MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 16.07.2014
Suchlauf-Zeit: 23:02:43
Logdatei: mbamb-log-2014-07-16 (23-02-41).txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.16.09
Rootkit Datenbank: v2014.07.14.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Kilaoa
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 293853
Verstrichene Zeit: 7 Min, 2 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 1
PUP.Optional.FastStart.A, HKU\S-1-5-21-2172048925-2899888979-4254774926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [86b3f7a912691f175ce5616032d06e92]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 0
(No malicious items detected)
Dateien: 0
(No malicious items detected)
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 27.06.2014
Suchlauf-Zeit: 21:50:34
Logdatei: mbamb-log-2014-06-27 (21-49-50).txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.27.08
Rootkit Datenbank: v2014.06.23.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Kilaoa
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 291457
Verstrichene Zeit: 13 Min, 8 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 2
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\wprotectmanager.exe, 5516, Löschen bei Neustart, [5420d2ab25569f97a9c2bdd1be43b848]
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 5776, Löschen bei Neustart, [d59f3746d0ab55e1099089d2f30e0df3]
Module: 1
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [82f245386b108ea8dfdf7119a35e7c84],
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 2
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [f282abd21467c4725f2d55542cd6ee12],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger, In Quarantäne, [c9ab700d78032f07d95aa703c1418a76],
Dateien: 3
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\wprotectmanager.exe, In Quarantäne, [5420d2ab25569f97a9c2bdd1be43b848],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [d59f3746d0ab55e1099089d2f30e0df3],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [82f245386b108ea8dfdf7119a35e7c84],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 27.06.2014
Suchlauf-Zeit: 21:28:07
Logdatei: mbamb-log-2014-06-27 (21-28-05).txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.27.08
Rootkit Datenbank: v2014.06.23.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Kilaoa
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 291326
Verstrichene Zeit: 8 Min, 19 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 2
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\wprotectmanager.exe, 5516, Löschen bei Neustart, [f97bdba2483364d299d247473ec3d927]
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 5776, Löschen bei Neustart, [97dd1667f883b5811b7ebf9cf50c916f]
Module: 1
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [b0c454290b700234be00553512ef47b9],
Registrierungsschlüssel: 13
PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsProtectManger, In Quarantäne, [f97bdba2483364d299d247473ec3d927],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsProtectManger, In Quarantäne, [f97bdba2483364d299d247473ec3d927],
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [97dd1667f883b5811b7ebf9cf50c916f],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [353f8cf16c0fe1556a38dd6e837f956b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [353f8cf16c0fe1556a38dd6e837f956b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [353f8cf16c0fe1556a38dd6e837f956b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [353f8cf16c0fe1556a38dd6e837f956b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [353f8cf16c0fe1556a38dd6e837f956b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [353f8cf16c0fe1556a38dd6e837f956b],
PUP.Optional.Skytech.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\sweet-page uninstall, In Quarantäne, [da9a2b52c6b589ad526c5535df22aa56],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [ed87fb82502b3ff72535718a946f48b8],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2172048925-2899888979-4254774926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [3a3a98e595e6dc5a6e26f6daee147b85],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2172048925-2899888979-4254774926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [284cd6a7f58663d308a5c71f5ea55ca4],
Registrierungswerte: 5
PUP.Optional.SupTab.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~2.DLL, In Quarantäne, [3b3956276318ad89f9e4c8e3877be41c]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, c:\progra~2\suptab\search~1.dll, In Quarantäne, [cfa5c3ba90ebb5814d905754b74bef11]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com, In Quarantäne, [660e7eff6318bf772cf055b118ec2ed2]
PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WINDOWSPROTECTMANGER|ImagePath, C:\ProgramData\WindowsProtectManger\wprotectmanager.exe -service, In Quarantäne, [fd771b624833043213d7515d34ce07f9]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2172048925-2899888979-4254774926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [284cd6a7f58663d308a5c71f5ea55ca4]
Registrierungsdaten: 12
PUP.Optional.Skytech.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SupTab\SEARCH~2.DLL, Gut: (), Schlecht: (C:\PROGRA~2\SupTab\SEARCH~2.DLL),Ersetzt,[165e93ea116ad5614c729eece61b36ca]
PUP.Optional.Skytech.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, c:\progra~2\suptab\search~1.dll, Gut: (), Schlecht: (c:\progra~2\suptab\search~1.dll),Ersetzt,[b4c0d7a6453656e07747b9d145bc7c84]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112),Ersetzt,[6d07b6c77902f4422a1b3753c53f7090]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112),Ersetzt,[096b6f0ed2a9c67033143d4d31d3fd03]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112&q={searchTerms}),Ersetzt,[d2a295e87b00f4428fb7beccb54fda26]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112),Ersetzt,[b9bb74090c6f39fd7cc9781218ec7d83]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112),Ersetzt,[660e087581fae650d0779feb46be7789]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112&q={searchTerms}),Ersetzt,[6c08750839422016869d5a254eb68779]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://www.sweet-page.com/web/?type=ds&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112&q={searchTerms}, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112&q={searchTerms}),Ersetzt,[3c3893ea314a2115f059d1b9cb39d729]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCH|CustomizeSearch, hxxp://www.sweet-page.com/web/?type=ds&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112&q={searchTerms}, Gut: (hxxp://www.google.com/), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112&q={searchTerms}),Ersetzt,[1d57403d9cdf7fb7c880c9c1c341b34d]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-2172048925-2899888979-4254774926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112),Ersetzt,[155f403d700bf145f84a2367bc4827d9]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-2172048925-2899888979-4254774926-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112),Ersetzt,[a5cfc8b5bebdac8a8cb54a403acab050]
Ordner: 64
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
Rogue.Multiple, C:\ProgramData\374311380, In Quarantäne, [eb89621ba5d6e056ed0e582bab576d93],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [6212c7b6f38890a6a6e636734ab8ec14],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [6212c7b6f38890a6a6e636734ab8ec14],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger, Löschen bei Neustart, [da9adca1accfdc5aba793f6b867caa56],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log, In Quarantäne, [da9adca1accfdc5aba793f6b867caa56],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update, In Quarantäne, [da9adca1accfdc5aba793f6b867caa56],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\include, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\include\tools, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\lib, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\module, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\pack, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\en, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\en-US, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\es, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\es-419, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr-BE, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr-CA, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr-CH, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr-LU, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\it, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\it-CH, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\pl, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\pt-BR, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\ru, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\ru-MO, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\tr, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\vi, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\zh-CN, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\zh-TW, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\defaults, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\defaults\preferences, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
Dateien: 138
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\wprotectmanager.exe, Löschen bei Neustart, [f97bdba2483364d299d247473ec3d927],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [97dd1667f883b5811b7ebf9cf50c916f],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [b0c454290b700234be00553512ef47b9],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect64.dll, In Quarantäne, [165e93ea116ad5614c729eece61b36ca],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\SearchProtect32.dll, In Quarantäne, [b4c0d7a6453656e07747b9d145bc7c84],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [353f8cf16c0fe1556a38dd6e837f956b],
PUP.Optional.Skytech.A, C:\Users\Kilaoa\AppData\Roaming\sweet-page\UninstallManager.exe, In Quarantäne, [da9a2b52c6b589ad526c5535df22aa56],
PUP.Optional.IePluginService.A, C:\Users\Kilaoa\AppData\Local\Temp\2302824\2302824.zipDir\tmp\SupTab_Setup448.exe, In Quarantäne, [ec885528e09bed4976232b30fe0340c0],
PUP.Optional.WPM.A, C:\Users\Kilaoa\AppData\Local\Temp\2302824\2302824.zipDir\tmp\wpm_v20.0.0.401.exe, In Quarantäne, [a5cffb82ec8f2a0c78f3721ce71ac43c],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\ient.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\WebDataJs, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\data.html, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE.html, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\indexIE8.html, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\main.css, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\ver.txt, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\arrow.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_add_logo_hover.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\default_logo.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\googlelogo2.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\google_trends.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon128.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon16.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\icon48.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\loading.gif, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\weather\0.png, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\en-US\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-419\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\es-ES\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-BE\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CA\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-CH\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-FR\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\fr-LU\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-CH\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\it-IT\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pl\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\pt-BR\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\ru-MO\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\tr-TR\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\vi-VI\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-CN\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\_locales\zh-TW\messages.json, In Quarantäne, [5123017c3c3f6dc92735418caf530df3],
PUP.Optional.SweetPage.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml, In Quarantäne, [7bf92459accff5410f4ac932b64d4db3],
Rogue.Multiple, C:\ProgramData\374311380\BIT4182.tmp, In Quarantäne, [eb89621ba5d6e056ed0e582bab576d93],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [6212c7b6f38890a6a6e636734ab8ec14],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log\wprotectmanager_2014-06-27[20-52-50-600].log, In Quarantäne, [da9adca1accfdc5aba793f6b867caa56],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update\conf, In Quarantäne, [da9adca1accfdc5aba793f6b867caa56],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome.manifest, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\install.rdf, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\index.html, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\quick_start.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\quick_start.xul, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\include\speed_dial.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\include\tools\about_blank_hook.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\include\tools\misc.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\include\tools\popup_image_helper.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\include\tools\urlrequestor.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\js.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\lib\doT.min.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery-2.1.0.min.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\lib\jquery.autocomplete.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\module\hotSearch.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\module\mostgrid.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\module\other.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\module\search.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\module\stat.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\pack\common.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\pack\ga.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\content\js\pack\xagainit.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\en\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\en-US\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\es\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\es-419\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr-BE\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr-CA\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr-CH\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\fr-LU\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\it\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\it-CH\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\pl\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\pt-BR\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\ru\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\ru-MO\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\tr\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\vi\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\zh-CN\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\locale\zh-TW\locale.properties, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\default_add_logo.png, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\default_add_logo_hover.png, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\default_logo.png, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\googlelogo.png, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\google_trends.png, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\icon.png, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\loading.gif, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\logo.ico, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\logo.png, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\logo32.ico, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\simple.css, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\chrome\skin\style.css, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\defaults\preferences\fvd.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\defaults\preferences\preferences.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\addonmanager.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\aes.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\config.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\dialogs.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\last_tab.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\misc.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\properties.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\remoterequest.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\restoreprefs.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.FastStart.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\extensions\faststartff@gmail.com\modules\settings.js, In Quarantäne, [1262631adf9c56e0447a4763b44e1ee2],
PUP.Optional.SweetPage.A, C:\Users\Kilaoa\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112",), Ersetzt,[df9515681f5c7cba8ea222970cf8629e]
PUP.Optional.SweetPage.A, C:\Users\Kilaoa\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "search_url": "hxxp://www.sweet-page.com/web/?type=ds&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112&q={searchTerms}",), Ersetzt,[4f25de9fbcbff6408ea40aafa361728e]
PUP.Optional.SweetPage.A, C:\Users\Kilaoa\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112" ],), Ersetzt,[8ee6f687156653e33003a71245bfa45c]
PUP.Optional.SweetPage.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.sweet-page.com/newtab/?type=nt&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112");), Ersetzt,[91e33e3fe7943afcc9648237b64eab55]
PUP.Optional.SweetPage.A, C:\Users\Kilaoa\AppData\Roaming\Mozilla\Firefox\Profiles\d5eeteom.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.sweet-page.com/?type=hp&ts=1403895152&from=cor&uid=SAMSUNGXHD322HJ_S17AJ90SA21112");), Ersetzt,[a5cf45380b7071c541edd7e232d27f81]
Physische Sektoren: 0
(No malicious items detected)
(end) ClamAV: Code:
/mnt/Program Files (x86)/Windows Media Player/wmpconfig.exe: Win.Worm.Whiteice-17 FOUND
/mnt/Program Files (x86)/LinuxLive USB Creator/LiLi USB Creator.exe: Win.Trojan.11477628 FOUND
/mnt/Program Files (x86)/LinuxLive USB Creator/tools/VirtualBox/Portable-VirtualBox/Portable-VirtualBox.exe: Win.Trojan.11477628 FOUND
LibClamAV info: scancws: Error decompressing SWF file
LibClamAV info: scancws: Error decompressing SWF file
LibClamAV info: scancws: Error decompressing SWF file
LibClamAV Warning: SWF: Invalid tag length.
LibClamAV Warning: SWF: Invalid tag length.
LibClamAV info: scancws: Error decompressing SWF file
LibClamAV Warning: SWF: Invalid tag length.
LibClamAV info: scancws: Error decompressing SWF file
LibClamAV info: scancws: Error decompressing SWF file
LibClamAV Warning: SWF: Invalid tag length.
LibClamAV info: scancws: Error decompressing SWF file
/mnt/Users/Kilaoa/Downloads/LinuxLive USB Creator 2.8.29.exe: Win.Trojan.11477628 FOUND
/mnt/ProgramData/Blizzard Entertainment/Battle.net/Cache/03/65/0365085e6db8869534846414c5dcbdc1d1ffe13f8db92c1f12ea5c7eddf9298f.auth: WIN.Downloader.Adload-47 FOUND
LibClamAV info: scancws: Error decompressing SWF file
LibClamAV info: scancws: Error decompressing SWF file
LibClamAV info: scancws: Error decompressing SWF file
/mnt/Windows/System32/drivers/rdbss.sys: Win.Trojan.Zbot-35241 FOUND
/mnt/Windows/SysWOW64/aecache.dll: Win.Trojan.Agent-752483 FOUND
/mnt/Windows/SysWOW64/appwiz.cpl: Win.Trojan.Agent-728870 FOUND
/mnt/Windows/SysWOW64/user32.dll: Win.Trojan.11486308 FOUND
/mnt/Windows/winsxs/amd64_microsoft-windows-rdbss_31bf3856ad364e35_6.1.7601.17514_none_b7fadd3b7808f9d5/rdbss.sys: Win.Trojan.Zbot-35241 FOUND
/mnt/Windows/winsxs/Backup/amd64_microsoft-windows-rdbss_31bf3856ad364e35_6.1.7601.17514_none_b7fadd3b7808f9d5_rdbss.sys_f97a2535: Win.Trojan.Zbot-35241 FOUND
/mnt/Windows/winsxs/Backup/wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e_user32.dll_55f4ed20: Win.Trojan.11486308 FOUND
/mnt/Windows/winsxs/wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e/user32.dll: Win.Trojan.11486308 FOUND
/mnt/Windows/winsxs/x86_microsoft-windows-appwiz_31bf3856ad364e35_6.1.7601.17514_none_0dcda26885283f50/appwiz.cpl: Win.Trojan.Agent-728870 FOUND
/mnt/Windows/winsxs/x86_microsoft-windows-dims-keyroam_31bf3856ad364e35_6.1.7600.16385_none_5b7a6e238ef0e573/adprovider.dll: Win.Trojan.Agent-752453 FOUND
/mnt/Windows/winsxs/x86_microsoft-windows-sysprep-aecache_31bf3856ad364e35_6.1.7600.16385_none_f4906b14fa5f4e62/aecache.dll: Win.Trojan.Agent-752483 FOUND
/mnt/Windows/winsxs/wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.1.7601.17514_none_73e472e09a1a05d1/wmpconfig.exe: Win.Worm.Whiteice-17 FOUND
/mnt/Windows/winsxs/wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.1.7601.18150_none_73b513a89a3e353e/wmpconfig.exe: Win.Worm.Whiteice-17 FOUND
/mnt/Windows/winsxs/wow64_microsoft-windows-mediaplayer-core_31bf3856ad364e35_6.1.7601.22322_none_746122b1b341b10a/wmpconfig.exe: Win.Worm.Whiteice-17 FOUND So dass war's, vielen Dank schonmal für's Anschauen. |