af18fec5cdae78877ce9a683bc5],
PUP.Optional.WowSearch.A, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB2C1CC-4A7D-4CD5-BCE9-0CA5F9FF8391}, Löschen bei Neustart, [40398af18fec5cdae78877ce9a683bc5],
PUP.Optional.WowSearch.A, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB2C1CC-4A7D-4CD5-BCE9-0CA5F9FF8391}, Löschen bei Neustart, [40398af18fec5cdae78877ce9a683bc5],
PUP.Optional.WowSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB2C1CC-4A7D-4CD5-BCE9-0CA5F9FF8391}, In Quarantäne, [40398af18fec5cdae78877ce9a683bc5],
PUP.Optional.WowSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB2C1CC-4A7D-4CD5-BCE9-0CA5F9FF8391}, In Quarantäne, [40398af18fec5cdae78877ce9a683bc5],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HypeNet, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{ac225167-00fc-452d-94c5-bb93600e7d9a}, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [adcc691267141125622e4c9f3bc8a55b],
PUP.Optional.HypeNet.A, HKLM\SOFTWARE\WOW6432NODE\HypeNet, In Quarantäne, [5a1f0279ccaf3afc8e760bb739c94bb5],
PUP.Optional.Qone8.A, HKLM\SOFTWARE\WOW6432NODE\qone8Software, In Quarantäne, [1f5aaecda2d97bbbe55843a7897add23],
PUP.Optional.HypeNet.A, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HypeNet, Löschen bei Neustart, [cbae7cff1962d75fa45f923043bf7789],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [502933483447fa3cd0f2ccfd49b99b65],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [19603348f18ae155349d8e51946f857b],
Registrierungswerte: 7
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [0574304b9dde49edd245fd4b7a883dc3],
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, C:\Program Files\V-bates\Firefox, In Quarantäne, [0574304b9dde49edd245fd4b7a883dc3]
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, C:\Program Files\V-bates\Firefox, In Quarantäne, [0574304b9dde49edd245fd4b7a883dc3]
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [0970d7a44d2e290d9d7a1b2d936f7090],
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com, In Quarantäne, [0871d3a89fdc9d99686d6954ff03ca36]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0X2O1C0R2R1R, Löschen bei Neustart, [19603348f18ae155349d8e51946f857b]
PUP.Optional.QuickStart.A, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, quick_start@gmail.com, Löschen bei Neustart, [5f1ae497d9a2d066b6e0d3d325dd6997]
Registrierungsdaten: 8
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.qone8.com/?type=hp&ts=1397231746&from=sien&uid=WDCXWD10EZRX-22L4HB0_WD-WCC4J096138361383, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.qone8.com/?type=hp&ts=1397231746&from=sien&uid=WDCXWD10EZRX-22L4HB0_WD-WCC4J096138361383),Ersetzt,[8aef9cdff388f14558dfceaa30d453ad]
Hijack.StartPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://start.qone8.com/?type=hp&ts=1397231746&from=sien&uid=WDCXWD10EZRX-22L4HB0_WD-WCC4J096138361383, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.qone8.com/?type=hp&ts=1397231746&from=sien&uid=WDCXWD10EZRX-22L4HB0_WD-WCC4J096138361383),Ersetzt,[78016615611ac76f41f8c4b452b246ba]
Hijack.StartPage, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://start.qone8.com/?type=hp&ts=1397231746&from=sien&uid=WDCXWD10EZRX-22L4HB0_WD-WCC4J096138361383, Gut: (hxxp://www.google.com), Schlecht: (hxxp://start.qone8.com/?type=hp&ts=1397231746&from=sien&uid=WDCXWD10EZRX-22L4HB0_WD-WCC4J096138361383),Ersetzt,[10695c1f0c6fc96dbd7a0e6a1de703fd]
PUP.Optional.SnapDo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPxaISMkHdlmbcGktBgceMVIus_zJpLlGeicNvhaZXGmtPuVNQxpia1TPSXHrvFn&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPxaISMkHdlmbcGktBgceMVIus_zJpLlGeicNvhaZXGmtPuVNQxpia1TPSXHrvFn&q={searchTerms}),Ersetzt,[d3a6fa81e695dd597e5eafc8f60e8878]
PUP.Optional.Snapdo, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPAQtnBgxwlmUcv8eI13Fy51n8-1q9LK65Y0ixZ4-5fW3qrdz-7DKire2vxYieHb, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPAQtnBgxwlmUcv8eI13Fy51n8-1q9LK65Y0ixZ4-5fW3qrdz-7DKire2vxYieHb),Löschen bei Neustart,[3148dba09fdcce68e1625a270cf831cf]
PUP.Optional.Snapdo, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPxaISMkHdlmbcGktBgceMVIus_zJpLlGeicNvhaZXGmtPuVNQxpia1TPSXHrvFg&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPxaISMkHdlmbcGktBgceMVIus_zJpLlGeicNvhaZXGmtPuVNQxpia1TPSXHrvFg&q={searchTerms}),Löschen bei Neustart,[7702cdae047763d3c282275ac53f16ea]
PUP.Optional.Snapdo, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPxaISMkHdlmbcGktBgceMVIus_zJpLlGeicNvhaZXGmtPuVNQxpia1TPSXHrvFg&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPxaISMkHdlmbcGktBgceMVIus_zJpLlGeicNvhaZXGmtPuVNQxpia1TPSXHrvFg&q={searchTerms}),Löschen bei Neustart,[1f5a3b405a21e3534ff6f78a51b312ee]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-3157235878-4259759608-4195695675-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPxaISMkHdlmbcGktBgceMVIus_zJpLlGeicNvhaZXGmtPuVNQxpia1TPSXHrvFg&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPxaISMkHdlmbcGktBgceMVIus_zJpLlGeicNvhaZXGmtPuVNQxpia1TPSXHrvFg&q={searchTerms}),Löschen bei Neustart,[007989f2fd7ec076b627b1c68c788e72]
Ordner: 65
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\TEMP, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.RegCleanerPro.A, C:\Users\Max\AppData\Roaming\Systweak\RegClean Pro, In Quarantäne, [4138730834470036f320721d2dd5c23e],
PUP.Optional.RegCleanerPro.A, C:\Users\Max\AppData\Roaming\Systweak\RegClean Pro\Version 6.1, In Quarantäne, [4138730834470036f320721d2dd5c23e],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, Löschen bei Neustart, [4138dc9fc3b8bc7a12439af7d52df808],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [4138dc9fc3b8bc7a12439af7d52df808],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\include, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\include\tools, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\en, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\en-US, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\es, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\es-419, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr-BE, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr-CA, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr-CH, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr-LU, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\it, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\it-CH, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\pl, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\pt-BR, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\ru, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\ru-MO, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\tr, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\vi, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\zh-CN, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\zh-TW, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\weather, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\defaults, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\defaults\preferences, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.SecurityUpdatesService.A, C:\Program Files (x86)\Security Updates Service, Löschen bei Neustart, [caaf1368de9d1b1b147410939b6736ca],
Dateien: 151
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\PluginService.exe, Löschen bei Neustart, [17624f2c413a8aacb8ca3426f30e7090],
PUP.Optional.WindowsUpdateService.A, C:\Program Files (x86)\Security Updates Service\winupdsvc.exe, Löschen bei Neustart, [9edb2a51700b83b3cd8724258a76a55b],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\updateHypeNet.exe, Löschen bei Neustart, [5d1c05765a2178bea9b20e56c8397c84],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\utilHypeNet.exe, Löschen bei Neustart, [6c0d245732493bfb0556560ef60be21e],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [96e3d0ab7803e056edb0ab9b10f2728e],
PUP.Optional.SupTab.A, C:\Users\Max\AppData\Roaming\SupTab\SupTab.dll, In Quarantäne, [4c2da4d7d8a374c2f46ca293b34d37c9],
PUP.Optional.Superfish.A, C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, Löschen bei Neustart, [5b1e9fdc6d0e04324aaf58582fd30ef2],
PUP.Optional.Superfish.A, C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [e594601bc5b690a6906989276c96dd23],
PUP.Optional.WebSearch.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\searchplugins\Web Search.xml, In Quarantäne, [8ced2e4d72092f0730a23788986ad42c],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\HypeNet.ico, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\0, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\7za.exe, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\HypeNetUn.exe, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\HypeNetUninstall.exe, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\updateHypeNet.InstallState, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\7za.exe, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\BrowserAdapterS.7z, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\HypeNet.BrowserAdapter.exe, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\HypeNet.PurBrowse.zip, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\HypeNet.PurBrowse64.exe, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\HypeNet.PurBrowseG.zip, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\HypeNetBAApp.dll, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\sqlite3.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\utilHypeNet.InstallState, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\{b1ce3ece-1927-4e6e-b064-2f9628964a7a}.dll, Löschen bei Neustart, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins\HypeNet.Bromon.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins\HypeNet.BroStats.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins\HypeNet.BrowserAdapterS.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins\HypeNet.CompatibilityChecker.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins\HypeNet.FFUpdate.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins\HypeNet.IEUpdate.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins\HypeNet.PurBrowse.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins\HypeNet.PurBrowseG.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.HypeNet.A, C:\Program Files (x86)\HypeNet\bin\plugins\HypeNet.Repmon.dll, In Quarantäne, [24550675bbc064d2de24a71b4ab854ac],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [58214b3082f9a492a00feed5e61c40c0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\search.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\sliders.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [d4a5c1ba3744db5b43432a9ce51d06fa],
PUP.Optional.Qone8.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\qone8.xml, In Quarantäne, [d5a495e62b505dd941fbdd0d788bd62a],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [4138dc9fc3b8bc7a12439af7d52df808],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome.manifest, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\install.rdf, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\index.html, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\quick_start.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\quick_start.xul, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\include\speed_dial.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\include\tools\about_blank_hook.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\include\tools\misc.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\include\tools\popup_image_helper.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\include\tools\urlrequestor.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\js\common.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\js\doT.min.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\js\ga.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\js\jquery-2.1.0.min.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\js\jquery.autocomplete.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\js\js.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\content\js\xagainit.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\en\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\en-US\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\es\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\es-419\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr-BE\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr-CA\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr-CH\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\fr-LU\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\it\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\it-CH\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\pl\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\pt-BR\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\ru\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\ru-MO\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\tr\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\vi\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\zh-CN\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\locale\zh-TW\locale.properties, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\arrow.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\default_add_logo.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\default_add_logo_hover.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\default_logo.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\googlelogo.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\googlelogo2.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\google_trends.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\icon.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\loading.gif, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\logo.ico, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\logo.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\logo32.ico, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\style.css, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\chrome\skin\weather\0.png, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\defaults\preferences\fvd.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\addonmanager.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\aes.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\config.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\dialogs.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\last_tab.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\misc.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\properties.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\remoterequest.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\restoreprefs.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.QuickStart.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\extensions\quick_start@gmail.com\modules\settings.js, In Quarantäne, [4f2a0873116aa096b24414802cd6d12f],
PUP.Optional.SecurityUpdatesService.A, C:\Program Files (x86)\Security Updates Service\search_checker.exe, In Quarantäne, [caaf1368de9d1b1b147410939b6736ca],
PUP.Optional.Snapdo.A, C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPAQtnBgxwlmUcv8eI13Fy51n8-1q9LK65Y0ixZ4-5fW3qrdz-7DKire2vxYieHb",), Ersetzt,[3940dd9ec4b732043139832ca06407f9]
PUP.Optional.WowSearch.A, C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://wow.utop.it/?q={searchTerms}");), Ersetzt,[d9a00f6c19623105ffbda30c27ddc23e]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner: Code:
# AdwCleaner v3.212 - Bericht erstellt am 22/06/2014 um 11:00:14
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : Max - MAX-PC
# Gestartet von : C:\Users\Max\Desktop\adwcleaner_3.212.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\FreeRIP
Ordner Gelöscht : C:\Program Files (x86)\RegClean Pro
Ordner Gelöscht : C:\Users\Max\AppData\Roaming\qone8
Ordner Gelöscht : C:\Users\Max\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\Max\AppData\Roaming\Systweak
Datei Gelöscht : C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FreeRIP3_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\FreeRIP3_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SupTab_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SupTab_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\systweakasp_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wpm_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wpm_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\Software\IePlugin
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{501451DE-5808-4599-B544-8BD0915B6B24}_is1
***** [ Browser ] *****
-\\ Internet Explorer v8.0.7601.17514
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\prefs.js ]
Zeile gelöscht : user_pref("browser.uiCustomization.state", "{\"placements\":{\"PanelUI-contents\":[\"edit-controls\",\"zoom-controls\",\"new-window-button\",\"privatebrowsing-button\",\"save-page-button\",\"print-but[...]
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPxaISMkHdlmbcGktBgceMVIus_zJpLlGeicNvhaZXGmtPuVNQxpia1TPSXHrvFn&q={searchTerms}
Gelöscht [Homepage] : hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPHRo0PyGG1_Kxr4dEqi2tMc9XvzeUiwAdwAQWGgFfaATxqSEOj-zgOl4nGHu2dbgC4ZyyEXkQsG9Ob3y4nN29Z3ayUwXcFkZfPB_dAhPAQtnBgxwlmUcv8eI13Fy51n8-1q9LK65Y0ixZ4-5fW3qrdz-7DKire2vxYieHb
*************************
AdwCleaner[R0].txt - [4858 octets] - [22/06/2014 10:59:41]
AdwCleaner[S0].txt - [4322 octets] - [22/06/2014 11:00:14]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4382 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x64
Ran by Max on 22.06.2014 at 11:02:10,83
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Emptied folder: C:\Users\Max\AppData\Roaming\mozilla\firefox\profiles\ojkhbsfc.default\minidumps [37 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.06.2014 at 11:04:19,46
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-06-2014 01
Ran by Max (administrator) on MAX-PC on 22-06-2014 11:06:45
Running from C:\Users\Max\Desktop
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(SteelSeries ApS) C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7192792 2013-07-06] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1096480 2013-11-29] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2273056 2013-11-29] (NVIDIA Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-06-06] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-3157235878-4259759608-4195695675-1000\...\Run: [SteelSeries Engine] => C:\Program Files\SteelSeries\SteelSeries Engine\SteelSeriesEngine.exe [242688 2013-11-05] (SteelSeries ApS)
Startup: C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk
ShortcutTarget: Curse.lnk -> C:\Users\Max\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x6D9B2C8A02E3CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {9bb2c1cc-4a7d-4cd5-bce9-0ca5f9ff8391} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll No File
BHO-x32: EZ YouTube Video Downloader 1.0 - {FDBFEA30-EC51-4B8D-B4F0-8CA4F7253C0A} - C:\Program Files (x86)\EZ YouTube Video Downloader\yvd.dll (XtensionPlus)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default
FF NewTab: chrome://quick_start/content/index.html
FF DefaultSearchEngine: wow search
FF SearchEngineOrder.1: wow search
FF SelectedSearchEngine: wow search
FF Homepage: hxxp://www.facebook.com/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1209149.dll (Adobe Systems, Inc.)
FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 - C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF Plugin-x32: @esn/npbattlelog,version=2.3.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.3.2\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\searchplugins\search_engine.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\ojkhbsfc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-11-16]
FF HKLM\...\Firefox\Extensions: [{8167E8F2-A770-4EFB-BA53-8A511051CD9B}] - C:\Program Files (x86)\EZ YouTube Video Downloader\{8167E8F2-A770-4EFB-BA53-8A511051CD9B}
FF Extension: EZ YouTube Video Downloader - C:\Program Files (x86)\EZ YouTube Video Downloader\{8167E8F2-A770-4EFB-BA53-8A511051CD9B} [2014-04-13]
FF HKLM-x32\...\Firefox\Extensions: [{8167E8F2-A770-4EFB-BA53-8A511051CD9B}] - C:\Program Files (x86)\EZ YouTube Video Downloader\{8167E8F2-A770-4EFB-BA53-8A511051CD9B}
FF Extension: EZ YouTube Video Downloader - C:\Program Files (x86)\EZ YouTube Video Downloader\{8167E8F2-A770-4EFB-BA53-8A511051CD9B} [2014-04-13]
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR StartupUrls: "hxxp://google.de/", "hxxp://www.twitch.tv/marcelamariaeuw"
CHR NewTab: "chrome-extension://mnhlhlpdiiefbhhmoljklbejhnlgniop/index.html"
CHR DefaultSearchKeyword: wow.utop.it
CHR DefaultSearchProvider: wow search
CHR DefaultSearchURL: hxxp://wow.utop.it/?q={searchTerms}
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-02]
CHR Extension: (Google Drive) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-02]
CHR Extension: (YouTube) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-02]
CHR Extension: (Google-Suche) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-02]
CHR Extension: (AdBlock) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-01]
CHR Extension: (Google Wallet) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-02]
CHR Extension: (Google Mail) - C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-02]
CHR Extension: (Tab Plus) - C:\Users\Max\AppData\Local\ChromeTabExtension [2014-06-15]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-06] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-06] (Avira Operations GmbH & Co. KG)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.01\atkexComSvc.exe [927232 2012-10-29] ()
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-02-07] () [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1370912 2013-11-29] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15128352 2013-11-29] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2014-01-11] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-03-01] ()
==================== Drivers (Whitelisted) ====================
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-21] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-06-06] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-06] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [496400 2013-02-27] (Intel Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-10-30] (NVIDIA Corporation)
R3 SAlphamHid; C:\Windows\System32\DRIVERS\SAlpham64.sys [38016 2013-05-31] (SteelSeries Corporation)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R1 {b1ce3ece-1927-4e6e-b064-2f9628964a7a}Gw64; C:\Windows\System32\drivers\{b1ce3ece-1927-4e6e-b064-2f9628964a7a}Gw64.sys [61112 2014-05-22] (StdLib)
R1 {b1ce3ece-1927-4e6e-b064-2f9628964a7a}w64; C:\Windows\System32\drivers\{b1ce3ece-1927-4e6e-b064-2f9628964a7a}w64.sys [61112 2014-06-09] (StdLib)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-22 11:06 - 2014-06-22 11:06 - 00014039 _____ () C:\Users\Max\Desktop\FRST.txt
2014-06-22 11:04 - 2014-06-22 11:04 - 00000819 _____ () C:\Users\Max\Desktop\JRT.txt
2014-06-22 11:02 - 2014-06-22 11:02 - 00000000 ____D () C:\Windows\ERUNT
2014-06-22 11:01 - 2014-06-22 11:01 - 00004474 _____ () C:\Users\Max\Desktop\AdwCleaner[S0].txt
2014-06-22 10:59 - 2014-06-22 11:00 - 00000000 ____D () C:\AdwCleaner
2014-06-22 10:59 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-22 10:58 - 2014-06-22 10:58 - 00049803 _____ () C:\Users\Max\Desktop\mbam.txt
2014-06-22 10:45 - 2014-06-22 10:56 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-22 10:44 - 2014-06-22 10:44 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-22 10:44 - 2014-06-22 10:44 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-22 10:44 - 2014-06-22 10:44 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-22 10:44 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-22 10:44 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-22 10:44 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-22 10:31 - 2014-06-22 10:40 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Max\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-22 10:28 - 2014-06-22 11:05 - 00000000 ____D () C:\Users\Max\Desktop\AntiVir
2014-06-22 10:25 - 2014-06-22 10:27 - 01016261 _____ (Thisisu) C:\Users\Max\Desktop\JRT.exe
2014-06-22 10:25 - 2014-06-22 10:26 - 01333465 _____ () C:\Users\Max\Desktop\adwcleaner_3.212.exe
2014-06-21 13:13 - 2014-06-21 13:13 - 00013982 _____ () C:\ComboFix.txt
2014-06-21 13:09 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-21 13:09 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-21 13:09 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-21 13:09 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-21 13:09 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-21 13:09 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-21 13:09 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-21 13:09 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-21 13:08 - 2014-06-21 13:13 - 00000000 ____D () C:\Qoobox
2014-06-21 13:08 - 2014-06-21 13:12 - 00000000 ____D () C:\Windows\erdnt
2014-06-21 12:59 - 2014-06-21 12:59 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-21 10:45 - 2014-06-22 11:06 - 00000000 ____D () C:\FRST
2014-06-21 10:35 - 2014-06-21 10:36 - 02083328 _____ (Farbar) C:\Users\Max\Desktop\FRST64.exe
2014-06-21 10:34 - 2014-06-21 10:34 - 00000000 _____ () C:\Users\Max\defogger_reenable
2014-06-20 18:12 - 2014-06-22 10:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-15 16:07 - 2014-06-15 16:07 - 00000000 ____D () C:\Users\Max\AppData\Local\EZ YouTube Video Downloader
2014-06-15 13:06 - 2014-06-15 13:06 - 00000000 ____D () C:\Users\Max\AppData\Local\ChromeTabExtension
2014-06-14 11:41 - 2014-06-09 12:08 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{b1ce3ece-1927-4e6e-b064-2f9628964a7a}w64.sys
2014-06-08 18:15 - 2014-06-08 18:15 - 00000562 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-06-08 18:15 - 2014-06-08 18:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-06-08 18:15 - 2014-06-08 18:15 - 00000000 ____D () C:\Fraps
2014-06-08 18:12 - 2014-06-08 18:12 - 00001038 _____ () C:\Users\Public\Desktop\Vegas Pro 12.0 (64-bit).lnk
2014-06-08 18:12 - 2014-06-08 18:12 - 00000000 ____D () C:\Users\Max\AppData\Roaming\Publish Providers
2014-06-08 18:12 - 2014-06-08 18:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-06-08 18:11 - 2014-06-08 18:11 - 00000000 ____D () C:\Program Files\Sony
2014-06-08 18:11 - 2014-06-08 18:11 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-06-08 18:02 - 2014-06-08 18:02 - 00000212 _____ () C:\Users\Max\Desktop\Magic 2014.url
2014-06-08 17:58 - 2014-06-08 18:11 - 00000000 ____D () C:\Users\Max\AppData\Local\Sony
2014-06-08 17:43 - 2014-06-08 18:11 - 00000000 ____D () C:\ProgramData\Sony
2014-06-08 17:42 - 2014-06-08 18:12 - 00000000 ____D () C:\Users\Max\AppData\Roaming\Sony
2014-06-08 11:22 - 2014-06-08 11:22 - 00000000 ____D () C:\Users\Max\AppData\Local\Ubisoft
2014-06-01 15:31 - 2014-06-01 15:31 - 00000212 _____ () C:\Users\Max\Desktop\Tom Clancy's Ghost Recon Phantoms - EU.url
2014-05-31 13:56 - 2014-06-22 10:49 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-31 13:56 - 2014-05-31 13:56 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-28 22:30 - 2014-05-28 22:30 - 00000000 ____D () C:\Users\Max\Desktop\King
2014-05-28 18:48 - 2014-05-28 18:48 - 00000000 ____D () C:\Users\Max\AppData\Roaming\Wargaming.net
2014-05-24 13:29 - 2014-05-24 13:29 - 00000658 _____ () C:\Users\Public\Desktop\Guild Wars 2.lnk
2014-05-24 13:29 - 2014-05-24 13:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2
2014-05-24 13:23 - 2014-05-24 13:23 - 00000000 ____D () C:\Users\Max\AppData\Roaming\Guild Wars 2
2014-05-24 13:03 - 2014-05-24 13:23 - 00000000 ____D () C:\Users\Max\Documents\Guild Wars 2
2014-05-23 23:47 - 2014-05-22 18:18 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{b1ce3ece-1927-4e6e-b064-2f9628964a7a}Gw64.sys
==================== One Month Modified Files and Folders =======
2014-06-22 11:06 - 2014-06-22 11:06 - 00014039 _____ () C:\Users\Max\Desktop\FRST.txt
2014-06-22 11:06 - 2014-06-21 10:45 - 00000000 ____D () C:\FRST
2014-06-22 11:05 - 2014-06-22 10:28 - 00000000 ____D () C:\Users\Max\Desktop\AntiVir
2014-06-22 11:04 - 2014-06-22 11:04 - 00000819 _____ () C:\Users\Max\Desktop\JRT.txt
2014-06-22 11:02 - 2014-06-22 11:02 - 00000000 ____D () C:\Windows\ERUNT
2014-06-22 11:01 - 2014-06-22 11:01 - 00004474 _____ () C:\Users\Max\Desktop\AdwCleaner[S0].txt
2014-06-22 11:01 - 2013-11-28 19:24 - 00174074 _____ () C:\Windows\PFRO.log
2014-06-22 11:01 - 2013-11-17 14:14 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-22 11:01 - 2013-11-16 23:51 - 00049126 _____ () C:\Windows\setupact.log
2014-06-22 11:01 - 2013-11-16 21:39 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-06-22 11:01 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-22 11:00 - 2014-06-22 10:59 - 00000000 ____D () C:\AdwCleaner
2014-06-22 11:00 - 2013-11-16 21:15 - 00694059 _____ () C:\Windows\WindowsUpdate.log
2014-06-22 11:00 - 2009-07-14 06:45 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-22 11:00 - 2009-07-14 06:45 - 00026544 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-22 10:58 - 2014-06-22 10:58 - 00049803 _____ () C:\Users\Max\Desktop\mbam.txt
2014-06-22 10:56 - 2014-06-22 10:45 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-22 10:56 - 2013-11-17 04:04 - 00000000 ____D () C:\Windows\Panther
2014-06-22 10:54 - 2013-11-17 14:14 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-22 10:49 - 2014-05-31 13:56 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-22 10:44 - 2014-06-22 10:44 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-22 10:44 - 2014-06-22 10:44 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-22 10:44 - 2014-06-22 10:44 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-22 10:40 - 2014-06-22 10:31 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Max\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-22 10:32 - 2014-05-16 14:32 - 00000000 ____D () C:\Users\Max\AppData\Roaming\vlc
2014-06-22 10:30 - 2014-04-23 18:08 - 00000000 ____D () C:\Users\Max\Desktop\Stronk
2014-06-22 10:27 - 2014-06-22 10:25 - 01016261 _____ (Thisisu) C:\Users\Max\Desktop\JRT.exe
2014-06-22 10:27 - 2014-06-20 18:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-22 10:26 - 2014-06-22 10:25 - 01333465 _____ () C:\Users\Max\Desktop\adwcleaner_3.212.exe
2014-06-22 10:16 - 2011-04-12 09:43 - 00696622 _____ () C:\Windows\system32\perfh007.dat
2014-06-22 10:16 - 2011-04-12 09:43 - 00147918 _____ () C:\Windows\system32\perfc007.dat
2014-06-22 10:16 - 2009-07-14 07:13 - 01612464 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-22 10:14 - 2009-07-14 04:34 - 00000505 _____ () C:\Windows\win.ini
2014-06-22 00:09 - 2013-11-16 23:47 - 00000000 ____D () C:\Users\Max\AppData\Roaming\TS3Client
2014-06-21 18:13 - 2014-05-01 01:59 - 00000000 ____D () C:\Users\Max\Desktop\Instalok
2014-06-21 18:13 - 2013-12-20 16:55 - 00000000 ____D () C:\Users\Max\Desktop\Musik
2014-06-21 14:11 - 2014-05-01 02:09 - 00000000 ____D () C:\Users\Max\Desktop\LoL
2014-06-21 14:11 - 2014-05-01 02:02 - 00000000 ____D () C:\Users\Max\Desktop\Charts
2014-06-21 14:11 - 2014-05-01 01:59 - 00000000 ____D () C:\Users\Max\Desktop\Mixes
2014-06-21 14:11 - 2014-03-24 13:53 - 00000000 ____D () C:\Users\Max\Desktop\Kollegah
2014-06-21 13:13 - 2014-06-21 13:13 - 00013982 _____ () C:\ComboFix.txt
2014-06-21 13:13 - 2014-06-21 13:08 - 00000000 ____D () C:\Qoobox
2014-06-21 13:12 - 2014-06-21 13:08 - 00000000 ____D () C:\Windows\erdnt
2014-06-21 13:12 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-06-21 12:59 - 2014-06-21 12:59 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-21 10:57 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-06-21 10:36 - 2014-06-21 10:35 - 02083328 _____ (Farbar) C:\Users\Max\Desktop\FRST64.exe
2014-06-21 10:34 - 2014-06-21 10:34 - 00000000 _____ () C:\Users\Max\defogger_reenable
2014-06-21 10:34 - 2013-11-16 21:08 - 00000000 ____D () C:\Users\Max
2014-06-20 16:49 - 2013-11-17 14:14 - 00004100 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-20 16:49 - 2013-11-17 14:14 - 00003848 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-15 16:07 - 2014-06-15 16:07 - 00000000 ____D () C:\Users\Max\AppData\Local\EZ YouTube Video Downloader
2014-06-15 13:06 - 2014-06-15 13:06 - 00000000 ____D () C:\Users\Max\AppData\Local\ChromeTabExtension
2014-06-15 13:06 - 2014-04-18 22:01 - 00761485 _____ () C:\ProgramData\ChromeTabExtension.crx
2014-06-13 23:27 - 2014-04-16 19:05 - 00000000 ____D () C:\Users\Max\AppData\Roaming\Skype
2014-06-09 12:08 - 2014-06-14 11:41 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{b1ce3ece-1927-4e6e-b064-2f9628964a7a}w64.sys
2014-06-08 18:15 - 2014-06-08 18:15 - 00000562 _____ () C:\Users\Public\Desktop\Fraps.lnk
2014-06-08 18:15 - 2014-06-08 18:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fraps
2014-06-08 18:15 - 2014-06-08 18:15 - 00000000 ____D () C:\Fraps
2014-06-08 18:12 - 2014-06-08 18:12 - 00001038 _____ () C:\Users\Public\Desktop\Vegas Pro 12.0 (64-bit).lnk
2014-06-08 18:12 - 2014-06-08 18:12 - 00000000 ____D () C:\Users\Max\AppData\Roaming\Publish Providers
2014-06-08 18:12 - 2014-06-08 18:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2014-06-08 18:12 - 2014-06-08 17:42 - 00000000 ____D () C:\Users\Max\AppData\Roaming\Sony
2014-06-08 18:11 - 2014-06-08 18:11 - 00000000 ____D () C:\Program Files\Sony
2014-06-08 18:11 - 2014-06-08 18:11 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-06-08 18:11 - 2014-06-08 17:58 - 00000000 ____D () C:\Users\Max\AppData\Local\Sony
2014-06-08 18:11 - 2014-06-08 17:43 - 00000000 ____D () C:\ProgramData\Sony
2014-06-08 18:02 - 2014-06-08 18:02 - 00000212 _____ () C:\Users\Max\Desktop\Magic 2014.url
2014-06-08 18:00 - 2014-05-09 13:39 - 00000555 _____ () C:\Windows\cdplayer.ini
2014-06-08 18:00 - 2014-05-09 13:11 - 00001534 _____ () C:\ProgramData\ss.ini
2014-06-08 11:22 - 2014-06-08 11:22 - 00000000 ____D () C:\Users\Max\AppData\Local\Ubisoft
2014-06-06 20:16 - 2014-04-07 12:00 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-06-06 20:16 - 2014-04-07 12:00 - 00112080 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-01 15:31 - 2014-06-01 15:31 - 00000212 _____ () C:\Users\Max\Desktop\Tom Clancy's Ghost Recon Phantoms - EU.url
2014-05-31 13:58 - 2013-11-23 15:08 - 00000000 ____D () C:\ProgramData\Origin
2014-05-31 13:56 - 2014-05-31 13:56 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-31 13:56 - 2013-11-16 21:58 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-31 13:56 - 2013-11-16 21:58 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-05-30 21:57 - 2013-12-15 03:44 - 00000000 ____D () C:\Users\Max\AppData\Local\Battle.net
2014-05-28 22:30 - 2014-05-28 22:30 - 00000000 ____D () C:\Users\Max\Desktop\King
2014-05-28 18:48 - 2014-05-28 18:48 - 00000000 ____D () C:\Users\Max\AppData\Roaming\Wargaming.net
2014-05-24 13:29 - 2014-05-24 13:29 - 00000658 _____ () C:\Users\Public\Desktop\Guild Wars 2.lnk
2014-05-24 13:29 - 2014-05-24 13:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Guild Wars 2
2014-05-24 13:23 - 2014-05-24 13:23 - 00000000 ____D () C:\Users\Max\AppData\Roaming\Guild Wars 2
2014-05-24 13:23 - 2014-05-24 13:03 - 00000000 ____D () C:\Users\Max\Documents\Guild Wars 2
Some content of TEMP:
====================
C:\Users\Max\AppData\Local\Temp\avgnt.exe
C:\Users\Max\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-20 15:38
==================== End Of Log ============================ --- --- ---
--- --- --- |