Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Trojaner Artemis in C:\Windows\System32\microsoft.com (https://www.trojaner-board.de/157131-trojaner-artemis-c-windows-system32-microsoft-com.html)

TOMROSSI 01.08.2014 14:55

Trojaner Artemis in C:\Windows\System32\microsoft.com
 
Hi
jetzt hats mich auch mal erwischt...der McAffe Stinger hat einen Trojaner gefunden, den Artemis!B5E07021F4DB
Vesteckt sich in C:\Windows\System32\Microsoft.com

Hab schon mal die logs zusammengestellt, bite um Anweisung wies weitergeht, danke

FRST
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-07-2014 02
Ran by HomeBasic1 (administrator) on HOMEBASIC1-PC on 01-08-2014 15:05:02
Running from C:\Users\HomeBasic1\Downloads
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files\GNU\GnuPG\dirmngr.exe
() C:\Program Files\LPT\srpts.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
() C:\Users\HomeBasic1\AppData\Roaming\DRPSu\DrvUpdater.exe
(Smartbar) C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.exe
(StarWind Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
() C:\Program Files\LPT\srptsl.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-05] (Microsoft Corporation)
HKU\.DEFAULT\...\RunOnce: [WindowsUpdate] => C:\Program Files\Windows Manager\winmgr.exe [445952 2014-05-24] (Kitsai)
HKU\.DEFAULT\...\CurrentVersion\Windows: [Load] C:\Windows\system32\Microsoft.com <===== ATTENTION
HKU\S-1-5-21-2801197354-4021152197-1246408157-1001\...\Run: [AviraSpeedup] => "C:\Program Files\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun
HKU\S-1-5-21-2801197354-4021152197-1246408157-1001\...\Run: [DrvUpdater] => C:\Users\HomeBasic1\AppData\Roaming\DRPSu\DrvUpdater.exe [195256 2012-05-31] ()
HKU\S-1-5-21-2801197354-4021152197-1246408157-1001\...\Run: [Browser Infrastructure Helper] => C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.exe [28952 2014-06-11] (Smartbar)
HKU\S-1-5-21-2801197354-4021152197-1246408157-1001\...\CurrentVersion\Windows: [Load] C:\Windows\system32\Microsoft.com <===== ATTENTION
HKU\S-1-5-21-2801197354-4021152197-1246408157-1001\...\MountPoints2: {134d1525-1b76-11e3-a7f3-001635669cca} - E:\DriverPackSolution.exe
HKU\S-1-5-21-2801197354-4021152197-1246408157-1001\...\MountPoints2: {215cc0d6-4dc1-11e3-adf2-001635669cca} - H:\LaunchU3.exe -a
IFEO\AvastSvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\AvastUI.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avcenter.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avconfig.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgcsrvx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgidsagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgnt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgrsx.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avguard.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avgwdsvc.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avira_system_speedup.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avp.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\avscan.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\bdagent.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ccuac.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\ComboFix.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\egui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\hijackthis.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\instup.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\keyscrambler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbam.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamgui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbampt.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamscheduler.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\mbamservice.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MpCmdRun.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MSASCui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\MsMpEng.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\msseces.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\rstrui.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\spybotsd.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\wireshark.exe: [Debugger] C:\Windows\system32\Microsoft.com
IFEO\zlclient.exe: [Debugger] C:\Windows\system32\Microsoft.com
ShellIconOverlayIdentifiers: snxPluginsShell -> {F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE} => C:\Program Files\Alwil Software\Avast5\snxPlugins.dll No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voCiIS4l2kPC6yMc5xXI0YFNPjL2B-TJeKRQ8aYnONf06D_mc32csI8rWgu3CwrJBrb3V_Hqh7YwbkwBQoXe3H6JQmr_eBahg,,
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8C162D5705A4CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}
SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}
BHO: Yahoo Community Smartbar (by Linkury)Engine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Wondershare Player 1.6.0 -> {43D9786F-A485-683B-9B5B-ACC97ABC17FC} -> C:\ProgramData\Wondershare\Player\WSBrowserAppMgr.dll (Wondershare)
Toolbar: HKLM - Yahoo Community Smartbar (by Linkury) - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Handler: WSIEChrome - {6D02ED5F-FD0D-4C4C -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.15

FireFox:
========
FF ProfilePath: C:\Users\HomeBasic1\AppData\Roaming\Mozilla\Firefox\Profiles\m91r75y2.default
FF NewTab: hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voEBfhFK3pEsAaigd-weSBLWjTAKyRjnmhlodqXsk_EocpZvnKjjwsqNva0REtQMSai-xdyNWwcnLuHt8UShQTHdLUuI5YeBA,,
FF SearchEngineOrder.1: SuchMaschine
FF Homepage: about:home
FF Keyword.URL: hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\HomeBasic1\AppData\Roaming\Mozilla\Firefox\Profiles\m91r75y2.default\searchplugins\Web Search.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [Player@Wondershare.com] - C:\ProgramData\Wondershare\Player\Player@Wondershare.com
FF Extension: Wondershare Player - C:\ProgramData\Wondershare\Player\Player@Wondershare.com [2013-11-29]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 DirMngr; C:\Program Files\GNU\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed]
R2 LPTSystemUpdater; C:\Program Files\LPT\srpts.exe [33560 2014-06-11] ()
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-17] (Elaborate Bytes AG)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [477240 2013-10-24] (Duplex Secure Ltd.)
R3 teamviewervpn; C:\Windows\System32\DRIVERS\teamviewervpn.sys [25088 2013-06-06] (TeamViewer GmbH)
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-01 15:05 - 2014-08-01 15:07 - 00013499 _____ () C:\Users\HomeBasic1\Downloads\FRST.txt
2014-08-01 15:04 - 2014-08-01 15:05 - 00000000 ____D () C:\FRST
2014-08-01 15:04 - 2014-08-01 15:04 - 01084928 _____ (Farbar) C:\Users\HomeBasic1\Downloads\FRST.exe
2014-08-01 15:01 - 2014-08-01 15:01 - 00000022 _____ () C:\Windows\S.dirmngr
2014-08-01 15:00 - 2014-08-01 15:00 - 00000660 _____ () C:\Users\HomeBasic1\Downloads\defogger_disable.log
2014-08-01 15:00 - 2014-08-01 15:00 - 00000204 _____ () C:\Users\HomeBasic1\defogger_reenable
2014-08-01 14:59 - 2014-08-01 15:00 - 00050477 _____ () C:\Users\HomeBasic1\Downloads\Defogger.exe
2014-08-01 13:44 - 2014-08-01 14:12 - 00000929 _____ () C:\Users\HomeBasic1\Downloads\Stinger_01082014_134433.html
2014-08-01 13:44 - 2014-08-01 13:44 - 01273068 _____ () C:\Users\HomeBasic1\Downloads\runtime.dat
2014-08-01 13:43 - 2014-08-01 13:43 - 10968424 _____ (McAfee Inc) C:\Users\HomeBasic1\Downloads\stinger32(1).exe
2014-07-30 09:50 - 2014-07-30 09:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-07-16 09:06 - 2014-06-18 12:21 - 00021452 _____ () C:\Users\HomeBasic1\Documents\Heidelberger02_Kündigung.odt
2014-07-14 07:59 - 2014-07-14 08:25 - 00000000 ____D () C:\Program Files\GetSolar
2014-07-14 07:59 - 2014-07-14 07:59 - 01101165 _____ (Ing.-Büro solar energie information ) C:\Users\HomeBasic1\Downloads\gs73inst.exe
2014-07-14 07:59 - 2014-07-14 07:59 - 00000917 _____ () C:\Users\HomeBasic1\Desktop\GetSolar.lnk
2014-07-14 07:59 - 2014-07-14 07:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GetSolar
2014-07-14 07:29 - 2014-07-14 07:29 - 00002452 _____ () C:\Users\HomeBasic1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-14 07:29 - 2014-07-14 07:29 - 00002390 _____ () C:\Users\HomeBasic1\Desktop\Search.lnk
2014-07-14 07:29 - 2014-07-14 07:29 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Local\Smartbar
2014-07-14 07:29 - 2014-07-14 07:29 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Local\LPT
2014-07-14 07:29 - 2014-07-14 07:29 - 00000000 ____D () C:\Program Files\LPT
2014-07-14 07:28 - 2014-07-14 07:28 - 00001017 _____ () C:\Users\Public\Desktop\PasswdFinder.lnk
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\OpenCandy
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PasswdFinder
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\Program Files\PasswdFinder
2014-07-14 07:27 - 2014-07-14 07:27 - 04546280 _____ (PasswdFinder ) C:\Users\HomeBasic1\Downloads\Passwd25FinderInstaller.exe
2014-07-13 19:23 - 2014-07-13 19:23 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Local\Adobe
2014-07-11 07:44 - 2014-07-11 07:44 - 00911722 _____ () C:\Users\HomeBasic1\Downloads\bayernwerkantrge.zip
2014-07-10 17:28 - 2014-08-01 13:43 - 00000124 ___RH () C:\Users\HomeBasic1\Downloads\Stinger.opt
2014-07-10 15:01 - 2014-07-10 15:10 - 00000931 _____ () C:\Users\HomeBasic1\Downloads\Stinger_10072014_150139.html
2014-07-10 14:58 - 2014-07-10 14:58 - 00167344 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe.f9c1.deleteme
2014-07-10 14:58 - 2014-07-10 14:58 - 00000000 ____D () C:\Quarantine
2014-07-10 14:57 - 2014-07-10 15:01 - 00001039 _____ () C:\Users\HomeBasic1\Downloads\Stinger_10072014_145704.html
2014-07-10 14:56 - 2014-08-01 13:58 - 00000000 ____D () C:\Program Files\stinger
2014-07-10 14:56 - 2014-07-10 14:56 - 10959720 _____ (McAfee Inc) C:\Users\HomeBasic1\Downloads\stinger32.exe
2014-07-10 13:08 - 2014-08-01 15:00 - 00000000 __SHD () C:\Program Files\Windows Manager
2014-07-10 13:08 - 2014-05-24 14:17 - 00445952 __RSH (Kitsai) C:\Windows\system32\Microsoft.com
2014-07-09 09:56 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 09:56 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 09:56 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 09:56 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 09:56 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 09:56 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 09:56 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 09:56 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 09:56 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 09:56 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 09:56 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 09:56 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 09:56 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 09:56 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 09:56 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 09:56 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 09:56 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 09:55 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 09:55 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 09:55 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 09:55 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 09:55 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 09:55 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 09:55 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 09:55 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 09:55 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 09:55 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 09:55 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 09:55 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 09:55 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 09:55 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 09:55 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 09:55 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 09:55 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 09:54 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 09:54 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 09:54 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-01 15:07 - 2014-08-01 15:05 - 00013499 _____ () C:\Users\HomeBasic1\Downloads\FRST.txt
2014-08-01 15:06 - 2013-08-26 09:07 - 01150138 _____ () C:\Windows\WindowsUpdate.log
2014-08-01 15:05 - 2014-08-01 15:04 - 00000000 ____D () C:\FRST
2014-08-01 15:04 - 2014-08-01 15:04 - 01084928 _____ (Farbar) C:\Users\HomeBasic1\Downloads\FRST.exe
2014-08-01 15:01 - 2014-08-01 15:01 - 00000022 _____ () C:\Windows\S.dirmngr
2014-08-01 15:01 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-01 15:01 - 2009-07-14 06:39 - 00045912 _____ () C:\Windows\setupact.log
2014-08-01 15:00 - 2014-08-01 15:00 - 00000660 _____ () C:\Users\HomeBasic1\Downloads\defogger_disable.log
2014-08-01 15:00 - 2014-08-01 15:00 - 00000204 _____ () C:\Users\HomeBasic1\defogger_reenable
2014-08-01 15:00 - 2014-08-01 14:59 - 00050477 _____ () C:\Users\HomeBasic1\Downloads\Defogger.exe
2014-08-01 15:00 - 2014-07-10 13:08 - 00000000 __SHD () C:\Program Files\Windows Manager
2014-08-01 15:00 - 2013-08-28 18:10 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\BOM
2014-08-01 15:00 - 2013-08-26 09:29 - 00000000 ____D () C:\Users\HomeBasic1
2014-08-01 14:12 - 2014-08-01 13:44 - 00000929 _____ () C:\Users\HomeBasic1\Downloads\Stinger_01082014_134433.html
2014-08-01 14:10 - 2013-09-11 13:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-01 13:58 - 2014-07-10 14:56 - 00000000 ____D () C:\Program Files\stinger
2014-08-01 13:44 - 2014-08-01 13:44 - 01273068 _____ () C:\Users\HomeBasic1\Downloads\runtime.dat
2014-08-01 13:43 - 2014-08-01 13:43 - 10968424 _____ (McAfee Inc) C:\Users\HomeBasic1\Downloads\stinger32(1).exe
2014-08-01 13:43 - 2014-07-10 17:28 - 00000124 ___RH () C:\Users\HomeBasic1\Downloads\Stinger.opt
2014-08-01 10:17 - 2013-08-28 18:10 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\GrabIt
2014-08-01 08:12 - 2009-07-14 06:34 - 00019760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-01 08:12 - 2009-07-14 06:34 - 00019760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-31 18:58 - 2013-08-28 18:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-07-30 13:54 - 2013-08-28 18:10 - 00000000 ____D () C:\Program Files\Biet-O-Matic
2014-07-30 09:50 - 2014-07-30 09:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-07-21 14:48 - 2013-09-18 11:49 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\vlc
2014-07-16 09:06 - 2013-12-12 09:07 - 00000000 ____D () C:\Users\HomeBasic1\Documents\Fax
2014-07-16 08:50 - 2014-03-24 15:06 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\Notepad++
2014-07-16 08:50 - 2014-03-24 15:06 - 00000000 ____D () C:\Program Files\Notepad++
2014-07-14 08:25 - 2014-07-14 07:59 - 00000000 ____D () C:\Program Files\GetSolar
2014-07-14 07:59 - 2014-07-14 07:59 - 01101165 _____ (Ing.-Büro solar energie information ) C:\Users\HomeBasic1\Downloads\gs73inst.exe
2014-07-14 07:59 - 2014-07-14 07:59 - 00000917 _____ () C:\Users\HomeBasic1\Desktop\GetSolar.lnk
2014-07-14 07:59 - 2014-07-14 07:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GetSolar
2014-07-14 07:29 - 2014-07-14 07:29 - 00002452 _____ () C:\Users\HomeBasic1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-14 07:29 - 2014-07-14 07:29 - 00002390 _____ () C:\Users\HomeBasic1\Desktop\Search.lnk
2014-07-14 07:29 - 2014-07-14 07:29 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Local\Smartbar
2014-07-14 07:29 - 2014-07-14 07:29 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Local\LPT
2014-07-14 07:29 - 2014-07-14 07:29 - 00000000 ____D () C:\Program Files\LPT
2014-07-14 07:28 - 2014-07-14 07:28 - 00001017 _____ () C:\Users\Public\Desktop\PasswdFinder.lnk
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\OpenCandy
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PasswdFinder
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\Program Files\PasswdFinder
2014-07-14 07:27 - 2014-07-14 07:27 - 04546280 _____ (PasswdFinder ) C:\Users\HomeBasic1\Downloads\Passwd25FinderInstaller.exe
2014-07-13 19:23 - 2014-07-13 19:23 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Local\Adobe
2014-07-11 10:05 - 2013-08-26 09:25 - 00000000 __SHD () C:\Recovery
2014-07-11 07:53 - 2013-09-05 20:52 - 00000000 ____D () C:\Allerlei
2014-07-11 07:44 - 2014-07-11 07:44 - 00911722 _____ () C:\Users\HomeBasic1\Downloads\bayernwerkantrge.zip
2014-07-10 15:10 - 2014-07-10 15:01 - 00000931 _____ () C:\Users\HomeBasic1\Downloads\Stinger_10072014_150139.html
2014-07-10 15:01 - 2014-07-10 14:57 - 00001039 _____ () C:\Users\HomeBasic1\Downloads\Stinger_10072014_145704.html
2014-07-10 15:00 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-10 14:58 - 2014-07-10 14:58 - 00167344 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe.f9c1.deleteme
2014-07-10 14:58 - 2014-07-10 14:58 - 00000000 ____D () C:\Quarantine
2014-07-10 14:56 - 2014-07-10 14:56 - 10959720 _____ (McAfee Inc) C:\Users\HomeBasic1\Downloads\stinger32.exe
2014-07-10 14:22 - 2013-08-26 13:46 - 00000000 ____D () C:\ProgramData\Alwil Software
2014-07-10 14:22 - 2013-08-26 13:46 - 00000000 ____D () C:\Program Files\Alwil Software
2014-07-10 14:22 - 2009-07-14 04:04 - 00002577 _____ () C:\Windows\system32\config.nt
2014-07-10 13:09 - 2013-09-11 16:40 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\TeamViewer
2014-07-10 08:42 - 2013-11-15 09:47 - 00000000 ____D () C:\Windows\rescache
2014-07-10 07:24 - 2009-07-14 06:33 - 00324536 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 07:22 - 2014-05-08 18:21 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-10 07:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-07-09 16:10 - 2013-09-11 13:52 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-09 16:10 - 2013-09-11 13:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-08 06:54 - 2013-09-06 08:00 - 00080776 _____ () C:\Windows\PFRO.log
2014-07-07 08:06 - 2014-06-21 08:45 - 00002544 _____ () C:\Windows\system32\TeamViewer9_Hooks.log
2014-07-07 08:06 - 2014-06-21 08:45 - 00001060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-07-07 08:06 - 2014-06-21 08:45 - 00001048 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk

Some content of TEMP:
====================
C:\Users\HomeBasic1\AppData\Local\Temp\AviraSetup163125.exe
C:\Users\HomeBasic1\AppData\Local\Temp\Foxit PhantomPDF Updater.exe
C:\Users\HomeBasic1\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
C:\Users\HomeBasic1\AppData\Local\Temp\fp_pl_pfs_installer.exe
C:\Users\HomeBasic1\AppData\Local\Temp\install_reader11_de_mssd_aaa_aih.exe
C:\Users\HomeBasic1\AppData\Local\Temp\npp.6.5.5.Installer.exe
C:\Users\HomeBasic1\AppData\Local\Temp\npp.6.6.7.Installer.exe
C:\Users\HomeBasic1\AppData\Local\Temp\PrefJsonCpp.exe
C:\Users\HomeBasic1\AppData\Local\Temp\sqlite3.exe
C:\Users\HomeBasic1\AppData\Local\Temp\vlc-2.1.2-win32.exe
C:\Users\HomeBasic1\AppData\Local\Temp\vlc-2.1.3-win32.exe
C:\Users\HomeBasic1\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-30 08:52

==================== End Of Log ============================

Additional
Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version:31-07-2014 02
Ran by HomeBasic1 at 2014-08-01 15:07:54
Running from C:\Users\HomeBasic1\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - )
Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
AVS Video Editor 6 (HKLM\...\AVS Video Editor_is1) (Version: 6.4.1.240 - Online Media Technologies Ltd.)
FileZilla Client 3.8.0 (HKLM\...\FileZilla Client) (Version: 3.8.0 - Tim Kosse)
FilterFTP (HKLM\...\FilterFTP_is1) (Version: Actual Version - IN MEDIA KG)
Foxit PhantomPDF (HKLM\...\{1A6F678C-BC3D-47CC-A125-713E58BED472}) (Version: 6.0.4.619 - Foxit Corporation)
Gpg4win (2.2.1) (HKLM\...\GPG4Win) (Version: 2.2.1 - The Gpg4win Project)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
K-Lite Codec Pack 8.4.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 8.4.0 - )
LibreOffice 4.2.4.2 (HKLM\...\{6B4977CB-5B9F-4B24-8310-3BA527A8AF22}) (Version: 4.2.4.2 - The Document Foundation)
LPT System Updater Service (Version: 1.0.0.0 - LPT) Hidden <==== ATTENTION
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Mozilla Firefox 31.0 (x86 de) (HKLM\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
Notepad++ (HKLM\...\Notepad++) (Version: 6.6.7 - Notepad++ Team)
Ravensburger tiptoi (HKLM\...\Ravensburger tiptoi) (Version:  - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6482 - Realtek Semiconductor Corp.)
SketchUp 2013 (HKLM\...\{2C0777B8-E91F-45AA-976B-7EB6B40E5400}) (Version: 13.0.4812 - Trimble Navigation Limited)
TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.29947 - TeamViewer)
VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version:  - Elaborate Bytes)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Yahoo Community Smartbar (HKLM\...\{3BC7022B-CDE0-4664-9AB6-E3EC25CE644A}) (Version: 11.63.66.17714 - Linkury Inc.) <==== ATTENTION
Yahoo Community Smartbar Engine (HKCU\...\{9e649bf2-763f-4c09-8f97-906d058ee513}) (Version: 11.63.66.17714 - Linkury Inc.) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

20-07-2014 13:31:38 Windows Update
21-07-2014 07:31:02 Windows-Sicherung
27-07-2014 17:38:12 Windows Update
27-07-2014 17:43:43 Windows-Sicherung
01-08-2014 06:12:25 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {2C0BEB03-9F30-4407-B5BE-6ED86B72858D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan
Task: {59920169-F6A4-46B6-965E-BA2A42104B95} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {777A30B2-6D2C-4DB1-9FA7-67BE8E3D3899} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09] (Adobe Systems Incorporated)
Task: {8BC4C4EE-5643-490F-90C0-B04B5651071C} - System32\Tasks\AviraSpeedup => C:\Program Files\Avira\AviraSpeedup\avira_system_speedup.exe
Task: {B7EFDB48-6BDB-4E9E-B752-63FCFA96E458} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2014-02-13 08:30 - 2013-10-17 17:32 - 00019448 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\TeamViewer_PrintProcessor.dll
2014-03-28 11:35 - 2014-03-28 11:35 - 00093696 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2013-10-07 16:54 - 2013-10-07 16:54 - 00218112 _____ () C:\Program Files\GNU\GnuPG\dirmngr.exe
2013-10-07 16:49 - 2013-10-07 16:49 - 00221184 _____ () C:\Program Files\GNU\GnuPG\libksba-8.dll
2013-10-07 16:47 - 2013-10-07 16:47 - 00037888 _____ () C:\Program Files\GNU\GnuPG\libgpg-error-0.dll
2013-10-07 16:44 - 2013-10-07 16:44 - 00050176 _____ () C:\Program Files\GNU\GnuPG\libw32pth-0.dll
2013-10-07 16:49 - 2013-10-07 16:49 - 00069632 _____ () C:\Program Files\GNU\GnuPG\libassuan-0.dll
2013-10-07 16:49 - 2013-10-07 16:49 - 00628224 _____ () C:\Program Files\GNU\GnuPG\libgcrypt-11.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00033560 _____ () C:\Program Files\LPT\srpts.exe
2014-06-11 15:28 - 2014-06-11 15:28 - 00043288 _____ () C:\Program Files\LPT\srptc.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00018200 _____ () C:\Program Files\LPT\Smartbar.Common.dll
2013-11-29 13:08 - 2013-07-24 10:24 - 00137728 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2012-05-31 16:35 - 2012-05-31 16:35 - 00195256 ____R () C:\Users\HomeBasic1\AppData\Roaming\DRPSu\DrvUpdater.exe
2014-06-11 15:28 - 2014-06-11 15:28 - 00045848 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00070936 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srau.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00166680 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 02337048 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00067864 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\spbl.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00156952 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00015128 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\siem.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00066840 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sppsm.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00697624 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00015640 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00079640 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00027928 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll
2014-06-11 15:29 - 2014-06-11 15:29 - 00060184 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srut.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00030488 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srsbs.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00066328 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00150296 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\smti.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00032024 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srom.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00031512 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\smtu.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00040216 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\smta.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00046872 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srbu.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00024856 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sgml.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00062744 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00025368 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srpdm.dll
2014-06-11 15:27 - 2014-06-11 15:27 - 00044312 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\MACTrackBarLib.dll
2014-06-11 15:27 - 2014-06-11 15:27 - 00025880 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00036120 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00256280 _____ () C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srns.dll
2014-06-11 15:28 - 2014-06-11 15:28 - 00035608 _____ () C:\Program Files\LPT\srptsl.exe
2014-06-11 15:29 - 2014-06-11 15:29 - 00060184 _____ () C:\Program Files\LPT\srut.dll
2014-07-30 09:50 - 2014-07-30 09:50 - 03800688 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2014-07-09 16:10 - 2014-07-09 16:10 - 17029808 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


==================== Faulty Device Manager Devices =============

Name: PS/2-kompatible Maus
Description: PS/2-kompatible Maus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Standardtastatur (PS/2)
Description: Standardtastatur (PS/2)
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtastaturen)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================

Error: (07/24/2014 11:00:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: TeamViewer_Service.exe, Version: 9.0.29947.0, Zeitstempel: 0x53b3d40e
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x5c692549
ID des fehlerhaften Prozesses: 0x15fc
Startzeit der fehlerhaften Anwendung: 0xTeamViewer_Service.exe0
Pfad der fehlerhaften Anwendung: TeamViewer_Service.exe1
Pfad des fehlerhaften Moduls: TeamViewer_Service.exe2
Berichtskennung: TeamViewer_Service.exe3

Error: (07/24/2014 11:00:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: TeamViewer_Service.exe, Version: 9.0.29947.0, Zeitstempel: 0x53b3d40e
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x5c692549
ID des fehlerhaften Prozesses: 0x944
Startzeit der fehlerhaften Anwendung: 0xTeamViewer_Service.exe0
Pfad der fehlerhaften Anwendung: TeamViewer_Service.exe1
Pfad des fehlerhaften Moduls: TeamViewer_Service.exe2
Berichtskennung: TeamViewer_Service.exe3

Error: (07/21/2014 10:04:24 AM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)"

Error: (07/14/2014 07:28:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 30.0.0.5269, Zeitstempel: 0x53914233
Name des fehlerhaften Moduls: mozalloc.dll, Version: 30.0.0.5269, Zeitstempel: 0x53911393
Ausnahmecode: 0x80000003
Fehleroffset: 0x0000141b
ID des fehlerhaften Prozesses: 0xe90
Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0
Pfad der fehlerhaften Anwendung: plugin-container.exe1
Pfad des fehlerhaften Moduls: plugin-container.exe2
Berichtskennung: plugin-container.exe3

Error: (07/11/2014 08:20:38 AM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Die Sicherung war nicht erfolgreich. Fehler: "Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)"

Error: (07/11/2014 07:13:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: taskhost.exe, Version: 6.1.7601.18010, Zeitstempel: 0x50aee407
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x69f82549
ID des fehlerhaften Prozesses: 0x610
Startzeit der fehlerhaften Anwendung: 0xtaskhost.exe0
Pfad der fehlerhaften Anwendung: taskhost.exe1
Pfad des fehlerhaften Moduls: taskhost.exe2
Berichtskennung: taskhost.exe3

Error: (07/11/2014 07:13:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: RtHDVCpl.exe, Version: 1.0.0.738, Zeitstempel: 0x4e9bd2dc
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x69f82549
ID des fehlerhaften Prozesses: 0x6d8
Startzeit der fehlerhaften Anwendung: 0xRtHDVCpl.exe0
Pfad der fehlerhaften Anwendung: RtHDVCpl.exe1
Pfad des fehlerhaften Moduls: RtHDVCpl.exe2
Berichtskennung: RtHDVCpl.exe3

Error: (07/10/2014 01:09:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17567, Zeitstempel: 0x4d6727a7
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x5eaa2549
ID des fehlerhaften Prozesses: 0x9b4
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3

Error: (07/10/2014 01:09:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: TeamViewer.exe, Version: 9.0.29947.0, Zeitstempel: 0x53b3d3c5
Name des fehlerhaften Moduls: unknown, Version: 0.0.0.0, Zeitstempel: 0x00000000
Ausnahmecode: 0xc0000005
Fehleroffset: 0x5eaa2549
ID des fehlerhaften Prozesses: 0x9a8
Startzeit der fehlerhaften Anwendung: 0xTeamViewer.exe0
Pfad der fehlerhaften Anwendung: TeamViewer.exe1
Pfad des fehlerhaften Moduls: TeamViewer.exe2
Berichtskennung: TeamViewer.exe3


System errors:
=============
Error: (08/01/2014 03:04:03 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FCFE987F-0BD3-4668-AD1A-00C2C4CCCA-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (08/01/2014 01:44:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Dienst "Adobe Acrobat Update Service" wurde unerwartet beendet. Dies ist bereits 1 Mal passiert.

Error: (08/01/2014 08:09:14 AM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FCFE987F-0BD3-4668-AD1A-00C2C4CCCA-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (07/31/2014 07:04:59 PM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FCFE987F-0BD3-4668-AD1A-00C2C4CCCA-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (07/31/2014 07:42:04 AM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FCFE987F-0BD3-4668-AD1A-00C2C4CCCA-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (07/30/2014 08:25:25 AM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FCFE987F-0BD3-4668-AD1A-00C2C4CCCA-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (07/30/2014 08:22:34 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎30.‎07.‎2014 um 08:15:40 unerwartet heruntergefahren.

Error: (07/30/2014 07:34:20 AM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FCFE987F-0BD3-4668-AD1A-00C2C4CCCA-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (07/29/2014 06:58:50 AM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FCFE987F-0BD3-4668-AD1A-00C2C4CCCA-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.

Error: (07/28/2014 07:23:35 AM) (Source: bowser) (EventID: 8003) (User: )
Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "EASYBOX",
der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{FCFE987F-0BD3-4668-AD1A-00C2C4CCCA-Transport zu sein scheint.
Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen.


Microsoft Office Sessions:
=========================
Error: (07/31/2014 07:16:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GrabIt.exe1.7.2.100800000000unknown0.0.0.000000000000000000000000013bc01cface299d774d8C:\Program Files\GrabIt\GrabIt.exeunknown5d632ef0-18d6-11e4-9e0a-001635669cca

Error: (07/24/2014 11:00:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: TeamViewer_Service.exe9.0.29947.053b3d40eunknown0.0.0.000000000c00000055c69254915fc01cfa71dbbdb0d84C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exeunknownfd40f9b3-1310-11e4-9944-001635669cca

Error: (07/24/2014 11:00:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: TeamViewer_Service.exe9.0.29947.053b3d40eunknown0.0.0.000000000c00000055c69254994401cfa70bb1376078C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exeunknownf7133796-1310-11e4-9944-001635669cca

Error: (07/21/2014 10:04:24 AM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)

Error: (07/14/2014 07:28:40 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe30.0.0.526953914233mozalloc.dll30.0.0.526953911393800000030000141be9001cf9f23dc7f43ddC:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dllb5db800d-0b17-11e4-81f5-001635669cca

Error: (07/11/2014 08:20:38 AM) (Source: Windows Backup) (EventID: 4104) (User: )
Description: Auf diesem Laufwerk ist nicht genügend Speicherplatz zum Speichern der Sicherung verfügbar. Löschen Sie ältere Sicherungen und nicht benötigte Daten, um Speicherplatz freizugeben, oder ändern Sie die Sicherungseinstellungen. (0x81000005)

Error: (07/11/2014 07:13:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: taskhost.exe6.1.7601.1801050aee407unknown0.0.0.000000000c000000569f8254961001cf9cc698aef336C:\Windows\system32\taskhost.exeunknown1c929e3a-08ba-11e4-a31b-001635669cca

Error: (07/11/2014 07:13:30 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: RtHDVCpl.exe1.0.0.7384e9bd2dcunknown0.0.0.000000000c000000569f825496d801cf9cc69bd00956C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exeunknown182d2224-08ba-11e4-a31b-001635669cca

Error: (07/10/2014 01:09:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Explorer.EXE6.1.7601.175674d6727a7unknown0.0.0.000000000c00000055eaa25499b401cf9bff7b527140C:\Windows\Explorer.EXEunknowna7766c54-0822-11e4-b11c-001635669cca

Error: (07/10/2014 01:09:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: TeamViewer.exe9.0.29947.053b3d3c5unknown0.0.0.000000000c00000055eaa25499a801cf9bff7b500ee6C:\Program Files\TeamViewer\Version9\TeamViewer.exeunknowna00c7656-0822-11e4-b11c-001635669cca


==================== Memory info ===========================

Percentage of memory in use: 40%
Total physical RAM: 3063.43 MB
Available physical RAM: 1818.41 MB
Total Pagefile: 6125.14 MB
Available Pagefile: 4770.54 MB
Total Virtual: 2047.88 MB
Available Virtual: 1905 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:74.43 GB) (Free:26.29 GB) NTFS
Drive d: () (Fixed) (Total:37.26 GB) (Free:9.73 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 37 GB) (Disk ID: 00079FFC)
Partition 1: (Active) - (Size=37 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 75 GB) (Disk ID: E21F6652)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=74 GB) - (Type=07 NTFS)

==================== End Of Log ============================

GMER
Code:

GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-08-01 15:28:08
Windows 6.1.7601 Service Pack 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP2T0L0-2 ST380819AS rev.3.04 74,53GB
Running: Gmer-19357.exe; Driver: C:\Users\HOMEBA~1\AppData\Local\Temp\kwtirpob.sys


---- Kernel code sections - GMER 2.1 ----

.text  ntkrnlpa.exe!ZwRollbackEnlistment + 142D                                                                              82C55A15 1 Byte  [06]
.text  ntkrnlpa.exe!KiDispatchInterrupt + 5A2                                                                                82C8F212 19 Bytes  [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}

---- User IAT/EAT - GMER 2.1 ----

IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                      [73F7249F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                  [73F55652] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                [73F55710] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                        [73F7251A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                              [73F6857E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                [73F64D32] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                              [73F650D9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                              [73F651AE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP]                    [73F666DB] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                              [73F682D5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                          [73F68824] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                        [73F69085] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                              [73F6E228] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll
IAT    C:\Windows\Explorer.EXE[1764] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                  [73F64C64] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18455_none_72d576ad8665e853\gdiplus.dll

---- Registry - GMER 2.1 ----

Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                     
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                  C:\Program Files\Alcohol Soft\Alcohol 120\
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                  0
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                0x10 0xA1 0xB3 0x52 ...
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                           
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                          0xA0 0x02 0x00 0x00 ...
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                      0xB5 0x67 0xAF 0x58 ...
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40                     
Reg    HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                0x8C 0xC0 0xC4 0x8A ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)                 
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                      C:\Program Files\Alcohol Soft\Alcohol 120\
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                      0
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                    0x10 0xA1 0xB3 0x52 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)       
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                              0xA0 0x02 0x00 0x00 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                          0xB5 0x67 0xAF 0x58 ...
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet) 
Reg    HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                    0x8C 0xC0 0xC4 0x8A ...

---- EOF - GMER 2.1 ----

Danke schon mal im voraus
Thomas

cosinus 01.08.2014 15:02

Hallo und :hallo:

Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden?

Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520

Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten!
Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht!





Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

TOMROSSI 01.08.2014 15:06

Hi
nur den vom Stinger

Code:

McAfee® Labs Stinger™ Version 12.1.0.1015 built on Aug  1 2014 at 13:53:20
Copyright© 2014, McAfee, Inc. All Rights Reserved.

AV Engine version v5700.7147 for Windows.
Virus data file v1000.0 created on Aug 1, 2014
Ready to scan for 6351 viruses, trojans and variants.

Scan initiated on Freitag, August 01, 2014 13:44:33

C:\Windows\System32\Microsoft.com is infected with Artemis!B5E07021F4DB

Rootkit scan result : Infected.



Summary Report on Smart Scan
File(s)
        TotalFiles:............        20784
        Clean:.................        15282
        Not Scanned:........... 5501
        Possibly Infected:.....        1

Time: 00:28:16

Scan completed on Freitag, August 01, 2014 14:12:49


cosinus 01.08.2014 15:08

Dann bitte jetzt Combofix ausführen:

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


TOMROSSI 01.08.2014 15:37

Problem, ich hab Combofix auf den Desktop gelegt und gestartet, kurz danach kam eine Explorer.exe Meldung...Problem wird gesucht....Explorer.exe hat sich dann verabschiedet und jetzt kann ich die Comofix nicht mehr herunterladen bzw umbenennen, löschen...strange

cosinus 01.08.2014 15:44

Rechner neustarten und nochmal probieren

TOMROSSI 01.08.2014 16:42

Neu abgespeichert, nachdem ich im abgesicherten Modus das File gelöscht hatte, habs mehmals versucht zu starten, dreht kurz die Sanduhr und dann passiert nix mehr

cosinus 01.08.2014 22:14

Ok, hab da schon so eine Idee. Kannst du die combofix.exe auf dem Desktop umbenennen? In irgendwas, meinetwegen tb.exe - wenn ja mach das mal und führ dann das in tb.exe umbenannte Combofix aus.

TOMROSSI 03.08.2014 19:29

Log vom ComboFix

Code:

ComboFix 14-08-02.02 - HomeBasic1 03.08.2014  19:42:47.1.2 - x86
Microsoft Windows 7 Ultimate  6.1.7601.1.1252.49.1031.18.3063.1974 [GMT 2:00]
ausgeführt von:: c:\users\HomeBasic1\Desktop\tb.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((  Dateien erstellt von 2014-07-03 bis 2014-08-03  ))))))))))))))))))))))))))))))
.
.
2014-08-03 18:15 . 2014-08-03 18:15        --------        d-----w-        c:\users\Default\AppData\Local\temp
2014-08-03 17:48 . 2014-08-03 17:48        62576        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{333A3794-CC42-4D8C-8A41-FC445C32EB48}\offreg.dll
2014-08-01 14:52 . 2014-08-01 14:52        --------        d--h--w-        c:\windows\PIF
2014-08-01 13:04 . 2014-08-01 13:08        --------        d-----w-        C:\FRST
2014-08-01 06:14 . 2014-07-14 02:12        8217224        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{333A3794-CC42-4D8C-8A41-FC445C32EB48}\mpengine.dll
2014-07-14 05:59 . 2014-07-14 06:25        --------        d-----w-        c:\program files\GetSolar
2014-07-14 05:29 . 2014-07-14 05:29        --------        d-----w-        c:\program files\LPT
2014-07-14 05:29 . 2014-07-14 05:29        --------        d-----w-        c:\users\HomeBasic1\AppData\Local\LPT
2014-07-14 05:29 . 2014-07-14 05:29        --------        d-----w-        c:\users\HomeBasic1\AppData\Local\Smartbar
2014-07-14 05:28 . 2014-07-14 05:28        --------        d-----w-        c:\program files\PasswdFinder
2014-07-14 05:28 . 2014-07-14 05:28        --------        d-----w-        c:\users\HomeBasic1\AppData\Roaming\OpenCandy
2014-07-14 05:27 . 2014-07-14 05:27        --------        d-----w-        c:\users\HomeBasic1\AppData\Local\Programs
2014-07-13 17:23 . 2014-07-13 17:23        --------        d-----w-        c:\users\HomeBasic1\AppData\Local\Adobe
2014-07-10 12:58 . 2014-07-10 12:58        167344        ----a-w-        c:\windows\system32\mfevtps.exe.f9c1.deleteme
2014-07-10 12:58 . 2014-07-10 12:58        --------        d-----w-        C:\Quarantine
2014-07-10 12:56 . 2014-08-01 11:58        --------        d-----w-        c:\program files\stinger
2014-07-10 11:08 . 2014-05-24 12:17        445952        --sha-r-        c:\windows\system32\Microsoft.com
2014-07-10 11:08 . 2014-08-03 18:16        --------        d-sh--w-        c:\program files\Windows Manager
2014-07-09 07:55 . 2014-06-18 23:56        4096        ----a-w-        c:\windows\system32\ieetwcollectorres.dll
2014-07-09 07:54 . 2014-05-30 07:52        172032        ----a-w-        c:\windows\system32\wdigest.dll
2014-07-09 07:54 . 2014-05-30 07:52        65536        ----a-w-        c:\windows\system32\TSpkg.dll
2014-07-09 07:54 . 2014-05-30 07:52        247808        ----a-w-        c:\windows\system32\schannel.dll
2014-07-09 07:54 . 2014-05-30 07:52        220160        ----a-w-        c:\windows\system32\ncrypt.dll
2014-07-09 07:54 . 2014-05-30 07:52        259584        ----a-w-        c:\windows\system32\msv1_0.dll
2014-07-09 07:54 . 2014-05-30 07:52        550912        ----a-w-        c:\windows\system32\kerberos.dll
2014-07-09 07:54 . 2014-05-30 07:52        17408        ----a-w-        c:\windows\system32\credssp.dll
2014-07-09 07:54 . 2014-06-30 01:40        404480        ----a-w-        c:\windows\system32\aepdu.dll
2014-07-09 07:54 . 2014-06-30 01:36        302592        ----a-w-        c:\windows\system32\aeinv.dll
2014-07-09 07:54 . 2014-06-05 14:26        1059840        ----a-w-        c:\windows\system32\lsasrv.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-09 14:10 . 2013-09-11 11:52        71344        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2014-07-09 14:10 . 2013-09-11 11:52        699056        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2014-05-08 09:06 . 2014-06-12 06:59        2742784        ----a-w-        c:\windows\system32\rdpcorets.dll
2014-05-08 09:06 . 2014-06-12 06:59        13824        ----a-w-        c:\windows\system32\RdpGroupPolicyExtension.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DrvUpdater"="c:\users\HomeBasic1\AppData\Roaming\DRPSu\DrvUpdater.exe" [2012-05-31 195256]
"Browser Infrastructure Helper"="c:\users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.exe" [2014-06-11 28952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"Wondershare Helper Compact.exe"="c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2013-07-25 1985824]
"DelaypluginInstall"="c:\programdata\Wondershare\Player\DelayPluginI.exe" [2013-09-28 1960008]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-10-17 11430504]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-09-05 280576]
"WindowsUpdate"="c:\windows\system32\Microsoft.com" [2014-05-24 445952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvastSvc.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvastUI.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avcenter.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avconfig.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgcsrvx.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgidsagent.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgnt.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgrsx.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avguard.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgui.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgwdsvc.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avscan.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdagent.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccuac.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ComboFix.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\egui.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\hijackthis.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\instup.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\keyscrambler.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbam.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbamgui.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbampt.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbamscheduler.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbamservice.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MpCmdRun.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MSASCui.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MsMpEng.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\msseces.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\spybotsd.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\wireshark.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\zlclient.exe]
"Debugger"=c:\windows\system32\Microsoft.com
.
R2 AxAutoMntSrv;Alcohol Virtual Drive Auto-mount Service;c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2012-01-05 75624]
R2 DirMngr;DirMngr;c:\program files\GNU\GnuPG\dirmngr.exe [2013-10-07 218112]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-06-18 108032]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S2 LPTSystemUpdater;LPT System Updater Service;c:\program files\LPT\srpts.exe [2014-06-11 33560]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2014-07-02 5037888]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2013-06-06 25088]
.
.
Inhalt des "geplante Tasks" Ordners
.
2014-08-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-11 14:10]
.
Supplementary scan did not complete!
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
ShellIconOverlayIdentifiers-{F4B3B0AA-13D1-4a36-BDA2-2055B0F3D5DE} - c:\program files\Alwil Software\Avast5\snxPlugins.dll
HKCU-Run-AviraSpeedup - c:\program files\Avira\AviraSpeedup\avira_system_speedup.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows NT\CurrentVersion\Windows]
@Denied: (A C D 2 3) (Everyone)
"UserSelectedDefault"=dword:00000001
"Device"="Canon MP500 Series Printer,winspool,Ne04:"
"Load"="c:\\Windows\\system32\\Microsoft.com"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-08-03  20:19:47
ComboFix-quarantined-files.txt  2014-08-03 18:19
.
Vor Suchlauf: 8 Verzeichnis(se), 30.601.134.080 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 32.792.059.904 Bytes frei
.
- - End Of File - - D077A49CF21E01A9D3B278B9DBD66A66
A36C5E4F47E84449FF07ED3517B43A31


cosinus 03.08.2014 20:29

Ok, dann scripten wir mal, aber ich poste hier eine Standardanleitung, der der davon ausgegangen wird, das Combofix auch Combofix.exe heißt und nicht tb.exe in deinem Fall, denk dir einfach statt combofix.exe stünde da tb.exe :)


Combofix-Skript
WARNUNG für die MITLESER:
Folgendes ComboFix Skript ist ausschließlich für diesen User in dieser Situtation erstellt worden.
Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!

  • Lösche die vorhandene Combofix.exe von deinem Desktop und lade das Programm von folgenden Download-Spiegel neu herunter: Link
  • Speichere es erneut auf dem Desktop (nicht woanders hin, das ist wichtig)!
  • Drücke die Windows + R Taste --> notepad (hinein schreiben) --> OK
  • Kopiere nun den Text aus der folgenden Codebox komplett in das leere Textdokument.
    Code:

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvastSvc.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\AvastUI.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avcenter.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avconfig.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgcsrvx.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgidsagent.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgnt.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgrsx.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avguard.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgui.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avgwdsvc.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avp.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\avscan.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\bdagent.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ccuac.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\ComboFix.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\egui.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\hijackthis.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\instup.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\keyscrambler.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbam.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbamgui.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbampt.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbamscheduler.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\mbamservice.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MpCmdRun.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MSASCui.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\MsMpEng.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\msseces.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\spybotsd.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\wireshark.exe]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\zlclient.exe]

    File::
    c:\windows\system32\Microsoft.com

  • Speichere dies als CFScript.txt auf deinem Desktop.
  • Wichtig: Stelle deine Anti Viren Software temporär ab. Dies kann ComboFix nämlich bei der Arbeit behindern.
    Danach wieder anstellen nicht vergessen!
  • Schließe alle laufenden Programme damit ComboFix ungehindert arbeiten kann.
  • Ziehe CFScript.txt in die ComboFix.exe wie in diesem Bild:
  • Mache nichts am Computer, bewege nicht die Maus über das ComboFix-Fenster oder klicke in dieses hinein. Dies kann dazu führen, dass ComboFix sich aufhängt.
  • Wenn ComboFix fertig ist wird es ein Log erstellen: C:\ComboFix.txt
    Bitte füge es hier als Antwort (in CODE-Tags mit dem #-Button des Editors) ein.

Hinweis:
Suspect:: und Collect::
Falls im Skript diese Anweisungen enthalten sind, sollen Dateien zur Analyse eingeschickt werden. Es erscheint eine Message-Box, nachdem Combofix fertig ist. Klicke OK und folge den Aufforderungen/Anweisungen, um die Dateien hochzuladen. Teile mir unbedingt mit, ob der Upload geklappt hat!


TOMROSSI 04.08.2014 09:07

ComboFix mit Textdatei
Code:

ComboFix 14-08-02.02 - HomeBasic1 04.08.2014  9:55.3.2 - x86
Microsoft Windows 7 Ultimate  6.1.7601.1.1252.49.1031.18.3063.2138 [GMT 2:00]
ausgeführt von:: c:\users\HomeBasic1\Desktop\tb.exe
Benutzte Befehlsschalter :: c:\users\HomeBasic1\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
FILE ::
"c:\windows\system32\Microsoft.com"
.
.
(((((((((((((((((((((((  Dateien erstellt von 2014-07-04 bis 2014-08-04  ))))))))))))))))))))))))))))))
.
.
2014-08-04 08:02 . 2014-08-04 08:02        --------        d-----w-        c:\users\Default\AppData\Local\temp
2014-08-03 17:48 . 2014-08-03 17:48        62576        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{333A3794-CC42-4D8C-8A41-FC445C32EB48}\offreg.dll
2014-08-01 14:52 . 2014-08-01 14:52        --------        d--h--w-        c:\windows\PIF
2014-08-01 13:04 . 2014-08-01 13:08        --------        d-----w-        C:\FRST
2014-08-01 06:14 . 2014-07-14 02:12        8217224        ----a-w-        c:\programdata\Microsoft\Windows Defender\Definition Updates\{333A3794-CC42-4D8C-8A41-FC445C32EB48}\mpengine.dll
2014-07-14 05:59 . 2014-07-14 06:25        --------        d-----w-        c:\program files\GetSolar
2014-07-14 05:29 . 2014-07-14 05:29        --------        d-----w-        c:\program files\LPT
2014-07-14 05:29 . 2014-07-14 05:29        --------        d-----w-        c:\users\HomeBasic1\AppData\Local\LPT
2014-07-14 05:29 . 2014-07-14 05:29        --------        d-----w-        c:\users\HomeBasic1\AppData\Local\Smartbar
2014-07-14 05:28 . 2014-07-14 05:28        --------        d-----w-        c:\program files\PasswdFinder
2014-07-14 05:28 . 2014-07-14 05:28        --------        d-----w-        c:\users\HomeBasic1\AppData\Roaming\OpenCandy
2014-07-14 05:27 . 2014-07-14 05:27        --------        d-----w-        c:\users\HomeBasic1\AppData\Local\Programs
2014-07-13 17:23 . 2014-07-13 17:23        --------        d-----w-        c:\users\HomeBasic1\AppData\Local\Adobe
2014-07-10 12:58 . 2014-07-10 12:58        167344        ----a-w-        c:\windows\system32\mfevtps.exe.f9c1.deleteme
2014-07-10 12:58 . 2014-07-10 12:58        --------        d-----w-        C:\Quarantine
2014-07-10 12:56 . 2014-08-01 11:58        --------        d-----w-        c:\program files\stinger
2014-07-10 11:08 . 2014-05-24 12:17        445952        --sha-r-        c:\windows\system32\Microsoft.com
2014-07-10 11:08 . 2014-08-04 06:40        --------        d-sh--w-        c:\program files\Windows Manager
2014-07-09 07:55 . 2014-06-18 23:56        4096        ----a-w-        c:\windows\system32\ieetwcollectorres.dll
2014-07-09 07:54 . 2014-05-30 07:52        172032        ----a-w-        c:\windows\system32\wdigest.dll
2014-07-09 07:54 . 2014-05-30 07:52        65536        ----a-w-        c:\windows\system32\TSpkg.dll
2014-07-09 07:54 . 2014-05-30 07:52        247808        ----a-w-        c:\windows\system32\schannel.dll
2014-07-09 07:54 . 2014-05-30 07:52        220160        ----a-w-        c:\windows\system32\ncrypt.dll
2014-07-09 07:54 . 2014-05-30 07:52        259584        ----a-w-        c:\windows\system32\msv1_0.dll
2014-07-09 07:54 . 2014-05-30 07:52        550912        ----a-w-        c:\windows\system32\kerberos.dll
2014-07-09 07:54 . 2014-05-30 07:52        17408        ----a-w-        c:\windows\system32\credssp.dll
2014-07-09 07:54 . 2014-06-30 01:40        404480        ----a-w-        c:\windows\system32\aepdu.dll
2014-07-09 07:54 . 2014-06-30 01:36        302592        ----a-w-        c:\windows\system32\aeinv.dll
2014-07-09 07:54 . 2014-06-05 14:26        1059840        ----a-w-        c:\windows\system32\lsasrv.dll
.
.
.
((((((((((((((((((((((((((((((((((((  Find3M Bericht  ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-09 14:10 . 2013-09-11 11:52        71344        ----a-w-        c:\windows\system32\FlashPlayerCPLApp.cpl
2014-07-09 14:10 . 2013-09-11 11:52        699056        ----a-w-        c:\windows\system32\FlashPlayerApp.exe
2014-05-08 09:06 . 2014-06-12 06:59        2742784        ----a-w-        c:\windows\system32\rdpcorets.dll
2014-05-08 09:06 . 2014-06-12 06:59        13824        ----a-w-        c:\windows\system32\RdpGroupPolicyExtension.dll
.
.
((((((((((((((((((((((((((((  Autostartpunkte der Registrierung  ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DrvUpdater"="c:\users\HomeBasic1\AppData\Roaming\DRPSu\DrvUpdater.exe" [2012-05-31 195256]
"Browser Infrastructure Helper"="c:\users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.exe" [2014-06-11 28952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-23 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-23 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-23 150552]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"Wondershare Helper Compact.exe"="c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2013-07-25 1985824]
"DelaypluginInstall"="c:\programdata\Wondershare\Player\DelayPluginI.exe" [2013-09-28 1960008]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-10-17 11430504]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-09-05 280576]
"WindowsUpdate"="c:\program files\Windows Manager\winmgr.exe" [2014-05-24 445952]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 AxAutoMntSrv;Alcohol Virtual Drive Auto-mount Service;c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2012-01-05 75624]
R2 DirMngr;DirMngr;c:\program files\GNU\GnuPG\dirmngr.exe [2013-10-07 218112]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-06-18 108032]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys [x]
R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S2 LPTSystemUpdater;LPT System Updater Service;c:\program files\LPT\srpts.exe [2014-06-11 33560]
S2 TeamViewer9;TeamViewer 9;c:\program files\TeamViewer\Version9\TeamViewer_Service.exe [2014-07-02 5037888]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\DRIVERS\teamviewervpn.sys [2013-06-06 25088]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
Inhalt des "geplante Tasks" Ordners
.
2014-08-04 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-11 14:10]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voCiIS4l2kPC6yMc5xXI0YFNPjL2B-TJeKRQ8aYnONf06D_mc32csI8rWgu3CwrJBrb3V_Hqh7YwbkwBQoXe3H6JQmr_eBahg,,
mStart Page = about:blank
uSearchAssistant = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}
Trusted Zone: com\*.Wondershare
TCP: DhcpNameServer = 192.168.2.15
FF - ProfilePath - c:\users\HomeBasic1\AppData\Roaming\Mozilla\Firefox\Profiles\m91r75y2.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-AVS Video Editor_is1 - c:\program files\AVS4YOU\AVSVideoEditor\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows NT\CurrentVersion\Windows]
@Denied: (A C D 2 3) (Everyone)
"UserSelectedDefault"=dword:00000001
"Device"="Canon MP500 Series Printer,winspool,Ne04:"
"Load"="c:\\Windows\\system32\\Microsoft.com"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-08-04  10:04:27
ComboFix-quarantined-files.txt  2014-08-03 18:19
.
Vor Suchlauf: 10 Verzeichnis(se), 31.715.676.160 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 31.701.282.816 Bytes frei
.
- - End Of File - - D48AC03D1A496F03A861B4F39E1BA903
A36C5E4F47E84449FF07ED3517B43A31


cosinus 04.08.2014 09:46

Adware/Junkware/Toolbars entfernen

1. Schritt: Malwarebytes

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




2. Schritt: adwCleaner

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).



3. Schritt: JRT - Junkware Removal Tool

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.




4. Schritt: Frisches Log mit FRST

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)


TOMROSSI 04.08.2014 19:59

Hi
hab den Scan mitendrin abgebrochen und danach wieder gestrtet,deshalb 2 logs vom Malware

cosinus 04.08.2014 21:07

Lesestoff:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit.
Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten.
Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.
http://www.trojaner-board.de/picture...&pictureid=307

TOMROSSI 05.08.2014 06:23

Ok sorry, das System sagt eben genau das, ein Archiv anhängen, weil zu groß

Malware log1.1
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 04.08.2014
Suchlauf-Zeit: 10:59:08
Logdatei: 1telog_Mailware.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.08.04.02
Rootkit Datenbank: v2014.08.01.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: HomeBasic1

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgebrochen
Durchsuchte Objekte: 277200
Verstrichene Zeit: 1 Std, 11 Min, 50 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 2
PUP.Optional.Linkury.A, C:\Program Files\LPT\srpts.exe, 1912, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898]
PUP.Optional.Linkury.A, C:\Program Files\LPT\srptsl.exe, 2432, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898]

Module: 9
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Common.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Common.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Communication.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Communication.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Communication.NamedPipe.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Communication.NamedPipe.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srptc.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srptc.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srut.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],

Registrierungsschlüssel: 8
PUP.Optional.Snapdo.T, HKU\S-1-5-21-2801197354-4021152197-1246408157-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [5b373a88394286b0f02f4d51c93914ec],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [5b373a88394286b0f02f4d51c93914ec],
PUP.Optional.QuickShare.A, HKLM\SOFTWARE\CLASSES\IESmartBar.BHO, In Quarantäne, [dbb73191473493a30431d5c5d72b41bf],
PUP.Optional.Linkury.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\LPTSystemUpdater, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{3BC7022B-CDE0-4664-9AB6-E3EC25CE644A}, In Quarantäne, [2c6610b20675f244d156a832f11128d8],
PUP.Optional.Linkury.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}, In Quarantäne, [dbb7a81a106b290d2b815a88cc36ab55],
PUP.Optional.SmartBar, HKU\S-1-5-21-2801197354-4021152197-1246408157-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SmartbarBackup, In Quarantäne, [a4ee6f53700b8da990b68c9e22e223dd],
PUP.Optional.SmartBar, HKU\S-1-5-21-2801197354-4021152197-1246408157-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SmartbarLog, In Quarantäne, [f69cc8fa81fa0a2c66df0525c440956b],

Registrierungswerte: 6
Backdoor.RNDICN.Gen, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WindowsUpdate, "C:\Program Files\Windows Manager\winmgr.exe", In Quarantäne, [d8ba19a92a51a88e80d79af156abb34d]
Backdoor.RNDICN.Gen, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|WindowsUpdate, "C:\Program Files\Windows Manager\winmgr.exe", In Quarantäne, [d8ba19a92a51a88e80d79af156abb34d]
PUP.Optional.Linkury.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\LPTSYSTEMUPDATER|ImagePath, "C:\Program Files\LPT\srpts.exe", In Quarantäne, [761c378b35460234d53ac333ca385ca4]
Backdoor.Agent, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|Load, C:\Windows\system32\Microsoft.com, In Quarantäne, [ccc607bb8cefda5ceecc2bbec9395da3]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-2801197354-4021152197-1246408157-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [e5ad18aa78033006e556a52f15ed5aa6]
PUP.Optional.SmartBar.A, HKU\S-1-5-21-2801197354-4021152197-1246408157-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Browser Infrastructure Helper, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.exe startup, In Quarantäne, [ddb59f23e695f83ed2dbab6561a34fb1]

Registrierungsdaten: 1
Backdoor.RNDICN.Gen, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|Load, C:\Windows\system32\Microsoft.com, Gut: (), Schlecht: (C:\Windows\system32\Microsoft.com),Ersetzt,[dcb6be041f5c79bd9dba73186d9404fc]

Ordner: 41
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT, Löschen bei Neustart, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Configs, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Resources, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Program Files\LPT, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Configs, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Resources, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\CSS, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\ar, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Configs, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\de, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\es, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\fr, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\he, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\it, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\nl, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\pt, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\ru, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\tr, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\Configs, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\ServicesPlugins, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\Configs, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\Profiles, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\RollBack, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\RollBack\Profiles, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.OpenCandy, C:\Users\HomeBasic1\AppData\Roaming\OpenCandy, In Quarantäne, [a0f2cbf793e847ef9c5ab5f8ea18ab55],
PUP.Optional.OpenCandy, C:\Users\HomeBasic1\AppData\Roaming\OpenCandy\6A9D40B086844E0A8E9E5C8BA52AA651, In Quarantäne, [a0f2cbf793e847ef9c5ab5f8ea18ab55],

Mailware log 1.2
Code:

Dateien: 988
Backdoor.RNDICN.Gen, C:\Program Files\Windows Manager\winmgr.exe, In Quarantäne, [d8ba19a92a51a88e80d79af156abb34d],
Backdoor.RNDICN.Gen, C:\Windows\System32\Microsoft.com, In Quarantäne, [dcb6be041f5c79bd9dba73186d9404fc],
Hacktool.Agent, C:\Users\HomeBasic1\Downloads\Windows_Loader_v2.2.1.zip, In Quarantäne, [0d858939b8c3280e2b5a6ee5fa07e818],
PUP.Optional.SnapDo.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\BrowserHelper.exe, In Quarantäne, [b5dd2c9629525fd736260588dc25e719],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe, In Quarantäne, [e2b0e6dca2d9bc7a68913bec0af66f91],
PUP.Optional.SnapDo.A, C:\Windows\Installer\b3894.msi, In Quarantäne, [4151dee47902ce685408d9b4d62b41bf],
PUP.Optional.WebSearch.A, C:\Users\HomeBasic1\AppData\Roaming\Mozilla\Firefox\Profiles\m91r75y2.default\searchplugins\Web Search.xml, In Quarantäne, [553d5d65f9828caa5da100f1679b07f9],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\PublisherSettings.xml, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\sppsm.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\linmsl.exe, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\LPTInstaller.msi, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\lrrot.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\NewConfig.txt, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Newtonsoft.Json.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Proxy.Lib.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\ProxySettings.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Smartbar.Common.dll, Löschen bei Neustart, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Smartbar.Communication.dll, Löschen bei Neustart, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Smartbar.Communication.NamedPipe.dll, Löschen bei Neustart, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Smartbar.Infrastructure.Utilities.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Smartbar.Monetization.Proxy.ProxyRemover.exe, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Smartbar.Monetization.Proxy.ProxyService.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Smartbar.Personalization.Common.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\spusm.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srbs.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srbu.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\sreu.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srpdm.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srprl.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srpt.dll, Löschen bei Neustart, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srptc.dll, Löschen bei Neustart, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srptm.exe, Löschen bei Neustart, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srptm.exe.config, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srptsl.exe, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srptsl.exe.config, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\srut.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\UserSettings.xml, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\XMLOperations.xml, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Configs\BrowserSettings.xml, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Configs\LPTMapping.xml, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Configs\Timers.xml, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Resources\LPT.xml, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Resources\ntdis_32.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Users\HomeBasic1\AppData\Local\LPT\Resources\ntdis_64.dll, In Quarantäne, [1979f5cd06759a9c8884d0267b8739c7],
PUP.Optional.Linkury.A, C:\Program Files\LPT\PublisherSettings.xml, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Common.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\sreu.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\linmsl.exe, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\LPTInstaller.msi, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\lrrot.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\NewConfig.txt, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Newtonsoft.Json.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Proxy.Lib.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\ProxySettings.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Communication.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Communication.NamedPipe.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Infrastructure.Utilities.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Monetization.Proxy.ProxyRemover.exe, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Monetization.Proxy.ProxyService.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Personalization.Common.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\sppsm.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\spusm.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srbs.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srbu.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srpdm.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srprl.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srpt.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srptc.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srptm.exe, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srptm.exe.config, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srpts.exe, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srpts.exe.config, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srptsl.exe, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srptsl.exe.config, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\srut.dll, Löschen bei Neustart, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\System.Data.SQLite.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\UserSettings.xml, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\XMLOperations.xml, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Configs\BrowserSettings.xml, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Configs\LPTMapping.xml, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Configs\Timers.xml, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Resources\LPT.xml, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Resources\ntdis_32.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.Linkury.A, C:\Program Files\LPT\Resources\ntdis_64.dll, In Quarantäne, [d0c2774b5d1e5fd71cf1a84e55ad6898],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\BrowserHelper.exe.config, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\ChromeHost.exe, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\IEButton.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Interop.SHDocVw.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\lrcnt.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Lrcnta.exe, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\lrrot.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\MACTrackBarLib.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.Common.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.ExceptionHandling.Logging.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Microsoft.Practices.EnterpriseLibrary.Logging.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Microsoft.Practices.ObjectBuilder.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\NDde.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\NewConfig.txt, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Newtonsoft.Json.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Proxy.Lib.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\ProxySettings.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\RegAsm.exe, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sb.host.json, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sgml.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sidb.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\siem.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sipb.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sismlp.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Common.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Communication.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.exe.config, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Monetization.Proxy.ProxyService.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.XmlSerializers.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Resources.Translations.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\SmartbarInstallationIcon.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\SmartbarShortcutIcon.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\SmartbarVersionsHelper.exe.config, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\smta.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\smti.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\smtu.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\spbe.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Microsoft.mshtml.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\ProductsRemovalTool.exe, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Smartbar.Communication.NamedPipe.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\spbl.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sppsm.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\spsm.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\spusm.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srau.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srbhu.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srbs.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srbu.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sreu.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srgu.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srns.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srom.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srpdm.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srprl.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srpu.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srsbs.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srsbsau.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srsl.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\sruhs.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srus.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\srut.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\System.Data.SQLite.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\XMLOperations.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\bg.html, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\bg.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\manifest.json, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\options.htm, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\options.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\popup.html, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\popup.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\redirect.html, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\redirect.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\CSS\border.css, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\down-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\down-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\down-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\down.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\fb.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\fblike.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\gmail.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\google.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\googleplus.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\hide-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\hide-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\hide-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\left.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\maximize-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\maximize-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\maximize-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\mgsplusvideo.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\minimize-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\minimize-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\minimize-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\pinit.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\right.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\searchBox.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\show-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\show-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\show-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\twitter.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\up-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\up-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\up-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\images\up.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\alxbl.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\BackPageRemove.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\defaultBlockList.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\documentEvents.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\externalJS.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\FBImagePreview.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\filters.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\generalBackButtonDetection.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\InternalJS.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\jquery-1.9.0.min.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\PluginWrapper.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\publisherDefinitions.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\ta.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\tabReload.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\TopFrameJS.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\JS\trans.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages\Linkury.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages\Linkury128.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages\Linkury16.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\PublisherImages\Linkury48.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\ar\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Configs\QueryParameters.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\Configs\XmlSideBySideProtocol.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\es\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\fr\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\he\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome.manifest, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\install.rdf, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\BackPageRemove.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\externalJS.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\FBImagePreview.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\FirefoxExtensionMain.css, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\FirefoxExtensionMain.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\FirefoxExtensionMain.xul, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\InternalJS.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\jquery-1.5.1.min.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\publisherDefinitions.js, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\down-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\down-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\down-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\down.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\fb.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\fblike.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\gmail.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\googleplus.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\hide-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\hide-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\hide-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\left.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\maximize-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\maximize-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\maximize-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\mgsplusvideo.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\minimize-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\minimize-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\minimize-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\pinit.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\right.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\searchBox.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\show-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\show-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\show-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\twitter.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\up-1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\up-2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\up-3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\up.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages\Linkury.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages\Linkury128.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages\Linkury16.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages\Linkury_small.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\ISmartbarFireFoxRemotePlugin.xpt, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_25.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_26.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_27.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_28.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_29.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_30.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\it\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\nl\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\pt\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\ru\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Application\tr\Smartbar.Resources.LanguageSettings.resources.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\Configs\UserInfo.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\65B1A402-FC79-410D-AE1C-AF92E206AC1D.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\00659FA4-2CAD-45fc-A8A0-DB7862840BA9.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\00659FA4-2CAD-45fc-A8A0-DB7862840BA9hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\00659FA4-2CAD-45fc-A8A0-DB7862840BA9press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\07a9a58b-c653-4285-a870-1fa70cb6c00c.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\07a9a58b-c653-4285-a870-1fa70cb6c00chover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\07a9a58b-c653-4285-a870-1fa70cb6c00cPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7A.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7Apress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\0E29BC94-7C9B-4A23-B682-81D0D1A806E1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\0E29BC94-7C9B-4A23-B682-81D0D1A806E1hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\0E29BC94-7C9B-4A23-B682-81D0D1A806E1press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\0FA6F971-16AA-4921-A39F-543C9839CABE.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\0FA6F971-16AA-4921-A39F-543C9839CABEhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\0FA6F971-16AA-4921-A39F-543C9839CABEpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\101FF2F5-9F51-405F-ACBB-D4A5F3601679.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\101FF2F5-9F51-405F-ACBB-D4A5F3601679hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\101FF2F5-9F51-405F-ACBB-D4A5F3601679press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\1A039A19-BD34-4760-8DE0-E9A8E8AA8827.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\1A039A19-BD34-4760-8DE0-E9A8E8AA8827Ehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\1A039A19-BD34-4760-8DE0-E9A8E8AA8827press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\225323D0-97BB-46E4-85E1-15EA27174BF4.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\225323D0-97BB-46E4-85E1-15EA27174BF4hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\23E3FEB8-E6FF-4475-811A-805773D02D08.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\23E3FEB8-E6FF-4475-811A-805773D02D08hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\23E3FEB8-E6FF-4475-811A-805773D02D08press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\26E2804B-65B5-47E1-A457-DAA75A2B1370.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\26E2804B-65B5-47E1-A457-DAA75A2B1370hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\26E2804B-65B5-47E1-A457-DAA75A2B1370press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7Ahover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\225323D0-97BB-46E4-85E1-15EA27174BF4press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\30DFF8F0-BA79-4360-A3EA-51B6D006133CHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\3C610B86-19DE-4757-B46A-871C9C27FF0A.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\3f9ac55c-6db5-4c01-9d34-a92da2347be6press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\2C37338C-837B-4846-B50B-E32D70C6A0F5.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\2C37338C-837B-4846-B50B-E32D70C6A0F5hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\2C37338C-837B-4846-B50B-E32D70C6A0F5press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\30657846-199A-4D0D-984D-BE588084F1F6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\30657846-199A-4D0D-984D-BE588084F1F6hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\30657846-199A-4D0D-984D-BE588084F1F6press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\30DFF8F0-BA79-4360-A3EA-51B6D006133C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\30DFF8F0-BA79-4360-A3EA-51B6D006133CPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\328F7722-52E8-46A6-9197-B2F27C5142C7.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\328F7722-52E8-46A6-9197-B2F27C5142C7hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\328F7722-52E8-46A6-9197-B2F27C5142C7press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\372FF78B-6E4B-4B38-8E3F-797B4680FB98.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\372FF78B-6E4B-4B38-8E3F-797B4680FB98hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\372FF78B-6E4B-4B38-8E3F-797B4680FB98press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\39028511-3F15-4442-9188-DDC86BE1BBD0.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\39028511-3F15-4442-9188-DDC86BE1BBD0hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\39028511-3F15-4442-9188-DDC86BE1BBD0press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\39079B96-6DD1-42DE-89E6-76F79C8BB4E4.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\39079B96-6DD1-42DE-89E6-76F79C8BB4E4Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\39079B96-6DD1-42DE-89E6-76F79C8BB4E4Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\3C610B86-19DE-4757-B46A-871C9C27FF0AHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\3C610B86-19DE-4757-B46A-871C9C27FF0APress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\3DF17372-78B0-4978-81A5-F9D1800C1775.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\3DF17372-78B0-4978-81A5-F9D1800C1775Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\3DF17372-78B0-4978-81A5-F9D1800C1775Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\3f9ac55c-6db5-4c01-9d34-a92da2347be6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\3f9ac55c-6db5-4c01-9d34-a92da2347be6hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\412D5531-A3E1-40BB-B0C3-71E3C45A4E13.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\412D5531-A3E1-40BB-B0C3-71E3C45A4E13hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\412D5531-A3E1-40BB-B0C3-71E3C45A4E13press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\4a110a71-0e7e-4552-af6e-3ef88b2d6511.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\4a110a71-0e7e-4552-af6e-3ef88b2d6511Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\4a110a71-0e7e-4552-af6e-3ef88b2d6511Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5252af60-ef03-41a8-babe-415dba235478.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5252af60-ef03-41a8-babe-415dba235478Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5252af60-ef03-41a8-babe-415dba235478Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\536b9063-fc09-4e82-8769-73c77317aae6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\536b9063-fc09-4e82-8769-73c77317aae6hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\536b9063-fc09-4e82-8769-73c77317aae6press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\56591C8E-DA35-4A97-AC9B-5055E0F7089E.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\56591C8E-DA35-4A97-AC9B-5055E0F7089Ehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\56591C8E-DA35-4A97-AC9B-5055E0F7089Epress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002A.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002Ahover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002Apress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5D0A6D97-85F2-47E9-8F04-04A747B25A0E.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5D0A6D97-85F2-47E9-8F04-04A747B25A0Ehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5D0A6D97-85F2-47E9-8F04-04A747B25A0Epress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5F488FA5-C35B-44A9-A0E4-2C7B41035780.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5F488FA5-C35B-44A9-A0E4-2C7B41035780hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\5F488FA5-C35B-44A9-A0E4-2C7B41035780press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\65B1A402-FC79-410D-AE1C-AF92E206AC1Dhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\65B1A402-FC79-410D-AE1C-AF92E206AC1Dpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7EC.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7EChover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7ECpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\708d8b1e-6545-474a-9f07-d854acf8ad43.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\708d8b1e-6545-474a-9f07-d854acf8ad43hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\70F16DCA-C71C-4ECB-994C-D180F2BBF736.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\70F16DCA-C71C-4ECB-994C-D180F2BBF736Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\70F16DCA-C71C-4ECB-994C-D180F2BBF736Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\72CDFC8C-6F2D-4df8-9811-18C4D682C406.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\72CDFC8C-6F2D-4df8-9811-18C4D682C406hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\72CDFC8C-6F2D-4df8-9811-18C4D682C406press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\7CF3BACC-BF1C-4860-BB4E-F1A8440250FE.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\7CF3BACC-BF1C-4860-BB4E-F1A8440250FEhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\7CF3BACC-BF1C-4860-BB4E-F1A8440250FEpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\7fe83ae9-caef-41f0-aa99-d114c0ce3941.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\7fe83ae9-caef-41f0-aa99-d114c0ce3941hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\7fe83ae9-caef-41f0-aa99-d114c0ce3941press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\8217d395-9ebe-4ebb-807c-38cc911a307f.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\8217d395-9ebe-4ebb-807c-38cc911a307fPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\85CF6427-8441-427A-859A-7A3C72288481.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\85CF6427-8441-427A-859A-7A3C72288481hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\85CF6427-8441-427A-859A-7A3C72288481press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\87442BEF-FD31-405C-A807-650CB7CC8886.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\87442BEF-FD31-405C-A807-650CB7CC8886hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\87442BEF-FD31-405C-A807-650CB7CC8886press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\89582936-094C-4880-B87A-2AF16FC33B2C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\89582936-094C-4880-B87A-2AF16FC33B2Chover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\89582936-094C-4880-B87A-2AF16FC33B2Cpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\8b3608b1-c2d5-4ad3-a382-33601228c6d3hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\8b3608b1-c2d5-4ad3-a382-33601228c6d3press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\8F4131CE-D4F0-4F08-9102-78C397F3748C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\8F4131CE-D4F0-4F08-9102-78C397F3748CHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\8F4131CE-D4F0-4F08-9102-78C397F3748CPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\90165d32-a3ef-438c-8625-be9b538b6eba.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\90165d32-a3ef-438c-8625-be9b538b6ebaHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\925D8F0E-E5EA-45F9-A657-0C14B68C4A61.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\925D8F0E-E5EA-45F9-A657-0C14B68C4A61hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\925D8F0E-E5EA-45F9-A657-0C14B68C4A61press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\929407CC-7E48-47E0-A9F9-A4A167AC24D1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\929407CC-7E48-47E0-A9F9-A4A167AC24D1hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\929407CC-7E48-47E0-A9F9-A4A167AC24D1press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\95ae73f0-9799-46fd-bceb-57efcb7f0537.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\95ae73f0-9799-46fd-bceb-57efcb7f0537hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\95ae73f0-9799-46fd-bceb-57efcb7f0537press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8Cpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A75C6A50-13B0-4704-AA87-8DD113E31310.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A75C6A50-13B0-4704-AA87-8DD113E31310hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A75C6A50-13B0-4704-AA87-8DD113E31310press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A89DA5A2-D390-47F4-84EF-6044EC8AC368.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A89DA5A2-D390-47F4-84EF-6044EC8AC368hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A89DA5A2-D390-47F4-84EF-6044EC8AC368press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\a94e6710-6021-4cdc-82de-1c001238bd8f.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\a94e6710-6021-4cdc-82de-1c001238bd8fHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\a94e6710-6021-4cdc-82de-1c001238bd8fPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\B1BEF453-913F-4EC4-B057-A2BB21C09DCBhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\B1BEF453-913F-4EC4-B057-A2BB21C09DCBpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55F.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55Fhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55Fpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\B81443D4-15F7-4B97-9DC8-3645A012C817.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\B81443D4-15F7-4B97-9DC8-3645A012C817hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\bc8dcde3-3fd0-4f9b-af5d-15c20f3239ab.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\bc8dcde3-3fd0-4f9b-af5d-15c20f3239ab.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\bc8dcde3-3fd0-4f9b-af5d-15c20f3239abhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\bc8dcde3-3fd0-4f9b-af5d-15c20f3239abpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\C0AC006A-9C65-42F9-AE11-D675DCCC6840.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\C0AC006A-9C65-42F9-AE11-D675DCCC6840hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\C0AC006A-9C65-42F9-AE11-D675DCCC6840press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\c1546a00-e42d-4ce7-aac5-5353a895f3cfhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\c1546a00-e42d-4ce7-aac5-5353a895f3cfpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\C438F0F0-525A-4942-8307-6B71E596367D.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\C438F0F0-525A-4942-8307-6B71E596367Dhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\C438F0F0-525A-4942-8307-6B71E596367Dpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\C48E3725-71FB-4824-969A-C6D428C18A2B.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\C48E3725-71FB-4824-969A-C6D428C18A2Bhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\708d8b1e-6545-474a-9f07-d854acf8ad43press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\8217d395-9ebe-4ebb-807c-38cc911a307fHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\8b3608b1-c2d5-4ad3-a382-33601228c6d3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\90165d32-a3ef-438c-8625-be9b538b6ebaPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8Chover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\B1BEF453-913F-4EC4-B057-A2BB21C09DCB.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\B81443D4-15F7-4B97-9DC8-3645A012C817press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\c1546a00-e42d-4ce7-aac5-5353a895f3cf.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\C48E3725-71FB-4824-969A-C6D428C18A2Bpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D13971C4-4DA8-4C4B-87F6-17E97BFE7448hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E458493F-867F-4712-A3AF-D9664ED47C19.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\f7fd4890-7f89-4c73-8ff2-52105657cbb6Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CCF42F56-0405-4697-A513-AA01DEE5DF02.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CCF42F56-0405-4697-A513-AA01DEE5DF02hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CCF42F56-0405-4697-A513-AA01DEE5DF02press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CE1500FE-6F59-421C-8005-3E137AC051A2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CE1500FE-6F59-421C-8005-3E137AC051A2hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CE1500FE-6F59-421C-8005-3E137AC051A2press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D13971C4-4DA8-4C4B-87F6-17E97BFE7448.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D13971C4-4DA8-4C4B-87F6-17E97BFE7448press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D2B0680C-17C4-492D-85D7-D4CA3E724D50.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D2B0680C-17C4-492D-85D7-D4CA3E724D50hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D2B0680C-17C4-492D-85D7-D4CA3E724D50press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D469E1BA-B745-45B3-B7EE-378E000E74C8.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D469E1BA-B745-45B3-B7EE-378E000E74C8Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D469E1BA-B745-45B3-B7EE-378E000E74C8Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D5113B95-781C-4737-A26F-3ED3A2CB876F.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D5113B95-781C-4737-A26F-3ED3A2CB876Fhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D5113B95-781C-4737-A26F-3ED3A2CB876Fpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],


TOMROSSI 05.08.2014 06:31

Malware1.3
Code:

PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4Chover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4Cpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e2870479-a572-412b-8a8f-5604d19b55cd.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e2870479-a572-412b-8a8f-5604d19b55cdhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e2870479-a572-412b-8a8f-5604d19b55cdpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E3345571-EEF9-4041-8C24-F7F5A9331C23.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E3345571-EEF9-4041-8C24-F7F5A9331C23hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E3345571-EEF9-4041-8C24-F7F5A9331C23press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e357f164-c5d8-4257-aab2-fe0cad41c12e.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e357f164-c5d8-4257-aab2-fe0cad41c12e.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e357f164-c5d8-4257-aab2-fe0cad41c12ehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e357f164-c5d8-4257-aab2-fe0cad41c12epress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E458493F-867F-4712-A3AF-D9664ED47C19hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E458493F-867F-4712-A3AF-D9664ED47C19press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E52BEFE7-6535-439c-B168-A3B105E4212E.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E52BEFE7-6535-439c-B168-A3B105E4212Ehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E52BEFE7-6535-439c-B168-A3B105E4212Epress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E8584703-6CA5-4351-82CC-09E40938A066.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E8584703-6CA5-4351-82CC-09E40938A066hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\E8584703-6CA5-4351-82CC-09E40938A066press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e8967c62-9ea0-4fde-9832-2c10f1d580de.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e8967c62-9ea0-4fde-9832-2c10f1d580dehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\e8967c62-9ea0-4fde-9832-2c10f1d580depress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\EA99E20A-FBBA-4197-954B-E2013280A29B.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\EA99E20A-FBBA-4197-954B-E2013280A29Bhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\EA99E20A-FBBA-4197-954B-E2013280A29Bpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F5297DBC-3B3B-4744-A54D-308EAD98D223.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F5297DBC-3B3B-4744-A54D-308EAD98D223hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F5297DBC-3B3B-4744-A54D-308EAD98D223press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\f7fd4890-7f89-4c73-8ff2-52105657cbb6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\f7fd4890-7f89-4c73-8ff2-52105657cbb6Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BD.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BDhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BDpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F9218572-58F0-4FB9-B0C5-4EA74848D6EC.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F9218572-58F0-4FB9-B0C5-4EA74848D6EChover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F9218572-58F0-4FB9-B0C5-4EA74848D6ECpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\fac5189f-f2c7-4eed-bae8-011eca170d7b.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\fac5189f-f2c7-4eed-bae8-011eca170d7bhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\fac5189f-f2c7-4eed-bae8-011eca170d7bpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\FF927FFB-35DC-43A3-A502-690B99FCC056.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\FF927FFB-35DC-43A3-A502-690B99FCC056hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\icons\FF927FFB-35DC-43A3-A502-690B99FCC056press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\00659FA4-2CAD-45fc-A8A0-DB7862840BA9.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\00659FA4-2CAD-45fc-A8A0-DB7862840BA9hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\00659FA4-2CAD-45fc-A8A0-DB7862840BA9press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\07a9a58b-c653-4285-a870-1fa70cb6c00c.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\07a9a58b-c653-4285-a870-1fa70cb6c00c.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\07a9a58b-c653-4285-a870-1fa70cb6c00chover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\07a9a58b-c653-4285-a870-1fa70cb6c00cpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7Ahover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7Apress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0AE6BC52-0A54-4F53-9848-1FC2D4CE3D3D.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0AE6BC52-0A54-4F53-9848-1FC2D4CE3D3DHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0AE6BC52-0A54-4F53-9848-1FC2D4CE3D3DPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0DB19630-EB33-4B18-8357-78FC2687C788.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0DB19630-EB33-4B18-8357-78FC2687C788hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0E29BC94-7C9B-4A23-B682-81D0D1A806E1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0E29BC94-7C9B-4A23-B682-81D0D1A806E1hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0E29BC94-7C9B-4A23-B682-81D0D1A806E1press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0FA6F971-16AA-4921-A39F-543C9839CABE.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0FA6F971-16AA-4921-A39F-543C9839CABEhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0FA6F971-16AA-4921-A39F-543C9839CABEpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\101FF2F5-9F51-405F-ACBB-D4A5F3601679.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\101FF2F5-9F51-405F-ACBB-D4A5F3601679hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\101FF2F5-9F51-405F-ACBB-D4A5F3601679press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE081313.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE081313hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE081313press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE08E613.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0A2DE7DB-ADE9-44FC-BC66-CF5604F9BF7A.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\0DB19630-EB33-4B18-8357-78FC2687C788press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE08E613hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\2141A104-423C-43EF-A27A-CA0DADB7B9BChover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\2C37338C-837B-4846-B50B-E32D70C6A0F5.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\30657846-199A-4D0D-984D-BE588084F1F6press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\389DA7E0-2A26-40AB-ACA4-9417E3B9EF13Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE08E613press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE131313.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE131313hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\139D15A7-C5E1-4C5E-ABF2-484DBE131313press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\1A039A19-BD34-4760-8DE0-E9A8E8AA8827.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\1A039A19-BD34-4760-8DE0-E9A8E8AA8827hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\1A039A19-BD34-4760-8DE0-E9A8E8AA8827press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\1A19CD12-F9A2-44A6-8F44-F3A95E0081A0press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\1FFDDB6E-8EB3-4CE0-9C2B-44910A3C5975press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\2141A104-423C-43EF-A27A-CA0DADB7B9BC.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\2141A104-423C-43EF-A27A-CA0DADB7B9BCpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\225323D0-97BB-46E4-85E1-15EA27174BF4.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\225323D0-97BB-46E4-85E1-15EA27174BF4hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\225323D0-97BB-46E4-85E1-15EA27174BF4press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\23E3FEB8-E6FF-4475-811A-805773D02D08.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\23E3FEB8-E6FF-4475-811A-805773D02D08hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\23E3FEB8-E6FF-4475-811A-805773D02D08press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\26E2804B-65B5-47E1-A457-DAA75A2B1370.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\26E2804B-65B5-47E1-A457-DAA75A2B1370hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\26E2804B-65B5-47E1-A457-DAA75A2B1370press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\28E2C7BC-F857-44D5-A42F-7DD66FAB5EE6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\28E2C7BC-F857-44D5-A42F-7DD66FAB5EE6hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\28E2C7BC-F857-44D5-A42F-7DD66FAB5EE6press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\2C37338C-837B-4846-B50B-E32D70C6A0F5hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\2C37338C-837B-4846-B50B-E32D70C6A0F5press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\2F274118-68DC-4951-92D7-54CD244FE02A.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\2F274118-68DC-4951-92D7-54CD244FE02AHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\2F274118-68DC-4951-92D7-54CD244FE02APress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\30657846-199A-4D0D-984D-BE588084F1F6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\30657846-199A-4D0D-984D-BE588084F1F6hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\30DEBC8A-1CC6-4480-B3E5-C55E214043A8.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\30DEBC8A-1CC6-4480-B3E5-C55E214043A8Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\30DEBC8A-1CC6-4480-B3E5-C55E214043A8Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\30DFF8F0-BA79-4360-A3EA-51B6D006133C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\30DFF8F0-BA79-4360-A3EA-51B6D006133CHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\30DFF8F0-BA79-4360-A3EA-51B6D006133CPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\328F7722-52E8-46A6-9197-B2F27C5142C7.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\328F7722-52E8-46A6-9197-B2F27C5142C7hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\328F7722-52E8-46A6-9197-B2F27C5142C7press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\372FF78B-6E4B-4B38-8E3F-797B4680FB98.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\372FF78B-6E4B-4B38-8E3F-797B4680FB98hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\372FF78B-6E4B-4B38-8E3F-797B4680FB98press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\389DA7E0-2A26-40AB-ACA4-9417E3B9EF13.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\389DA7E0-2A26-40AB-ACA4-9417E3B9EF13Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\39028511-3F15-4442-9188-DDC86BE1BBD0.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\39028511-3F15-4442-9188-DDC86BE1BBD0hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\39028511-3F15-4442-9188-DDC86BE1BBD0press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\39079B96-6DD1-42DE-89E6-76F79C8BB4E4.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\39079B96-6DD1-42DE-89E6-76F79C8BB4E4Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\39079B96-6DD1-42DE-89E6-76F79C8BB4E4Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3C610B86-19DE-4757-B46A-871C9C27FF0A.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3C610B86-19DE-4757-B46A-871C9C27FF0AHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3C610B86-19DE-4757-B46A-871C9C27FF0APress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3DF17372-78B0-4978-81A5-F9D1800C1775.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3DF17372-78B0-4978-81A5-F9D1800C1775Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3DF17372-78B0-4978-81A5-F9D1800C1775Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3f9ac55c-6db5-4c01-9d34-a92da2347be6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3f9ac55c-6db5-4c01-9d34-a92da2347be6hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3f9ac55c-6db5-4c01-9d34-a92da2347be6press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\412D5531-A3E1-40BB-B0C3-71E3C45A4E13.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\412D5531-A3E1-40BB-B0C3-71E3C45A4E13hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\412D5531-A3E1-40BB-B0C3-71E3C45A4E13press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\47BFF758-9581-4C68-9293-1181A70CDEE8.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\47BFF758-9581-4C68-9293-1181A70CDEE8Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\47BFF758-9581-4C68-9293-1181A70CDEE8Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\48A9C19C-5A4C-4652-A6E7-1C17AEE45675.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\48A9C19C-5A4C-4652-A6E7-1C17AEE45675Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\4a110a71-0e7e-4552-af6e-3ef88b2d6511.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\4a110a71-0e7e-4552-af6e-3ef88b2d6511.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\4a110a71-0e7e-4552-af6e-3ef88b2d6511Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\4a110a71-0e7e-4552-af6e-3ef88b2d6511Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\511B6809-2468-4A36-A6FC-FC24F05499BE.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\511B6809-2468-4A36-A6FC-FC24F05499BEHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5252af60-ef03-41a8-babe-415dba235478.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5252af60-ef03-41a8-babe-415dba235478.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5252af60-ef03-41a8-babe-415dba235478Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5252af60-ef03-41a8-babe-415dba235478Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\536b9063-fc09-4e82-8769-73c77317aae6.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\536b9063-fc09-4e82-8769-73c77317aae6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\536b9063-fc09-4e82-8769-73c77317aae6hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5558C4C6-18C1-4AF3-8F8D-0E2CF70D19C8press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\56591C8E-DA35-4A97-AC9B-5055E0F7089E.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\56591C8E-DA35-4A97-AC9B-5055E0F7089Ehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\56591C8E-DA35-4A97-AC9B-5055E0F7089Epress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002A.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002Ahover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\56B19DA1-B4C5-4FCF-87D0-44E8B2C1002Apress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5D0A6D97-85F2-47E9-8F04-04A747B25A0E.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5D0A6D97-85F2-47E9-8F04-04A747B25A0Ehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5D0A6D97-85F2-47E9-8F04-04A747B25A0Epress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5F1B269B-7C66-474F-A473-BE7FA51BE5B2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5F1B269B-7C66-474F-A473-BE7FA51BE5B2press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5F488FA5-C35B-44A9-A0E4-2C7B41035780.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5F488FA5-C35B-44A9-A0E4-2C7B41035780hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5F488FA5-C35B-44A9-A0E4-2C7B41035780press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\65B1A402-FC79-410D-AE1C-AF92E206AC1D.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\65B1A402-FC79-410D-AE1C-AF92E206AC1Dhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\65B1A402-FC79-410D-AE1C-AF92E206AC1Dpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\65C4AD03-739F-4EC9-8FFD-457CC4241B9F.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\65C4AD03-739F-4EC9-8FFD-457CC4241B9Fhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\65C4AD03-739F-4EC9-8FFD-457CC4241B9Fpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\684B31D0-535B-45EC-B3D1-15923CF5F790.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\684B31D0-535B-45EC-B3D1-15923CF5F790Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\684B31D0-535B-45EC-B3D1-15923CF5F790Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7EChover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7ECpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\708d8b1e-6545-474a-9f07-d854acf8ad43.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\708d8b1e-6545-474a-9f07-d854acf8ad43.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\708d8b1e-6545-474a-9f07-d854acf8ad43hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\708d8b1e-6545-474a-9f07-d854acf8ad43press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\70F16DCA-C71C-4ECB-994C-D180F2BBF736.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\70F16DCA-C71C-4ECB-994C-D180F2BBF736Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\72CDFC8C-6F2D-4df8-9811-18C4D682C406.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\72CDFC8C-6F2D-4df8-9811-18C4D682C406hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\72CDFC8C-6F2D-4df8-9811-18C4D682C406press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\7CF3BACC-BF1C-4860-BB4E-F1A8440250FE.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\7CF3BACC-BF1C-4860-BB4E-F1A8440250FEhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\7CF3BACC-BF1C-4860-BB4E-F1A8440250FEpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\7fe83ae9-caef-41f0-aa99-d114c0ce3941.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\7fe83ae9-caef-41f0-aa99-d114c0ce3941.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\7fe83ae9-caef-41f0-aa99-d114c0ce3941hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\7fe83ae9-caef-41f0-aa99-d114c0ce3941press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8217d395-9ebe-4ebb-807c-38cc911a307f.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8217d395-9ebe-4ebb-807c-38cc911a307f.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8217d395-9ebe-4ebb-807c-38cc911a307fHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\82F730CA-BA1C-4AFB-AC7C-FE4ED6B532FD.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\82F730CA-BA1C-4AFB-AC7C-FE4ED6B532FDHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\82F730CA-BA1C-4AFB-AC7C-FE4ED6B532FDPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\83B4B6FE-910D-412E-BED4-E3AFA6E5CA61press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\85CF6427-8441-427A-859A-7A3C72288481.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\85CF6427-8441-427A-859A-7A3C72288481hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\85CF6427-8441-427A-859A-7A3C72288481press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\87442BEF-FD31-405C-A807-650CB7CC8886.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\87442BEF-FD31-405C-A807-650CB7CC8886hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\87442BEF-FD31-405C-A807-650CB7CC8886press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\89582936-094c-4880-b87a-2af16fc31313Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\89582936-094c-4880-b87a-2af16fc31313Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\89582936-094C-4880-B87A-2AF16FC33B2C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\89582936-094C-4880-B87A-2AF16FC33B2Chover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\89582936-094C-4880-B87A-2AF16FC33B2Cpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8b3608b1-c2d5-4ad3-a382-33601228c6d3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8b3608b1-c2d5-4ad3-a382-33601228c6d3hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8b3608b1-c2d5-4ad3-a382-33601228c6d3press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8D338D8F-3189-41AB-BCFF-2958D48AAA6A.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8D338D8F-3189-41AB-BCFF-2958D48AAA6AHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8D338D8F-3189-41AB-BCFF-2958D48AAA6APress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8F4131CE-D4F0-4F08-9102-78C397F3748C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8F4131CE-D4F0-4F08-9102-78C397F3748CHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8F4131CE-D4F0-4F08-9102-78C397F3748CPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\48A9C19C-5A4C-4652-A6E7-1C17AEE45675Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\511B6809-2468-4A36-A6FC-FC24F05499BEPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\536b9063-fc09-4e82-8769-73c77317aae6press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\5F1B269B-7C66-474F-A473-BE7FA51BE5B2hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\69C7DFE3-CDAE-4A22-B753-93ABF8BAE7EC.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\70F16DCA-C71C-4ECB-994C-D180F2BBF736Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\8217d395-9ebe-4ebb-807c-38cc911a307fPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\89582936-094c-4880-b87a-2af16fc31313.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\90165d32-a3ef-438c-8625-be9b538b6eba.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\90165d32-a3ef-438c-8625-be9b538b6ebaHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\90165d32-a3ef-438c-8625-be9b538b6ebaPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\925D8F0E-E5EA-45F9-A657-0C14B68C4A61.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\925D8F0E-E5EA-45F9-A657-0C14B68C4A61hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\925D8F0E-E5EA-45F9-A657-0C14B68C4A61press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\929407CC-7E48-47E0-A9F9-A4A167AC24D1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\929407CC-7E48-47E0-A9F9-A4A167AC24D1press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\95ae73f0-9799-46fd-bceb-57efcb7f0537.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\95ae73f0-9799-46fd-bceb-57efcb7f0537.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\95ae73f0-9799-46fd-bceb-57efcb7f0537hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\95ae73f0-9799-46fd-bceb-57efcb7f0537press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\95D9E2EA-40AD-40B8-95D0-58209F584BBE.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\95D9E2EA-40AD-40B8-95D0-58209F584BBEHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\99938D89-FF78-49C8-B92B-5AB4C8DFA2D1press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8Chover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A1D51ECC-DBD7-4C7E-9A75-364B8E2F1D8Cpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A1F75F5D-1D24-4F7A-9ABC-BDA55E332E67press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A46C5E77-16B5-42A0-8761-C6F861D22308.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A46C5E77-16B5-42A0-8761-C6F861D22308Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A46C5E77-16B5-42A0-8761-C6F861D22308Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A75C6A50-13B0-4704-AA87-8DD113E31310.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A75C6A50-13B0-4704-AA87-8DD113E31310press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A89DA5A2-D390-47F4-84EF-6044EC8AC368.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A89DA5A2-D390-47F4-84EF-6044EC8AC368hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A89DA5A2-D390-47F4-84EF-6044EC8AC368press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\a94e6710-6021-4cdc-82de-1c001238bd8f.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\a94e6710-6021-4cdc-82de-1c001238bd8f.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\a94e6710-6021-4cdc-82de-1c001238bd8fHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B1BEF453-913F-4EC4-B057-A2BB21C09DCB.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B1BEF453-913F-4EC4-B057-A2BB21C09DCB.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B1BEF453-913F-4EC4-B057-A2BB21C09DCBhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B1BEF453-913F-4EC4-B057-A2BB21C09DCBpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55F.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55Fhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B81443D4-15F7-4B97-9DC8-3645A012C817.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B81443D4-15F7-4B97-9DC8-3645A012C817hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B81443D4-15F7-4B97-9DC8-3645A012C817press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\bbf677d4-d0bc-4a59-be4a-6a6cfd3c6c28press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\BC303DD4-37E7-4242-8DDD-8DEE2171066B.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\BC303DD4-37E7-4242-8DDD-8DEE2171066Bhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\BC303DD4-37E7-4242-8DDD-8DEE2171066Bpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\bc8dcde3-3fd0-4f9b-af5d-15c20f3239ab.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\bc8dcde3-3fd0-4f9b-af5d-15c20f3239ab.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\bc8dcde3-3fd0-4f9b-af5d-15c20f3239abhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\bc8dcde3-3fd0-4f9b-af5d-15c20f3239abpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\BE3608B1-C2D5-4AD3-A382-45635338C6D1.PNG, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\BE3608B1-C2D5-4AD3-A382-45635338C6D1HOVER.PNG, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\BE3608B1-C2D5-4AD3-A382-45635338C6D1PRESS.PNG, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C0AC006A-9C65-42F9-AE11-D675DCCC6840.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C0AC006A-9C65-42F9-AE11-D675DCCC6840hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\c1546a00-e42d-4ce7-aac5-5353a895f3cf.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\c1546a00-e42d-4ce7-aac5-5353a895f3cf.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\c1546a00-e42d-4ce7-aac5-5353a895f3cfhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\c1546a00-e42d-4ce7-aac5-5353a895f3cfpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C41AD485-FE91-4EFE-A613-66CB2BA96EAB.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C41AD485-FE91-4EFE-A613-66CB2BA96EABHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C41AD485-FE91-4EFE-A613-66CB2BA96EABPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C438F0F0-525A-4942-8307-6B71E596367D.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C438F0F0-525A-4942-8307-6B71E596367Dhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C438F0F0-525A-4942-8307-6B71E596367Dpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C48E3725-71FB-4824-969A-C6D428C18A2B.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C48E3725-71FB-4824-969A-C6D428C18A2Bhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C48E3725-71FB-4824-969A-C6D428C18A2Bpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CCF42F56-0405-4697-A513-AA01DEE5DF02.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CCF42F56-0405-4697-A513-AA01DEE5DF02hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CCF42F56-0405-4697-A513-AA01DEE5DF02press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CE1500FE-6F59-421C-8005-3E137AC051A2.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CE1500FE-6F59-421C-8005-3E137AC051A2hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\90165d32-a3ef-438c-8625-be9b538b6eba.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\929407CC-7E48-47E0-A9F9-A4A167AC24D1hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\95D9E2EA-40AD-40B8-95D0-58209F584BBEPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\A75C6A50-13B0-4704-AA87-8DD113E31310hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\a94e6710-6021-4cdc-82de-1c001238bd8fPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\B1FE90EC-CEDA-4467-86CE-6CD7F1D3D55Fpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\BCE4103A-6273-4E49-8B43-2BDEDA1C91B0.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\C0AC006A-9C65-42F9-AE11-D675DCCC6840press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CCEE5A80-8C88-4BB1-89BF-4A7EFF93E452.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CFEFCFCB-4871-46CD-86F7-14C1F17A7FF6press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D13971C4-4DA8-4C4B-87F6-17E97BFE7448.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D13971C4-4DA8-4C4B-87F6-17E97BFE7448hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D13971C4-4DA8-4C4B-87F6-17E97BFE7448press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D2B0680C-17C4-492D-85D7-D4CA3E724D50.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D2B0680C-17C4-492D-85D7-D4CA3E724D50hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D2B0680C-17C4-492D-85D7-D4CA3E724D50press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D469E1BA-B745-45B3-B7EE-378E000E74C8.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D469E1BA-B745-45B3-B7EE-378E000E74C8Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D469E1BA-B745-45B3-B7EE-378E000E74C8Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D5113B95-781C-4737-A26F-3ED3A2CB876F.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D5113B95-781C-4737-A26F-3ED3A2CB876FPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35c1Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\d65acfc2-6ab9-4b66-84fc-ecc7813e35d0Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D8043E67-EBD0-4ABD-A5A4-63CF4DADFC85press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\DBE2517B-67B8-4D8B-A7CC-B66F8FE52D82press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4C.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4Chover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\DCF8B81C-11B5-4B12-A6E5-F74F09BBDD4Cpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e2870479-a572-412b-8a8f-5604d19b55cd.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e2870479-a572-412b-8a8f-5604d19b55cdhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e2870479-a572-412b-8a8f-5604d19b55cdpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E3345571-EEF9-4041-8C24-F7F5A9331C23.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E3345571-EEF9-4041-8C24-F7F5A9331C23press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e357f164-c5d8-4257-aab2-fe0cad41c12e.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e357f164-c5d8-4257-aab2-fe0cad41c12e.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e357f164-c5d8-4257-aab2-fe0cad41c12ehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e357f164-c5d8-4257-aab2-fe0cad41c12epress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e3c610dc-deed-47cd-acc0-493d71556c16.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e3c610dc-deed-47cd-acc0-493d71556c16Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E458493F-867F-4712-A3AF-D9664ED47C19.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E458493F-867F-4712-A3AF-D9664ED47C19hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E458493F-867F-4712-A3AF-D9664ED47C19press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E52BEFE7-6535-439c-B168-A3B105E4212E.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E52BEFE7-6535-439c-B168-A3B105E4212Ehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E52BEFE7-6535-439c-B168-A3B105E4212Epress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E6EE3C0D-1AF6-4A1E-AD63-1AFD7CB84583press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E8584703-6CA5-4351-82CC-09E40938A066.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E8584703-6CA5-4351-82CC-09E40938A066hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E8584703-6CA5-4351-82CC-09E40938A066press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e8967c62-9ea0-4fde-9832-2c10f1d580de.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e8967c62-9ea0-4fde-9832-2c10f1d580dehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e8967c62-9ea0-4fde-9832-2c10f1d580depress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E9FFB47F-2B3F-430E-8F8D-0B640D6A9564.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E9FFB47F-2B3F-430E-8F8D-0B640D6A9564Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E9FFB47F-2B3F-430E-8F8D-0B640D6A9564Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\EA99E20A-FBBA-4197-954B-E2013280A29B.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\EA99E20A-FBBA-4197-954B-E2013280A29Bpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\EC116BC4-0583-4E07-908A-9D2AD3647177.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\EC116BC4-0583-4E07-908A-9D2AD3647177Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\EC116BC4-0583-4E07-908A-9D2AD3647177Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\EDDB2889-2088-4070-9F17-E71A95D7A1BC.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\EDDB2889-2088-4070-9F17-E71A95D7A1BCHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\EDDB2889-2088-4070-9F17-E71A95D7A1BCPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\f41901a8-2a78-4794-b455-d53a24b37aef.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\f41901a8-2a78-4794-b455-d53a24b37aefHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\f41901a8-2a78-4794-b455-d53a24b37aefPress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F5297DBC-3B3B-4744-A54D-308EAD98D223.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F5297DBC-3B3B-4744-A54D-308EAD98D223hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F5297DBC-3B3B-4744-A54D-308EAD98D223press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\f7fd4890-7f89-4c73-8ff2-52105657cbb6.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\f7fd4890-7f89-4c73-8ff2-52105657cbb6Hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\f7fd4890-7f89-4c73-8ff2-52105657cbb6Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BD.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BDhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F84A3FBA-7CF5-4F44-A080-C26C04D0E3BDpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F9218572-58F0-4FB9-B0C5-4EA74848D6EC.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F9218572-58F0-4FB9-B0C5-4EA74848D6ECpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F9B1CE4C-4CE6-4093-948F-F8FD6A8F48A3press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\FA3DE5E1-19AC-42FA-8E77-C25C60E60EC7press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\D5113B95-781C-4737-A26F-3ED3A2CB876FHover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\E3345571-EEF9-4041-8C24-F7F5A9331C23hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e3c610dc-deed-47cd-acc0-493d71556c16Press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\e8967c62-9ea0-4fde-9832-2c10f1d580de.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\EA99E20A-FBBA-4197-954B-E2013280A29Bhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\f7fd4890-7f89-4c73-8ff2-52105657cbb6.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\F9218572-58F0-4FB9-B0C5-4EA74848D6EChover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\3f9ac55c-6db5-4c01-9d34-a92da2347be6.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\CE1500FE-6F59-421C-8005-3E137AC051A2press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\fac5189f-f2c7-4eed-bae8-011eca170d7b.ico, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\fac5189f-f2c7-4eed-bae8-011eca170d7b.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\fac5189f-f2c7-4eed-bae8-011eca170d7bhover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\fac5189f-f2c7-4eed-bae8-011eca170d7bpress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\FF927FFB-35DC-43A3-A502-690B99FCC056.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\FF927FFB-35DC-43A3-A502-690B99FCC056hover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\FF927FFB-35DC-43A3-A502-690B99FCC056press.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\youtube.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\youtubehover.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\iconsWide\youtubepress.png, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.DMP.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.MessengerPlugin.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WeatherPlugin.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.WordPlugin.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\ServicesPlugins\Smartbar.Personalization.ServicesPlugins.YoutubeDownloadPlugin.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\Common\ServicesPlugins\spup.dll, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\Configs\IconsSettings.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\Configs\LocalMethods.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\Configs\ProfileManager.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\Configs\PublisherSettings.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\Configs\UserSettings.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.SmartBar.A, C:\Users\HomeBasic1\AppData\Local\Smartbar\DistributionFiles\Profiles\1E41668C-576B-4E6F-B01A-692B355989C9.xml, In Quarantäne, [6a280fb39be0b383973efbb27e849a66],
PUP.Optional.OpenCandy, C:\Users\HomeBasic1\AppData\Roaming\OpenCandy\6A9D40B086844E0A8E9E5C8BA52AA651\Installer.exe, In Quarantäne, [a0f2cbf793e847ef9c5ab5f8ea18ab55],

Physische Sektoren: 0
(No malicious items detected)


(end)

Malware log 2.1
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 04.08.2014
Suchlauf-Zeit: 12:40:18
Logdatei: 2telog_Mailware.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.08.04.03
Rootkit Datenbank: v2014.08.01.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: HomeBasic1

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 294735
Verstrichene Zeit: 1 Std, 44 Min, 24 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 1
Backdoor.Agent, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|Load, C:\Windows\system32\Microsoft.com, , [23705d65502b4aecd545886251b1aa56]

Registrierungsdaten: 5
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}),,[6033ecd6cead3ef894cabafbe61e56aa]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2801197354-4021152197-1246408157-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voCiIS4l2kPC6yMc5xXI0YFNPjL2B-TJeKRQ8aYnONf06D_mc32csI8rWgu3CwrJBrb3V_Hqh7YwbkwBQoXe3H6JQmr_eBahg,,, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voCiIS4l2kPC6yMc5xXI0YFNPjL2B-TJeKRQ8aYnONf06D_mc32csI8rWgu3CwrJBrb3V_Hqh7YwbkwBQoXe3H6JQmr_eBahg,,),,[cec5546eb4c7d85ef36fbff6e81cf20e]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2801197354-4021152197-1246408157-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}),,[60338f3390eb81b5d78c75408381b749]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2801197354-4021152197-1246408157-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}),,[c2d1d9e9760555e1f371e1d482828e72]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-2801197354-4021152197-1246408157-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q={searchTerms}),,[22713a883b40ea4c4b146c49ef158e72]

Ordner: 0
(No malicious items detected)

Dateien: 2
PUP.Optional.HelperBar.A, C:\Users\HomeBasic1\AppData\Roaming\Mozilla\Firefox\Profiles\m91r75y2.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voEBfhFK3pEsAaigd-weSBLWjTAKyRjnmhlodqXsk_EocpZvnKjjwsqNva0REtQMSai-xdyNWwcnLuHt8UShQTHdLUuI5YeBA,,");), ,[8310ecd6017a989e9292f3fc2cd803fd]
PUP.Optional.HelperBar.A, C:\Users\HomeBasic1\AppData\Roaming\Mozilla\Firefox\Profiles\m91r75y2.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iNgLt1gJ7RWMIrNBTCKaMwQhIb_ipukjO6k2e-TGkeaRUE9ptUw2y0HYSGu7dm9c_ZV9XxsKc3g,,&q=");), ,[9af91ca6e09b8caa75b0a748966ea060]

Physische Sektoren: 0
(No malicious items detected)


(end)

AdwCleaner
Code:

# AdwCleaner v3.302 - Bericht erstellt am 04/08/2014 um 17:19:55
# Aktualisiert 30/07/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits)
# Benutzername : HomeBasic1 - HOMEBASIC1-PC
# Gestartet von : C:\Users\HomeBasic1\Desktop\adwcleaner_3.302.exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\Users\HomeBasic1\AppData\LocalLow\Smartbar
Datei Gelöscht : C:\Users\HomeBasic1\Favorites\Startfenster.lnk
Datei Gelöscht : C:\Users\HomeBasic1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk
Datei Gelöscht : C:\Users\HomeBasic1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster.lnk
Datei Gelöscht : C:\Users\HomeBasic1\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
Datei Gelöscht : C:\Users\HomeBasic1\Desktop\Startfenster.lnk

***** [ Tasks ] *****


***** [ Verknüpfungen ] *****

Verknüpfung Desinfiziert : C:\Users\HomeBasic1\Desktop\Search.lnk
Verknüpfung Desinfiziert : C:\Users\HomeBasic1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
Verknüpfung Desinfiziert : C:\Users\HomeBasic1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Search.lnk

***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\5E8031606EB60A64C882918F8FF38DD4

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17207


-\\ Mozilla Firefox v31.0 (x86 de)

[ Datei : C:\Users\HomeBasic1\AppData\Roaming\Mozilla\Firefox\Profiles\m91r75y2.default\prefs.js ]

Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voEBfhFK3pEsAaigd[...]
Zeile gelöscht : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarDisabled", false);
Zeile gelöscht : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gelöscht : user_pref("extensions.helperbar.Visibility", false);
Zeile gelöscht : user_pref("extensions.helperbar.backPageCapacity", 3);
Zeile gelöscht : user_pref("extensions.helperbar.backPageCounter", 0);
Zeile gelöscht : user_pref("extensions.helperbar.backPageDay", 14);
Zeile gelöscht : user_pref("extensions.helperbar.backPageLastEvent", "1405142989616");
Zeile gelöscht : user_pref("extensions.helperbar.backPageMinInterval", 15);
Zeile gelöscht : user_pref("extensions.helperbar.barcodeid", "1262");
Zeile gelöscht : user_pref("extensions.helperbar.countryiso", "de");
Zeile gelöscht : user_pref("extensions.helperbar.downloadprovider", "yahoooc");
Zeile gelöscht : user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[\\\"snap.do\\\",\\\"snapdo.com\\\",\\\".search.yahoo.com\\\\\\/yhs\\\\\\/search?hspart=lkry\\\",\\\"www.only-apart[...]
Zeile gelöscht : user_pref("extensions.helperbar.fromautoupdate", "false");
Zeile gelöscht : user_pref("extensions.helperbar.installationid", "acc1792c-fb6f-955a-5a5c-52986d09a789");
Zeile gelöscht : user_pref("extensions.helperbar.installdate", "14/07/2014");
Zeile gelöscht : user_pref("extensions.helperbar.keepAliveLastevent", "1405315788");
Zeile gelöscht : user_pref("extensions.helperbar.lastExternalJsUpdate", "1406569415890");
Zeile gelöscht : user_pref("extensions.helperbar.publisher", "yahoooc");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAaumhxgv5Wo5nhlXCWIyXN3vSvCQ8hlUrrbsna_I9lgrjWj3hxN2HnPbrLwCaKr4voOikj69o2hjcK1OdtbSU6iN[...]

*************************

AdwCleaner[R0].txt - [6286 octets] - [04/08/2014 17:18:25]
AdwCleaner[S0].txt - [5634 octets] - [04/08/2014 17:19:55]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5694 octets] ##########

JRT:
Code:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Ultimate x86
Ran by HomeBasic1 on 04.08.2014 at 17:27:13,24
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{02DD8284-A49F-43E5-9D84-CF19DC9AD21D}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{27DE7D30-BCCD-44D1-ADCB-A74A4259EBEF}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3A0EFC4E-F167-4D0E-9C24-FC5519237993}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{55D63393-DB17-4A2B-9052-15D85B4B1344}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\HomeBasic1\AppData\Roaming\getrighttogo"



~~~ FireFox

Emptied folder: C:\Users\HomeBasic1\AppData\Roaming\mozilla\firefox\profiles\m91r75y2.default\minidumps [118 files]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 04.08.2014 at 17:31:18,38
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


TOMROSSI 05.08.2014 06:33

FRST

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:31-07-2014 02
Ran by HomeBasic1 (administrator) on HOMEBASIC1-PC on 04-08-2014 20:52:27
Running from C:\Users\HomeBasic1\Downloads
Platform: Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files\GNU\GnuPG\dirmngr.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Elaborate Bytes AG) C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Wondershare) C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(StarWind Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
() C:\Users\HomeBasic1\AppData\Roaming\DRPSu\DrvUpdater.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Don HO don.h@free.fr) C:\Program Files\Notepad++\notepad++.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKU\.DEFAULT\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2013-09-05] (Microsoft Corporation)
HKU\S-1-5-21-2801197354-4021152197-1246408157-1001\...\Run: [DrvUpdater] => C:\Users\HomeBasic1\AppData\Roaming\DRPSu\DrvUpdater.exe [195256 2012-05-31] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8C162D5705A4CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Wondershare Player 1.6.0 -> {43D9786F-A485-683B-9B5B-ACC97ABC17FC} -> C:\ProgramData\Wondershare\Player\WSBrowserAppMgr.dll (Wondershare)
Handler: WSIEChrome - {6D02ED5F-FD0D-4C4C -  No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.15

FireFox:
========
FF ProfilePath: C:\Users\HomeBasic1\AppData\Roaming\Mozilla\Firefox\Profiles\m91r75y2.default
FF SearchEngineOrder.1: SuchMaschine
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll (Foxit Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [Player@Wondershare.com] - C:\ProgramData\Wondershare\Player\Player@Wondershare.com
FF Extension: Wondershare Player - C:\ProgramData\Wondershare\Player\Player@Wondershare.com [2013-11-29]

========================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
R2 DirMngr; C:\Program Files\GNU\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-17] (Elaborate Bytes AG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-08-04] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [477240 2013-10-24] (Duplex Secure Ltd.)
R3 teamviewervpn; C:\Windows\System32\DRIVERS\teamviewervpn.sys [25088 2013-06-06] (TeamViewer GmbH)
S3 catchme; \??\C:\Users\HOMEBA~1\AppData\Local\Temp\catchme.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]

==================== NetSvcs (Whitelisted) ===================


(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-04 20:51 - 2014-08-04 20:53 - 00000000 ____D () C:\Users\HomeBasic1\Downloads\scan
2014-08-04 20:24 - 2014-08-04 20:24 - 00000022 _____ () C:\Windows\S.dirmngr
2014-08-04 17:24 - 2014-08-04 17:24 - 00000000 ____D () C:\Windows\ERUNT
2014-08-04 17:17 - 2014-08-04 17:19 - 00000000 ____D () C:\AdwCleaner
2014-08-04 10:57 - 2014-08-04 20:37 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-04 10:57 - 2014-08-04 12:39 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-04 10:57 - 2014-08-04 12:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-04 10:57 - 2014-08-04 12:39 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-08-04 10:57 - 2014-08-04 10:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-04 10:57 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-08-04 10:57 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-08-04 10:57 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-08-04 10:56 - 2014-08-04 10:56 - 01016261 _____ (Thisisu) C:\Users\HomeBasic1\Downloads\JRT.exe
2014-08-04 10:55 - 2014-08-04 10:55 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\HomeBasic1\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-04 10:55 - 2014-08-04 10:55 - 01361309 _____ () C:\Users\HomeBasic1\Desktop\adwcleaner_3.302.exe
2014-08-04 10:04 - 2014-08-04 10:04 - 00008802 _____ () C:\ComboFix.txt
2014-08-04 09:51 - 2014-08-04 09:51 - 00003664 _____ () C:\Users\HomeBasic1\Downloads\CFScript.txt
2014-08-04 09:39 - 2014-08-03 20:19 - 00012824 _____ () C:\ComboFix - Kopie.txt
2014-08-04 08:29 - 2014-08-04 08:38 - 05566616 ____R (Swearware) C:\Users\HomeBasic1\Desktop\tb.exe
2014-08-04 08:25 - 2014-08-04 08:25 - 05566616 _____ () C:\Users\HomeBasic1\Downloads\ComboFix(1).exe.part
2014-08-03 19:39 - 2014-08-04 10:04 - 00000000 ____D () C:\Qoobox
2014-08-03 19:39 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-08-03 19:39 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-08-03 19:39 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-08-03 19:39 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-08-03 19:39 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-08-03 19:39 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-08-03 19:39 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-08-03 19:39 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-08-03 19:38 - 2014-08-03 20:18 - 00000000 ____D () C:\Windows\erdnt
2014-08-01 16:54 - 2014-08-01 16:55 - 05567414 _____ (Swearware) C:\Users\HomeBasic1\Downloads\ComboFix.exe
2014-08-01 16:54 - 2014-08-01 16:55 - 05537792 _____ (Swearware) C:\Users\HomeBasic1\Downloads\ComboFix.exe.part
2014-08-01 16:52 - 2014-08-01 16:52 - 00000000 ___HD () C:\Windows\PIF
2014-08-01 15:28 - 2014-08-01 15:28 - 00006915 _____ () C:\Users\HomeBasic1\Downloads\GMER.log
2014-08-01 15:10 - 2014-08-01 15:10 - 00380416 _____ () C:\Users\HomeBasic1\Downloads\Gmer-19357.exe
2014-08-01 15:05 - 2014-08-04 20:52 - 00007617 _____ () C:\Users\HomeBasic1\Downloads\FRST.txt
2014-08-01 15:05 - 2014-08-01 15:08 - 00030682 _____ () C:\Users\HomeBasic1\Downloads\FRST1.txt
2014-08-01 15:04 - 2014-08-04 20:52 - 00000000 ____D () C:\FRST
2014-08-01 15:04 - 2014-08-01 15:04 - 01084928 _____ (Farbar) C:\Users\HomeBasic1\Downloads\FRST.exe
2014-08-01 15:00 - 2014-08-01 15:00 - 00000660 _____ () C:\Users\HomeBasic1\Downloads\defogger_disable.log
2014-08-01 15:00 - 2014-08-01 15:00 - 00000204 _____ () C:\Users\HomeBasic1\defogger_reenable
2014-08-01 14:59 - 2014-08-01 15:00 - 00050477 _____ () C:\Users\HomeBasic1\Downloads\Defogger.exe
2014-08-01 13:44 - 2014-08-01 14:12 - 00000929 _____ () C:\Users\HomeBasic1\Downloads\Stinger_01082014_134433.html
2014-08-01 13:44 - 2014-08-01 13:44 - 01273068 _____ () C:\Users\HomeBasic1\Downloads\runtime.dat
2014-08-01 13:43 - 2014-08-01 13:43 - 10968424 _____ (McAfee Inc) C:\Users\HomeBasic1\Downloads\stinger32(1).exe
2014-07-30 09:50 - 2014-08-04 18:12 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-07-16 09:06 - 2014-06-18 12:21 - 00021452 _____ () C:\Users\HomeBasic1\Documents\Heidelberger02_Kündigung.odt
2014-07-14 07:59 - 2014-07-14 08:25 - 00000000 ____D () C:\Program Files\GetSolar
2014-07-14 07:59 - 2014-07-14 07:59 - 01101165 _____ (Ing.-Büro solar energie information ) C:\Users\HomeBasic1\Downloads\gs73inst.exe
2014-07-14 07:59 - 2014-07-14 07:59 - 00000917 _____ () C:\Users\HomeBasic1\Desktop\GetSolar.lnk
2014-07-14 07:59 - 2014-07-14 07:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GetSolar
2014-07-14 07:29 - 2014-08-04 17:19 - 00001041 _____ () C:\Users\HomeBasic1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-14 07:29 - 2014-08-04 17:19 - 00001011 _____ () C:\Users\HomeBasic1\Desktop\Search.lnk
2014-07-14 07:28 - 2014-07-14 07:28 - 00001017 _____ () C:\Users\Public\Desktop\PasswdFinder.lnk
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PasswdFinder
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\Program Files\PasswdFinder
2014-07-14 07:27 - 2014-07-14 07:27 - 04546280 _____ (PasswdFinder ) C:\Users\HomeBasic1\Downloads\Passwd25FinderInstaller.exe
2014-07-13 19:23 - 2014-07-13 19:23 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Local\Adobe
2014-07-11 07:44 - 2014-07-11 07:44 - 00911722 _____ () C:\Users\HomeBasic1\Downloads\bayernwerkantrge.zip
2014-07-10 17:28 - 2014-08-01 13:43 - 00000124 ___RH () C:\Users\HomeBasic1\Downloads\Stinger.opt
2014-07-10 15:01 - 2014-07-10 15:10 - 00000931 _____ () C:\Users\HomeBasic1\Downloads\Stinger_10072014_150139.html
2014-07-10 14:58 - 2014-07-10 14:58 - 00167344 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe.f9c1.deleteme
2014-07-10 14:58 - 2014-07-10 14:58 - 00000000 ____D () C:\Quarantine
2014-07-10 14:57 - 2014-07-10 15:01 - 00001039 _____ () C:\Users\HomeBasic1\Downloads\Stinger_10072014_145704.html
2014-07-10 14:56 - 2014-08-01 13:58 - 00000000 ____D () C:\Program Files\stinger
2014-07-10 14:56 - 2014-07-10 14:56 - 10959720 _____ (McAfee Inc) C:\Users\HomeBasic1\Downloads\stinger32.exe
2014-07-10 13:08 - 2014-08-04 11:02 - 00000000 __SHD () C:\Program Files\Windows Manager
2014-07-09 09:56 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 09:56 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 09:56 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 09:56 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 09:56 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 09:56 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 09:56 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 09:56 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 09:56 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 09:56 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 09:56 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 09:56 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 09:56 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 09:56 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 09:56 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 09:56 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 09:56 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 09:55 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 09:55 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 09:55 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 09:55 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 09:55 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 09:55 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 09:55 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 09:55 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 09:55 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 09:55 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 09:55 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 09:55 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 09:55 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 09:55 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 09:55 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 09:55 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 09:55 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 09:54 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 09:54 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 09:54 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 09:54 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-04 20:53 - 2014-08-04 20:51 - 00000000 ____D () C:\Users\HomeBasic1\Downloads\scan
2014-08-04 20:52 - 2014-08-01 15:05 - 00007617 _____ () C:\Users\HomeBasic1\Downloads\FRST.txt
2014-08-04 20:52 - 2014-08-01 15:04 - 00000000 ____D () C:\FRST
2014-08-04 20:37 - 2014-08-04 10:57 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-08-04 20:29 - 2009-07-14 06:34 - 00019760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-04 20:29 - 2009-07-14 06:34 - 00019760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-04 20:24 - 2014-08-04 20:24 - 00000022 _____ () C:\Windows\S.dirmngr
2014-08-04 20:24 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-04 20:24 - 2009-07-14 06:39 - 00046416 _____ () C:\Windows\setupact.log
2014-08-04 18:12 - 2014-07-30 09:50 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-08-04 18:12 - 2013-08-26 09:07 - 01288028 _____ () C:\Windows\WindowsUpdate.log
2014-08-04 18:10 - 2013-09-11 13:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-04 17:24 - 2014-08-04 17:24 - 00000000 ____D () C:\Windows\ERUNT
2014-08-04 17:20 - 2013-09-06 08:00 - 00415148 _____ () C:\Windows\PFRO.log
2014-08-04 17:19 - 2014-08-04 17:17 - 00000000 ____D () C:\AdwCleaner
2014-08-04 17:19 - 2014-07-14 07:29 - 00001041 _____ () C:\Users\HomeBasic1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-04 17:19 - 2014-07-14 07:29 - 00001011 _____ () C:\Users\HomeBasic1\Desktop\Search.lnk
2014-08-04 15:02 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Cursors
2014-08-04 12:39 - 2014-08-04 10:57 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-04 12:39 - 2014-08-04 10:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-04 12:39 - 2014-08-04 10:57 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-08-04 11:02 - 2014-07-10 13:08 - 00000000 __SHD () C:\Program Files\Windows Manager
2014-08-04 10:57 - 2014-08-04 10:57 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-04 10:56 - 2014-08-04 10:56 - 01016261 _____ (Thisisu) C:\Users\HomeBasic1\Downloads\JRT.exe
2014-08-04 10:55 - 2014-08-04 10:55 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\HomeBasic1\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-04 10:55 - 2014-08-04 10:55 - 01361309 _____ () C:\Users\HomeBasic1\Desktop\adwcleaner_3.302.exe
2014-08-04 10:04 - 2014-08-04 10:04 - 00008802 _____ () C:\ComboFix.txt
2014-08-04 10:04 - 2014-08-03 19:39 - 00000000 ____D () C:\Qoobox
2014-08-04 10:02 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-08-04 09:51 - 2014-08-04 09:51 - 00003664 _____ () C:\Users\HomeBasic1\Downloads\CFScript.txt
2014-08-04 09:45 - 2013-09-18 11:49 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\vlc
2014-08-04 09:44 - 2013-09-18 11:43 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-08-04 08:38 - 2014-08-04 08:29 - 05566616 ____R (Swearware) C:\Users\HomeBasic1\Desktop\tb.exe
2014-08-04 08:25 - 2014-08-04 08:25 - 05566616 _____ () C:\Users\HomeBasic1\Downloads\ComboFix(1).exe.part
2014-08-04 08:23 - 2013-08-28 18:10 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\BOM
2014-08-03 20:19 - 2014-08-04 09:39 - 00012824 _____ () C:\ComboFix - Kopie.txt
2014-08-03 20:19 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2014-08-03 20:19 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-08-03 20:18 - 2014-08-03 19:38 - 00000000 ____D () C:\Windows\erdnt
2014-08-03 19:34 - 2013-09-11 16:40 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\TeamViewer
2014-08-01 16:55 - 2014-08-01 16:54 - 05567414 _____ (Swearware) C:\Users\HomeBasic1\Downloads\ComboFix.exe
2014-08-01 16:55 - 2014-08-01 16:54 - 05537792 _____ (Swearware) C:\Users\HomeBasic1\Downloads\ComboFix.exe.part
2014-08-01 16:52 - 2014-08-01 16:52 - 00000000 ___HD () C:\Windows\PIF
2014-08-01 15:34 - 2014-03-24 15:06 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\Notepad++
2014-08-01 15:28 - 2014-08-01 15:28 - 00006915 _____ () C:\Users\HomeBasic1\Downloads\GMER.log
2014-08-01 15:10 - 2014-08-01 15:10 - 00380416 _____ () C:\Users\HomeBasic1\Downloads\Gmer-19357.exe
2014-08-01 15:08 - 2014-08-01 15:05 - 00030682 _____ () C:\Users\HomeBasic1\Downloads\FRST1.txt
2014-08-01 15:04 - 2014-08-01 15:04 - 01084928 _____ (Farbar) C:\Users\HomeBasic1\Downloads\FRST.exe
2014-08-01 15:00 - 2014-08-01 15:00 - 00000660 _____ () C:\Users\HomeBasic1\Downloads\defogger_disable.log
2014-08-01 15:00 - 2014-08-01 15:00 - 00000204 _____ () C:\Users\HomeBasic1\defogger_reenable
2014-08-01 15:00 - 2014-08-01 14:59 - 00050477 _____ () C:\Users\HomeBasic1\Downloads\Defogger.exe
2014-08-01 15:00 - 2013-08-26 09:29 - 00000000 ____D () C:\Users\HomeBasic1
2014-08-01 14:12 - 2014-08-01 13:44 - 00000929 _____ () C:\Users\HomeBasic1\Downloads\Stinger_01082014_134433.html
2014-08-01 13:58 - 2014-07-10 14:56 - 00000000 ____D () C:\Program Files\stinger
2014-08-01 13:44 - 2014-08-01 13:44 - 01273068 _____ () C:\Users\HomeBasic1\Downloads\runtime.dat
2014-08-01 13:43 - 2014-08-01 13:43 - 10968424 _____ (McAfee Inc) C:\Users\HomeBasic1\Downloads\stinger32(1).exe
2014-08-01 13:43 - 2014-07-10 17:28 - 00000124 ___RH () C:\Users\HomeBasic1\Downloads\Stinger.opt
2014-08-01 10:17 - 2013-08-28 18:10 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Roaming\GrabIt
2014-07-31 18:58 - 2013-08-28 18:14 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-07-30 13:54 - 2013-08-28 18:10 - 00000000 ____D () C:\Program Files\Biet-O-Matic
2014-07-16 09:06 - 2013-12-12 09:07 - 00000000 ____D () C:\Users\HomeBasic1\Documents\Fax
2014-07-16 08:50 - 2014-03-24 15:06 - 00000000 ____D () C:\Program Files\Notepad++
2014-07-14 08:25 - 2014-07-14 07:59 - 00000000 ____D () C:\Program Files\GetSolar
2014-07-14 07:59 - 2014-07-14 07:59 - 01101165 _____ (Ing.-Büro solar energie information ) C:\Users\HomeBasic1\Downloads\gs73inst.exe
2014-07-14 07:59 - 2014-07-14 07:59 - 00000917 _____ () C:\Users\HomeBasic1\Desktop\GetSolar.lnk
2014-07-14 07:59 - 2014-07-14 07:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GetSolar
2014-07-14 07:28 - 2014-07-14 07:28 - 00001017 _____ () C:\Users\Public\Desktop\PasswdFinder.lnk
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PasswdFinder
2014-07-14 07:28 - 2014-07-14 07:28 - 00000000 ____D () C:\Program Files\PasswdFinder
2014-07-14 07:27 - 2014-07-14 07:27 - 04546280 _____ (PasswdFinder ) C:\Users\HomeBasic1\Downloads\Passwd25FinderInstaller.exe
2014-07-13 19:23 - 2014-07-13 19:23 - 00000000 ____D () C:\Users\HomeBasic1\AppData\Local\Adobe
2014-07-11 10:05 - 2013-08-26 09:25 - 00000000 ____D () C:\Recovery
2014-07-11 07:53 - 2013-09-05 20:52 - 00000000 ____D () C:\Allerlei
2014-07-11 07:44 - 2014-07-11 07:44 - 00911722 _____ () C:\Users\HomeBasic1\Downloads\bayernwerkantrge.zip
2014-07-10 15:10 - 2014-07-10 15:01 - 00000931 _____ () C:\Users\HomeBasic1\Downloads\Stinger_10072014_150139.html
2014-07-10 15:01 - 2014-07-10 14:57 - 00001039 _____ () C:\Users\HomeBasic1\Downloads\Stinger_10072014_145704.html
2014-07-10 15:00 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-10 14:58 - 2014-07-10 14:58 - 00167344 _____ (McAfee, Inc.) C:\Windows\system32\mfevtps.exe.f9c1.deleteme
2014-07-10 14:58 - 2014-07-10 14:58 - 00000000 ____D () C:\Quarantine
2014-07-10 14:56 - 2014-07-10 14:56 - 10959720 _____ (McAfee Inc) C:\Users\HomeBasic1\Downloads\stinger32.exe
2014-07-10 14:22 - 2013-08-26 13:46 - 00000000 ____D () C:\ProgramData\Alwil Software
2014-07-10 14:22 - 2013-08-26 13:46 - 00000000 ____D () C:\Program Files\Alwil Software
2014-07-10 14:22 - 2009-07-14 04:04 - 00002577 _____ () C:\Windows\system32\config.nt
2014-07-10 08:42 - 2013-11-15 09:47 - 00000000 ____D () C:\Windows\rescache
2014-07-10 07:24 - 2009-07-14 06:33 - 00324536 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-10 07:22 - 2014-05-08 18:21 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-10 07:22 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-07-09 16:10 - 2013-09-11 13:52 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-09 16:10 - 2013-09-11 13:52 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-07 08:06 - 2014-06-21 08:45 - 00002544 _____ () C:\Windows\system32\TeamViewer9_Hooks.log
2014-07-07 08:06 - 2014-06-21 08:45 - 00001060 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-07-07 08:06 - 2014-06-21 08:45 - 00001048 _____ () C:\Users\Public\Desktop\TeamViewer 9.lnk

Some content of TEMP:
====================
C:\Users\HomeBasic1\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-30 08:52

==================== End Of Log ============================

--- --- ---

--- --- ---


Addition
Code:

Additional scan result of Farbar Recovery Scan Tool (x86) Version:31-07-2014 02
Ran by HomeBasic1 at 2014-08-04 21:02:51
Running from C:\Users\HomeBasic1\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (HKLM\...\7-Zip) (Version:  - )
Adobe Flash Player 14 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Biet-O-Matic v2.14.12 (HKLM\...\Biet-O-Matic v2.14.12) (Version: 2.14.12 - BOM Development Team)
CAD Draw 10 Release 2012 (HKLM\...\CAD Draw 10 Eco) (Version: 2012 Service Pack 2, 2013.0.1.11, 2013-01-11 - Malz++Kassner GmbH)
DriverPack Solution Updater (HKCU\...\DRPSu Updater) (Version: 0.0.25 - DriverPack Solution)
FileZilla Client 3.8.0 (HKLM\...\FileZilla Client) (Version: 3.8.0 - Tim Kosse)
FilterFTP (HKLM\...\FilterFTP_is1) (Version: Actual Version - IN MEDIA KG)
Foxit PhantomPDF (HKLM\...\{1A6F678C-BC3D-47CC-A125-713E58BED472}) (Version: 6.0.4.619 - Foxit Corporation)
GetSolar 7.3 (HKLM\...\GetSolar_is1) (Version: 7.3.10 - Ing.-Büro solar energie information)
Gpg4win (2.2.1) (HKLM\...\GPG4Win) (Version: 2.2.1 - The Gpg4win Project)
GrabIt 1.7.2 Beta 6 (build 1008) (HKLM\...\GrabIt_is1) (Version:  - Ilan Shemes)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
K-Lite Codec Pack 8.4.0 (Full) (HKLM\...\KLiteCodecPack_is1) (Version: 8.4.0 - )
LibreOffice 4.2.4.2 (HKLM\...\{6B4977CB-5B9F-4B24-8310-3BA527A8AF22}) (Version: 4.2.4.2 - The Document Foundation)
Magical Jelly Bean PasswdFinder (HKLM\...\PasswdFinder_is1) (Version: 1.0.0.25 - PasswdFinder)
Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Mozilla Firefox 31.0 (x86 de) (HKLM\...\Mozilla Firefox 31.0 (x86 de)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla)
Notepad++ (HKLM\...\Notepad++) (Version: 6.6.7 - Notepad++ Team)
Ravensburger tiptoi (HKLM\...\Ravensburger tiptoi) (Version:  - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6482 - Realtek Semiconductor Corp.)
SketchUp 2013 (HKLM\...\{2C0777B8-E91F-45AA-976B-7EB6B40E5400}) (Version: 13.0.4812 - Trimble Navigation Limited)
TeamViewer 9 (HKLM\...\TeamViewer 9) (Version: 9.0.29947 - TeamViewer)
VirtualCloneDrive (HKLM\...\VirtualCloneDrive) (Version:  - Elaborate Bytes)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Yahoo Community Smartbar Engine (HKCU\...\{9e649bf2-763f-4c09-8f97-906d058ee513}) (Version: 11.63.66.17714 - Linkury Inc.) <==== ATTENTION

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

01-08-2014 06:12:25 Windows Update
03-08-2014 17:39:47 ComboFix created restore point
03-08-2014 17:43:29 Windows-Sicherung

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {2C0BEB03-9F30-4407-B5BE-6ED86B72858D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan
Task: {59920169-F6A4-46B6-965E-BA2A42104B95} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {777A30B2-6D2C-4DB1-9FA7-67BE8E3D3899} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-09] (Adobe Systems Incorporated)
Task: {8BC4C4EE-5643-490F-90C0-B04B5651071C} - System32\Tasks\AviraSpeedup => C:\Program Files\Avira\AviraSpeedup\avira_system_speedup.exe
Task: {B7EFDB48-6BDB-4E9E-B752-63FCFA96E458} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2014-02-13 08:30 - 2013-10-17 17:32 - 00019448 _____ () C:\Windows\system32\spool\PRTPROCS\W32X86\TeamViewer_PrintProcessor.dll
2014-03-28 11:35 - 2014-03-28 11:35 - 00093696 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2013-10-07 16:54 - 2013-10-07 16:54 - 00218112 _____ () C:\Program Files\GNU\GnuPG\dirmngr.exe
2013-10-07 16:49 - 2013-10-07 16:49 - 00221184 _____ () C:\Program Files\GNU\GnuPG\libksba-8.dll
2013-10-07 16:47 - 2013-10-07 16:47 - 00037888 _____ () C:\Program Files\GNU\GnuPG\libgpg-error-0.dll
2013-10-07 16:44 - 2013-10-07 16:44 - 00050176 _____ () C:\Program Files\GNU\GnuPG\libw32pth-0.dll
2013-10-07 16:49 - 2013-10-07 16:49 - 00069632 _____ () C:\Program Files\GNU\GnuPG\libassuan-0.dll
2013-10-07 16:49 - 2013-10-07 16:49 - 00628224 _____ () C:\Program Files\GNU\GnuPG\libgcrypt-11.dll
2013-11-29 13:08 - 2013-07-24 10:24 - 00137728 _____ () C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll
2012-05-31 16:35 - 2012-05-31 16:35 - 00195256 ____R () C:\Users\HomeBasic1\AppData\Roaming\DRPSu\DrvUpdater.exe

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)


==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)


==================== Faulty Device Manager Devices =============

Name: PS/2-kompatible Maus
Description: PS/2-kompatible Maus
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: Standardtastatur (PS/2)
Description: Standardtastatur (PS/2)
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardtastaturen)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================

System errors:
=============
Error: (08/04/2014 08:25:20 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Windows Defender" wurde mit folgendem Fehler beendet:
%%-2147024891


Microsoft Office Sessions:
=========================


cosinus 05.08.2014 08:47

Zitat:

Hacktool.Agent, C:\Users\HomeBasic1\Downloads\Windows_Loader_v2.2.1.zip
Klasse! Dann noch mal viel Spaß mit deinem gecrackten Windows :stirn:

TOMROSSI 05.08.2014 10:13

Ja Mist, den PC hab ich so übernommen, super was soll ich jetzt machen?

cosinus 05.08.2014 10:33

Zitat:

Zitat von TOMROSSI (Beitrag 1340214)
Ja Mist, den PC hab ich so übernommen, super was soll ich jetzt machen?

Den, der dir den Rechner angedreht mal so richtig schön :zzwhip: und :twak:

:p

Zitat:

Platform: Microsoft Windows 7 Ultimate Service Pack 1
Hat der Rechner ne passende Lizenz? Hast du überhaupt nen Windows-Lizenzaufkleber auf diesem Rechner?

TOMROSSI 05.08.2014 10:41

Da klebt einer für Windows XP, nicht für Win7
Geschenke ist nicht immer umsonst :headbang:

cosinus 05.08.2014 10:55

Naja. Im Log seh ich aber sonst keinen Hinweis dazu, dass das Teil auch angewandt wurde, ich hab nur die ZIP-Datei gesehen. Da diese jetzt gelöscht ist (in Quarantäne) würde es unseren Anti-Crack-Regeln nicht wiedersprechen, weiterzumachen ;)

Vorausgesetzt du willst weiter bereinigen, denn du hast 1. ne üble Backdoor-Infektion und 2. ist unklar, ob der, der dir den Rechner angedreht hat, eine offizielle Windows-Setup-DVD benutzt hat oder sich irgendeinen Müll aus dem Netz lud, was wie Windows aussah, aber von Crackern mit Backdoors gespickt wurde...

TOMROSSI 05.08.2014 11:14

Hmm, da bin ich überfragt, so wie ich Dich jetzt verstehe, wenn diese Windows Version Backdoors hat, kommen die immer wieder zurück?
Wieviel Aufwand wäre es den Rechner zu säubern, evtl ist ja eine Neuinstallation sinnvoller, was meinst Du?

cosinus 05.08.2014 11:50

Nein, was ich sagen wollte ist, dass keiner weiß wie vertrauenswürdig das Installationsmedium war, mit dem dieses Windows installiert wurde. Wenn es also ne gecrackte Windows-Geschichte ist, kann also schon grundsätzlich da drin was faul sein, unabhängig davon was zuletzt für Hintertüren gefunden wurden (zB microsoft.com in system32)

Zitat:

Wieviel Aufwand wäre es den Rechner zu säubern, evtl ist ja eine Neuinstallation sinnvoller, was meinst Du?
Wir haben schon viel bereinigt mit CF und Malwarebytes, ob da noch Reste drin sind müssten wir checken. Dann sehen wir weiter.

Es gibt aber keine 100 % Sicherheit und erst recht keine Garantie, dass wir alle Schädlinge gekillt haben, auch wenn die Logs alle sauber sind.


Wenn du weiter machen willst: ich würde gern mal schauen, was das Kaspersky-Tool zu deinem Rechner meint:

Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.

TOMROSSI 05.08.2014 12:10

Kaspersky log
Code:

13:05:07.0179 0x0f84  TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58
13:05:10.0418 0x0f84  ============================================================
13:05:10.0419 0x0f84  Current date / time: 2014/08/05 13:05:10.0418
13:05:10.0419 0x0f84  SystemInfo:
13:05:10.0419 0x0f84 
13:05:10.0419 0x0f84  OS Version: 6.1.7601 ServicePack: 1.0
13:05:10.0419 0x0f84  Product type: Workstation
13:05:10.0419 0x0f84  ComputerName: HOMEBASIC1-PC
13:05:10.0420 0x0f84  UserName: HomeBasic1
13:05:10.0420 0x0f84  Windows directory: C:\Windows
13:05:10.0420 0x0f84  System windows directory: C:\Windows
13:05:10.0420 0x0f84  Processor architecture: Intel x86
13:05:10.0421 0x0f84  Number of processors: 2
13:05:10.0421 0x0f84  Page size: 0x1000
13:05:10.0421 0x0f84  Boot type: Normal boot
13:05:10.0421 0x0f84  ============================================================
13:05:11.0709 0x0f84  KLMD registered as C:\Windows\system32\drivers\14943351.sys
13:05:12.0443 0x0f84  System UUID: {8572C3A4-5C5C-A38F-E439-0BFD79AF1456}
13:05:13.0746 0x0f84  Drive \Device\Harddisk0\DR0 - Size: 0x9516AE000 ( 37.27 Gb ), SectorSize: 0x200, Cylinders: 0x1301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:05:13.0752 0x0f84  Drive \Device\Harddisk1\DR1 - Size: 0x12A1F16000 ( 74.53 Gb ), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
13:05:13.0762 0x0f84  ============================================================
13:05:13.0762 0x0f84  \Device\Harddisk0\DR0:
13:05:13.0762 0x0f84  MBR partitions:
13:05:13.0763 0x0f84  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4A852C1
13:05:13.0763 0x0f84  \Device\Harddisk1\DR1:
13:05:13.0763 0x0f84  MBR partitions:
13:05:13.0763 0x0f84  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
13:05:13.0763 0x0f84  \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x94DC800
13:05:13.0763 0x0f84  ============================================================
13:05:13.0785 0x0f84  C: <-> \Device\Harddisk1\DR1\Partition2
13:05:13.0795 0x0f84  D: <-> \Device\Harddisk0\DR0\Partition1
13:05:13.0795 0x0f84  ============================================================
13:05:13.0796 0x0f84  Initialize success
13:05:13.0796 0x0f84  ============================================================
13:05:35.0794 0x1a64c  ============================================================
13:05:35.0794 0x1a64c  Scan started
13:05:35.0794 0x1a64c  Mode: Manual; SigCheck; TDLFS;
13:05:35.0794 0x1a64c  ============================================================
13:05:35.0794 0x1a64c  KSN ping started
13:05:50.0652 0x1a64c  KSN ping finished: true
13:05:51.0328 0x1a64c  ================ Scan system memory ========================
13:05:51.0328 0x1a64c  System memory - ok
13:05:51.0328 0x1a64c  ================ Scan services =============================
13:05:51.0465 0x1a64c  [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
13:05:51.0658 0x1a64c  1394ohci - ok
13:05:51.0735 0x1a64c  [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI            C:\Windows\system32\drivers\ACPI.sys
13:05:51.0768 0x1a64c  ACPI - ok
13:05:51.0802 0x1a64c  [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi        C:\Windows\system32\drivers\acpipmi.sys
13:05:51.0885 0x1a64c  AcpiPmi - ok
13:05:51.0976 0x1a64c  [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
13:05:52.0001 0x1a64c  AdobeARMservice - ok
13:05:52.0086 0x1a64c  [ A6B6AB9502B63F43A9A56AE6AFB22078, DD1F0BA3D8F3333F52A71EAE3719A001F6EF844D647FFABF0E4C56C6C764ACA7 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
13:05:52.0116 0x1a64c  AdobeFlashPlayerUpdateSvc - ok
13:05:52.0182 0x1a64c  [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx        C:\Windows\system32\DRIVERS\adp94xx.sys
13:05:52.0222 0x1a64c  adp94xx - ok
13:05:52.0270 0x1a64c  [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci        C:\Windows\system32\DRIVERS\adpahci.sys
13:05:52.0355 0x1a64c  adpahci - ok
13:05:52.0437 0x1a64c  [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320        C:\Windows\system32\DRIVERS\adpu320.sys
13:05:52.0478 0x1a64c  adpu320 - ok
13:05:52.0541 0x1a64c  [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc    C:\Windows\System32\aelupsvc.dll
13:05:52.0624 0x1a64c  AeLookupSvc - ok
13:05:52.0669 0x1a64c  [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD            C:\Windows\system32\drivers\afd.sys
13:05:52.0742 0x1a64c  AFD - ok
13:05:52.0769 0x1a64c  [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440          C:\Windows\system32\drivers\agp440.sys
13:05:52.0794 0x1a64c  agp440 - ok
13:05:52.0835 0x1a64c  [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx        C:\Windows\system32\DRIVERS\djsvs.sys
13:05:52.0861 0x1a64c  aic78xx - ok
13:05:52.0902 0x1a64c  [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG            C:\Windows\System32\alg.exe
13:05:52.0976 0x1a64c  ALG - ok
13:05:53.0002 0x1a64c  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide          C:\Windows\system32\drivers\aliide.sys
13:05:53.0026 0x1a64c  aliide - ok
13:05:53.0057 0x1a64c  [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
13:05:53.0083 0x1a64c  amdagp - ok
13:05:53.0101 0x1a64c  [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide          C:\Windows\system32\drivers\amdide.sys
13:05:53.0125 0x1a64c  amdide - ok
13:05:53.0162 0x1a64c  [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8          C:\Windows\system32\DRIVERS\amdk8.sys
13:05:53.0226 0x1a64c  AmdK8 - ok
13:05:53.0249 0x1a64c  [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
13:05:53.0300 0x1a64c  AmdPPM - ok
13:05:53.0345 0x1a64c  [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata        C:\Windows\system32\drivers\amdsata.sys
13:05:53.0372 0x1a64c  amdsata - ok
13:05:53.0410 0x1a64c  [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
13:05:53.0438 0x1a64c  amdsbs - ok
13:05:53.0461 0x1a64c  [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata        C:\Windows\system32\drivers\amdxata.sys
13:05:53.0485 0x1a64c  amdxata - ok
13:05:53.0522 0x1a64c  [ AEA177F783E20150ACE5383EE368DA19, 8FA9EE27AA1F22E8B8FE33A21028CA1E0062BAA95CB132C20D55B98C03B4254F ] AppID          C:\Windows\system32\drivers\appid.sys
13:05:53.0659 0x1a64c  AppID - ok
13:05:53.0695 0x1a64c  [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc        C:\Windows\System32\appidsvc.dll
13:05:53.0755 0x1a64c  AppIDSvc - ok
13:05:53.0786 0x1a64c  [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo        C:\Windows\System32\appinfo.dll
13:05:53.0854 0x1a64c  Appinfo - ok
13:05:53.0885 0x1a64c  [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt        C:\Windows\System32\appmgmts.dll
13:05:53.0963 0x1a64c  AppMgmt - ok
13:05:54.0004 0x1a64c  [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc            C:\Windows\system32\DRIVERS\arc.sys
13:05:54.0031 0x1a64c  arc - ok
13:05:54.0045 0x1a64c  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
13:05:54.0073 0x1a64c  arcsas - ok
13:05:54.0152 0x1a64c  [ 9D768C43FEF254DD50B1DBF8AD5C4C0B, A50854EA5C08605133B8BB4DFDC6090357C5665314AA72E0BFA1E07D4E451F09 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
13:05:54.0182 0x1a64c  aspnet_state - ok
13:05:54.0210 0x1a64c  [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
13:05:54.0332 0x1a64c  AsyncMac - ok
13:05:54.0372 0x1a64c  [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi          C:\Windows\system32\drivers\atapi.sys
13:05:54.0396 0x1a64c  atapi - ok
13:05:54.0463 0x1a64c  [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
13:05:54.0548 0x1a64c  AudioEndpointBuilder - ok
13:05:54.0581 0x1a64c  [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] Audiosrv        C:\Windows\System32\Audiosrv.dll
13:05:54.0637 0x1a64c  Audiosrv - ok
13:05:54.0702 0x1a64c  [ 66005CD6AA6764265EC67AD1A3F4552F, B26BB4BA0FC5DF24F9C34CB9D5E8821216507142A222C9B51DA920F8BA7E4898 ] Avgdiskx        C:\Windows\system32\DRIVERS\avgdiskx.sys
13:05:54.0794 0x1a64c  Avgdiskx - ok
13:05:55.0113 0x1a64c  [ 20B2C28E3914C6837B30D44D31D2A294, CB10530525CD36146391ECFB8875A284B7EF71A84EBC96D078FB3D637E29A504 ] AVGIDSAgent    C:\Program Files\AVG\AVG2014\avgidsagent.exe
13:05:55.0300 0x1a64c  AVGIDSAgent - ok
13:05:55.0359 0x1a64c  [ 572AA32C47BDFD17D3F7411503215D1B, 62E2F46A4E45CE44B4DF8F898FF7CFE75B69B349F3C91959D353BBEC0F4DC83D ] AVGIDSDriver    C:\Windows\system32\DRIVERS\avgidsdriverx.sys
13:05:55.0401 0x1a64c  AVGIDSDriver - ok
13:05:55.0446 0x1a64c  [ C0701A3C53F0A0F5E4900F26365A10A1, 2755AF8C98F4855FD467F0174D6AE7AC3E7050D95008FE521918194593684D51 ] AVGIDSHX        C:\Windows\system32\DRIVERS\avgidshx.sys
13:05:55.0473 0x1a64c  AVGIDSHX - ok
13:05:55.0482 0x1a64c  [ E7FEE532CEF01C97D7682E35D156244F, CF54B4B83E1A060FF52BDEAC4E20492ACFAABC87BC6BE784D6AB4CD64C965B92 ] AVGIDSShim      C:\Windows\system32\DRIVERS\avgidsshimx.sys
13:05:55.0508 0x1a64c  AVGIDSShim - ok
13:05:55.0532 0x1a64c  [ FA868D5784DE755DD8A1B4B1A80574E4, 9300B4ACBDA96FA4FEE9265ED0E50F750C2B6F7BE854953B8FB73904679DBCA3 ] Avgldx86        C:\Windows\system32\DRIVERS\avgldx86.sys
13:05:55.0563 0x1a64c  Avgldx86 - ok
13:05:55.0616 0x1a64c  [ 8D37558421330218C98722DF4AD85E83, 24C33B317BA605DFC9B9CE2868391A815870A61F58A172806533A16F29F92B0A ] Avglogx        C:\Windows\system32\DRIVERS\avglogx.sys
13:05:55.0646 0x1a64c  Avglogx - ok
13:05:55.0658 0x1a64c  [ 5C3A4A2F473E614C1BF807FE2ABE0D05, 71E786EA1DCBC6ECB915E887B19C86E041C8E4373DAB28548D344323FD9D6CD2 ] Avgmfx86        C:\Windows\system32\DRIVERS\avgmfx86.sys
13:05:55.0684 0x1a64c  Avgmfx86 - ok
13:05:55.0711 0x1a64c  [ 86FCB8CE3E68C4777B98F7AF06FE8519, 6B7507DA927ECDBA8B2DAA87530DDAEAC5B0983D3CF11D1F6D00D36601FBC60C ] Avgrkx86        C:\Windows\system32\DRIVERS\avgrkx86.sys
13:05:55.0736 0x1a64c  Avgrkx86 - ok
13:05:55.0757 0x1a64c  [ ACFEE559442E1FCD48EC74C7D3452608, 536E36CD59BB1E0F5732D8BF57208A07C88A51D02FA016F844648CA0B44F0073 ] Avgtdix        C:\Windows\system32\DRIVERS\avgtdix.sys
13:05:55.0786 0x1a64c  Avgtdix - ok
13:05:55.0842 0x1a64c  [ 13BB5F8819F90CE30A967FD94823E21B, 01E4AE673D0E48EAFAE6D879AE1A5D7E385848CBC0FDE45BA0AE1F96D02BC65B ] avgwd          C:\Program Files\AVG\AVG2014\avgwdsvc.exe
13:05:55.0874 0x1a64c  avgwd - ok
13:05:55.0952 0x1a64c  [ 7692F4B242E45870873CAF4CB85CF769, 9D28627FD73F62134792528A9D2F2FCCBB0FDD7E45D8D7D816B9FC3C07AE4CA2 ] AxAutoMntSrv    C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
13:05:55.0975 0x1a64c  AxAutoMntSrv - ok
13:05:56.0016 0x1a64c  [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV        C:\Windows\System32\AxInstSV.dll
13:05:56.0104 0x1a64c  AxInstSV - ok
13:05:56.0155 0x1a64c  [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv        C:\Windows\system32\DRIVERS\bxvbdx.sys
13:05:56.0231 0x1a64c  b06bdrv - ok
13:05:56.0285 0x1a64c  [ 15BCC5D933510D146B1EAFEC0448A0CE, F9614F483163EB859AD352AC2CECC7F0B1028F3F818309ABD622C4A660077A31 ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
13:05:56.0318 0x1a64c  b57nd60x - ok
13:05:56.0370 0x1a64c  [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC          C:\Windows\System32\bdesvc.dll
13:05:56.0500 0x1a64c  BDESVC - ok
13:05:56.0531 0x1a64c  [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep            C:\Windows\system32\drivers\Beep.sys
13:05:56.0582 0x1a64c  Beep - ok
13:05:56.0643 0x1a64c  [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE            C:\Windows\System32\bfe.dll
13:05:56.0733 0x1a64c  BFE - ok
13:05:56.0787 0x1a64c  [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS            C:\Windows\system32\qmgr.dll
13:05:56.0909 0x1a64c  BITS - ok
13:05:56.0942 0x1a64c  [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
13:05:56.0986 0x1a64c  blbdrive - ok
13:05:57.0040 0x1a64c  [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
13:05:57.0107 0x1a64c  bowser - ok
13:05:57.0127 0x1a64c  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
13:05:57.0185 0x1a64c  BrFiltLo - ok
13:05:57.0207 0x1a64c  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
13:05:57.0260 0x1a64c  BrFiltUp - ok
13:05:57.0346 0x1a64c  [ 77361D72A04F18809D0EFB6CCEB74D4B, 55E7DB65BB29FF421F138CDFF05E5ECFFC7C8862FAA68F6179A3BA9D6B69AE64 ] BridgeMP        C:\Windows\system32\DRIVERS\bridge.sys
13:05:57.0413 0x1a64c  BridgeMP - ok
13:05:57.0461 0x1a64c  [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser        C:\Windows\System32\browser.dll
13:05:57.0500 0x1a64c  Browser - ok
13:05:57.0529 0x1a64c  [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid        C:\Windows\System32\Drivers\Brserid.sys
13:05:57.0614 0x1a64c  Brserid - ok
13:05:57.0643 0x1a64c  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
13:05:57.0699 0x1a64c  BrSerWdm - ok
13:05:57.0723 0x1a64c  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
13:05:57.0773 0x1a64c  BrUsbMdm - ok
13:05:57.0798 0x1a64c  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
13:05:57.0847 0x1a64c  BrUsbSer - ok
13:05:57.0883 0x1a64c  [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
13:05:57.0931 0x1a64c  BTHMODEM - ok
13:05:57.0979 0x1a64c  [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv        C:\Windows\system32\bthserv.dll
13:05:58.0055 0x1a64c  bthserv - ok
13:05:58.0159 0x1a64c  catchme - ok
13:05:58.0185 0x1a64c  [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
13:05:58.0252 0x1a64c  cdfs - ok
13:05:58.0313 0x1a64c  [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom          C:\Windows\system32\DRIVERS\cdrom.sys
13:05:58.0362 0x1a64c  cdrom - ok
13:05:58.0407 0x1a64c  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc    C:\Windows\System32\certprop.dll
13:05:58.0478 0x1a64c  CertPropSvc - ok
13:05:58.0515 0x1a64c  [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
13:05:58.0551 0x1a64c  circlass - ok
13:05:58.0619 0x1a64c  [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS            C:\Windows\system32\CLFS.sys
13:05:58.0653 0x1a64c  CLFS - ok
13:05:58.0705 0x1a64c  [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
13:05:58.0732 0x1a64c  clr_optimization_v2.0.50727_32 - ok
13:05:58.0767 0x1a64c  [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
13:05:58.0798 0x1a64c  clr_optimization_v4.0.30319_32 - ok
13:05:58.0828 0x1a64c  [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
13:05:58.0858 0x1a64c  CmBatt - ok
13:05:58.0890 0x1a64c  [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
13:05:58.0920 0x1a64c  cmdide - ok
13:05:58.0963 0x1a64c  [ 85449EEBE8F8EBD6481EFBF0F352B4EB, E6FF04970C5A5BFDE7297A86C1C7B9BFE2E0F976A1A1AFB874CEB488DC6151CC ] CNG            C:\Windows\system32\Drivers\cng.sys
13:05:59.0008 0x1a64c  CNG - ok
13:05:59.0027 0x1a64c  [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
13:05:59.0053 0x1a64c  Compbatt - ok
13:05:59.0087 0x1a64c  [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
13:05:59.0122 0x1a64c  CompositeBus - ok
13:05:59.0139 0x1a64c  COMSysApp - ok
13:05:59.0166 0x1a64c  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk        C:\Windows\system32\DRIVERS\crcdisk.sys
13:05:59.0193 0x1a64c  crcdisk - ok
13:05:59.0259 0x1a64c  [ 7CA1BECEA5DE2643ADDAD32670E7A4C9, E3AB4CC52A97E3855D7EAB87363F807FDD2162ED8C76A036CD71549ED64E7797 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
13:05:59.0341 0x1a64c  CryptSvc - ok
13:05:59.0401 0x1a64c  [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC            C:\Windows\system32\drivers\csc.sys
13:05:59.0468 0x1a64c  CSC - ok
13:05:59.0516 0x1a64c  [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] CscService      C:\Windows\System32\cscsvc.dll
13:05:59.0587 0x1a64c  CscService - ok
13:05:59.0641 0x1a64c  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch      C:\Windows\system32\rpcss.dll
13:05:59.0722 0x1a64c  DcomLaunch - ok
13:05:59.0766 0x1a64c  [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc      C:\Windows\System32\defragsvc.dll
13:05:59.0821 0x1a64c  defragsvc - ok
13:05:59.0862 0x1a64c  [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
13:05:59.0922 0x1a64c  DfsC - ok
13:05:59.0973 0x1a64c  [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp            C:\Windows\system32\dhcpcore.dll
13:06:00.0026 0x1a64c  Dhcp - ok
13:06:00.0085 0x1a64c  [ 05F99DFF3A8D705F9AA6B87224F7BEB1, DDE133A44A330A07A0EB961559C840BBFC9D9E0CCA27DE0B4284C76BCAD31EDE ] DirMngr        C:\Program Files\GNU\GnuPG\dirmngr.exe
13:06:00.0125 0x1a64c  DirMngr - detected UnsignedFile.Multi.Generic ( 1 )
13:06:02.0904 0x1a64c  Detect skipped due to KSN trusted
13:06:02.0904 0x1a64c  DirMngr - ok
13:06:02.0925 0x1a64c  [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache        C:\Windows\system32\drivers\discache.sys
13:06:02.0971 0x1a64c  discache - ok
13:06:03.0013 0x1a64c  [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk            C:\Windows\system32\DRIVERS\disk.sys
13:06:03.0041 0x1a64c  Disk - ok
13:06:03.0063 0x1a64c  [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache        C:\Windows\System32\dnsrslvr.dll
13:06:03.0139 0x1a64c  Dnscache - ok
13:06:03.0174 0x1a64c  [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc        C:\Windows\System32\dot3svc.dll
13:06:03.0264 0x1a64c  dot3svc - ok
13:06:03.0324 0x1a64c  [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS            C:\Windows\system32\dps.dll
13:06:03.0393 0x1a64c  DPS - ok
13:06:03.0441 0x1a64c  [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud        C:\Windows\system32\drivers\drmkaud.sys
13:06:03.0511 0x1a64c  drmkaud - ok
13:06:03.0576 0x1a64c  [ 71BC35067CABC02C9453AEAA42B2E43E, 713B19F2C08EA5E4C087F7A74A8856932CF33E19D63384823DD4E02ED8798619 ] DXGKrnl        C:\Windows\System32\drivers\dxgkrnl.sys
13:06:03.0625 0x1a64c  DXGKrnl - ok
13:06:03.0673 0x1a64c  [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost        C:\Windows\System32\eapsvc.dll
13:06:03.0745 0x1a64c  EapHost - ok
13:06:03.0912 0x1a64c  [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv          C:\Windows\system32\DRIVERS\evbdx.sys
13:06:04.0126 0x1a64c  ebdrv - ok
13:06:04.0176 0x1a64c  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] EFS            C:\Windows\System32\lsass.exe
13:06:04.0227 0x1a64c  EFS - ok
13:06:04.0304 0x1a64c  [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr        C:\Windows\ehome\ehRecvr.exe
13:06:04.0426 0x1a64c  ehRecvr - ok
13:06:04.0453 0x1a64c  [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched        C:\Windows\ehome\ehsched.exe
13:06:04.0548 0x1a64c  ehSched - ok
13:06:04.0610 0x1a64c  [ D71233D7CCC2E64F8715A20428D5A33B, ECCF5820CFFFC083EA6A5D310E2E09CA61C0DCFEE1E58AD94D2A565CA86A87F3 ] ElbyCDIO        C:\Windows\system32\Drivers\ElbyCDIO.sys
13:06:04.0645 0x1a64c  ElbyCDIO - ok
13:06:04.0699 0x1a64c  [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor        C:\Windows\system32\DRIVERS\elxstor.sys
13:06:04.0761 0x1a64c  elxstor - ok
13:06:04.0791 0x1a64c  [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
13:06:04.0855 0x1a64c  ErrDev - ok
13:06:04.0927 0x1a64c  [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem    C:\Windows\system32\es.dll
13:06:05.0033 0x1a64c  EventSystem - ok
13:06:05.0080 0x1a64c  [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat          C:\Windows\system32\drivers\exfat.sys
13:06:05.0179 0x1a64c  exfat - ok
13:06:05.0225 0x1a64c  [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat        C:\Windows\system32\drivers\fastfat.sys
13:06:05.0324 0x1a64c  fastfat - ok
13:06:05.0400 0x1a64c  [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax            C:\Windows\system32\fxssvc.exe
13:06:05.0522 0x1a64c  Fax - ok
13:06:05.0553 0x1a64c  [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc            C:\Windows\system32\DRIVERS\fdc.sys
13:06:05.0626 0x1a64c  fdc - ok
13:06:05.0661 0x1a64c  [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost        C:\Windows\system32\fdPHost.dll
13:06:05.0707 0x1a64c  fdPHost - ok
13:06:05.0722 0x1a64c  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub        C:\Windows\system32\fdrespub.dll
13:06:05.0769 0x1a64c  FDResPub - ok
13:06:05.0784 0x1a64c  [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
13:06:05.0812 0x1a64c  FileInfo - ok
13:06:05.0833 0x1a64c  [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace      C:\Windows\system32\drivers\filetrace.sys
13:06:05.0883 0x1a64c  Filetrace - ok
13:06:05.0912 0x1a64c  [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
13:06:05.0959 0x1a64c  flpydisk - ok
13:06:05.0996 0x1a64c  [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
13:06:06.0031 0x1a64c  FltMgr - ok
13:06:06.0091 0x1a64c  [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache      C:\Windows\system32\FntCache.dll
13:06:06.0212 0x1a64c  FontCache - ok
13:06:06.0294 0x1a64c  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
13:06:06.0319 0x1a64c  FontCache3.0.0.0 - ok
13:06:06.0359 0x1a64c  [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends      C:\Windows\system32\drivers\FsDepends.sys
13:06:06.0385 0x1a64c  FsDepends - ok
13:06:06.0411 0x1a64c  [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
13:06:06.0438 0x1a64c  Fs_Rec - ok
13:06:06.0477 0x1a64c  [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
13:06:06.0512 0x1a64c  fvevol - ok
13:06:06.0538 0x1a64c  [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
13:06:06.0567 0x1a64c  gagp30kx - ok
13:06:06.0619 0x1a64c  [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc          C:\Windows\System32\gpsvc.dll
13:06:06.0705 0x1a64c  gpsvc - ok
13:06:06.0729 0x1a64c  [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
13:06:06.0797 0x1a64c  hcw85cir - ok
13:06:06.0848 0x1a64c  [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
13:06:06.0913 0x1a64c  HdAudAddService - ok
13:06:06.0953 0x1a64c  [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
13:06:06.0988 0x1a64c  HDAudBus - ok
13:06:07.0015 0x1a64c  [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt        C:\Windows\system32\DRIVERS\HidBatt.sys
13:06:07.0051 0x1a64c  HidBatt - ok
13:06:07.0075 0x1a64c  [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
13:06:07.0127 0x1a64c  HidBth - ok
13:06:07.0154 0x1a64c  [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr          C:\Windows\system32\DRIVERS\hidir.sys
13:06:07.0189 0x1a64c  HidIr - ok
13:06:07.0219 0x1a64c  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv        C:\Windows\System32\hidserv.dll
13:06:07.0459 0x1a64c  hidserv - ok
13:06:07.0547 0x1a64c  [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
13:06:07.0641 0x1a64c  HidUsb - ok
13:06:07.0666 0x1a64c  [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc          C:\Windows\system32\kmsvc.dll
13:06:07.0733 0x1a64c  hkmsvc - ok
13:06:07.0776 0x1a64c  [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
13:06:07.0856 0x1a64c  HomeGroupListener - ok
13:06:07.0886 0x1a64c  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
13:06:07.0948 0x1a64c  HomeGroupProvider - ok
13:06:08.0000 0x1a64c  [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
13:06:08.0033 0x1a64c  HpSAMD - ok
13:06:08.0088 0x1a64c  [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
13:06:08.0156 0x1a64c  HTTP - ok
13:06:08.0216 0x1a64c  [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
13:06:08.0244 0x1a64c  hwpolicy - ok
13:06:08.0294 0x1a64c  [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
13:06:08.0331 0x1a64c  i8042prt - ok
13:06:08.0377 0x1a64c  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV        C:\Windows\system32\drivers\iaStorV.sys
13:06:08.0416 0x1a64c  iaStorV - ok
13:06:08.0494 0x1a64c  [ C521D7EB6497BB1AF6AFA89E322FB43C, BDDCFCBB5B76A9295669B5AC9F732D6127199ED5C300770B554C4E4794F66BB7 ] idsvc          C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
13:06:08.0548 0x1a64c  idsvc - ok
13:06:08.0576 0x1a64c  IEEtwCollectorService - ok
13:06:08.0815 0x1a64c  [ 9467514EA189475A6E7FDC5D7BDE9D3F, E6F5B99BF6B614832770F9310B06334A8174C7660DDEC7589433640527A14683 ] igfx            C:\Windows\system32\DRIVERS\igdkmd32.sys
13:06:09.0139 0x1a64c  igfx - ok
13:06:09.0193 0x1a64c  [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp          C:\Windows\system32\DRIVERS\iirsp.sys
13:06:09.0221 0x1a64c  iirsp - ok
13:06:09.0277 0x1a64c  [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT          C:\Windows\System32\ikeext.dll
13:06:09.0385 0x1a64c  IKEEXT - ok
13:06:09.0576 0x1a64c  [ 345AC48D17F5C2F2AA1EE50D34C3978B, B43FD9B1B126AED8EBF4A435C9524A526FB703536040587BDD298CCCFC746518 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
13:06:09.0782 0x1a64c  IntcAzAudAddService - ok
13:06:09.0830 0x1a64c  [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide        C:\Windows\system32\drivers\intelide.sys
13:06:09.0859 0x1a64c  intelide - ok
13:06:09.0901 0x1a64c  [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
13:06:09.0952 0x1a64c  intelppm - ok
13:06:09.0985 0x1a64c  [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum      C:\Windows\system32\ipbusenum.dll
13:06:10.0075 0x1a64c  IPBusEnum - ok
13:06:10.0103 0x1a64c  [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:06:10.0165 0x1a64c  IpFilterDriver - ok
13:06:10.0243 0x1a64c  [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
13:06:10.0320 0x1a64c  iphlpsvc - ok
13:06:10.0353 0x1a64c  [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV        C:\Windows\system32\drivers\IPMIDrv.sys
13:06:10.0400 0x1a64c  IPMIDRV - ok
13:06:10.0440 0x1a64c  [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT          C:\Windows\system32\drivers\ipnat.sys
13:06:10.0490 0x1a64c  IPNAT - ok
13:06:10.0515 0x1a64c  [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
13:06:10.0573 0x1a64c  IRENUM - ok
13:06:10.0588 0x1a64c  [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
13:06:10.0620 0x1a64c  isapnp - ok
13:06:10.0664 0x1a64c  [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
13:06:10.0698 0x1a64c  iScsiPrt - ok
13:06:10.0733 0x1a64c  [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
13:06:10.0762 0x1a64c  kbdclass - ok
13:06:10.0797 0x1a64c  [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
13:06:10.0841 0x1a64c  kbdhid - ok
13:06:10.0871 0x1a64c  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] KeyIso          C:\Windows\system32\lsass.exe
13:06:10.0904 0x1a64c  KeyIso - ok
13:06:10.0933 0x1a64c  [ 4120DA10AA42A9996F4575DB9E3E6E6E, 1C6E790772EA327ACB885D731A030408160534997DD56FEE4D6CEE6929873BB8 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
13:06:10.0962 0x1a64c  KSecDD - ok
13:06:10.0982 0x1a64c  [ D3964885F0A11ACF51DA3AAA776973B2, 417ED5A3201FC50FBC0D646F8F2114A1E8A91E7919A62508DCBC156C0BFB2FBA ] KSecPkg        C:\Windows\system32\Drivers\ksecpkg.sys
13:06:11.0014 0x1a64c  KSecPkg - ok
13:06:11.0055 0x1a64c  [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm          C:\Windows\system32\msdtckrm.dll
13:06:11.0137 0x1a64c  KtmRm - ok
13:06:11.0192 0x1a64c  [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer    C:\Windows\System32\srvsvc.dll
13:06:11.0245 0x1a64c  LanmanServer - ok
13:06:11.0292 0x1a64c  [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
13:06:11.0363 0x1a64c  LanmanWorkstation - ok
13:06:11.0416 0x1a64c  [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
13:06:11.0463 0x1a64c  lltdio - ok
13:06:11.0496 0x1a64c  [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc        C:\Windows\System32\lltdsvc.dll
13:06:11.0573 0x1a64c  lltdsvc - ok
13:06:11.0604 0x1a64c  [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts        C:\Windows\System32\lmhsvc.dll
13:06:11.0654 0x1a64c  lmhosts - ok
13:06:11.0683 0x1a64c  [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
13:06:11.0713 0x1a64c  LSI_FC - ok
13:06:11.0726 0x1a64c  [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS        C:\Windows\system32\DRIVERS\lsi_sas.sys
13:06:11.0756 0x1a64c  LSI_SAS - ok
13:06:11.0767 0x1a64c  [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
13:06:11.0796 0x1a64c  LSI_SAS2 - ok
13:06:11.0808 0x1a64c  [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
13:06:11.0840 0x1a64c  LSI_SCSI - ok
13:06:11.0875 0x1a64c  [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv          C:\Windows\system32\drivers\luafv.sys
13:06:11.0925 0x1a64c  luafv - ok
13:06:11.0977 0x1a64c  [ 8683C1B450F4B3872839308D836E0F92, C6CEEEA780D2191AEAC2537FD96324FF5501D92CE46313FB95ABB51765D919ED ] MBAMProtector  C:\Windows\system32\drivers\mbam.sys
13:06:12.0004 0x1a64c  MBAMProtector - ok
13:06:12.0157 0x1a64c  [ D84AEA3F3329D622DFC1297DDDF6163B, 316FE56CC30ED1473A917253F46B79EAA12F4ABD5B4B1ADB03929DFEE940F577 ] MBAMScheduler  C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
13:06:12.0266 0x1a64c  MBAMScheduler - ok
13:06:12.0329 0x1a64c  [ 4F45ED469906494F9BF754E476390DBD, D8FF6AFD73D8C191F5732DF9737E6F83B2B52B06A3A6CD4CC6EAC9464CBB2772 ] MBAMService    C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
13:06:12.0401 0x1a64c  MBAMService - ok
13:06:12.0444 0x1a64c  [ 12E71DA845D76665B56753AD149E32B3, 0E403710CCBACD5AB85FD4C32AAB6CB2C27BC1F043E8008EE49EE96ECA944146 ] MBAMSwissArmy  C:\Windows\system32\drivers\MBAMSwissArmy.sys
13:06:12.0473 0x1a64c  MBAMSwissArmy - ok
13:06:12.0514 0x1a64c  [ BD27D97297934FD4217A37FD28A7ABC7, 446F3D6D278A4B3B79B331AA325632FD038952E5E910FC927894E9171A623794 ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
13:06:12.0542 0x1a64c  MBAMWebAccessControl - ok
13:06:12.0576 0x1a64c  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc        C:\Windows\system32\Mcx2Svc.dll
13:06:12.0649 0x1a64c  Mcx2Svc - ok
13:06:12.0677 0x1a64c  [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas        C:\Windows\system32\DRIVERS\megasas.sys
13:06:12.0706 0x1a64c  megasas - ok
13:06:12.0738 0x1a64c  [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
13:06:12.0776 0x1a64c  MegaSR - ok
13:06:12.0789 0x1a64c  mfehidk - ok
13:06:12.0799 0x1a64c  mferkdet - ok
13:06:12.0811 0x1a64c  mfevtp - ok
13:06:12.0837 0x1a64c  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS          C:\Windows\system32\mmcss.dll
13:06:12.0901 0x1a64c  MMCSS - ok
13:06:12.0926 0x1a64c  [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem          C:\Windows\system32\drivers\modem.sys
13:06:12.0990 0x1a64c  Modem - ok
13:06:13.0029 0x1a64c  [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor        C:\Windows\system32\DRIVERS\monitor.sys
13:06:13.0076 0x1a64c  monitor - ok
13:06:13.0113 0x1a64c  [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
13:06:13.0148 0x1a64c  mouclass - ok
13:06:13.0187 0x1a64c  [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
13:06:13.0240 0x1a64c  mouhid - ok
13:06:13.0291 0x1a64c  [ FC8771F45ECCCFD89684E38842539B9B, 806DDF2B4830CA866582FE74A521BB7DF26CA0E19013DAF584D3677FB48CC77A ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
13:06:13.0321 0x1a64c  mountmgr - ok
13:06:13.0375 0x1a64c  [ 4E9D8041D352A33332FD6F59A3A78B03, D4E6229B07EF9866993EEE4F6223DC7F1FF1108273FE14A3DC74E65C181DE56A ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
13:06:13.0411 0x1a64c  MozillaMaintenance - ok
13:06:13.0433 0x1a64c  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio            C:\Windows\system32\drivers\mpio.sys
13:06:13.0464 0x1a64c  mpio - ok
13:06:13.0500 0x1a64c  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
13:06:13.0564 0x1a64c  mpsdrv - ok
13:06:13.0627 0x1a64c  [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc          C:\Windows\system32\mpssvc.dll
13:06:13.0722 0x1a64c  MpsSvc - ok
13:06:13.0768 0x1a64c  [ 21F4B24ACFC79A483515BD986DD9043F, 22681907E02E0B723ABE2CEF0602D36C8EF862E7E2B62A9B40A5EF582E58D7BA ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
13:06:13.0809 0x1a64c  MRxDAV - ok
13:06:13.0854 0x1a64c  [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
13:06:14.0033 0x1a64c  mrxsmb - ok
13:06:14.0122 0x1a64c  [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:06:14.0282 0x1a64c  mrxsmb10 - ok
13:06:14.0311 0x1a64c  [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:06:14.0365 0x1a64c  mrxsmb20 - ok
13:06:14.0393 0x1a64c  [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci          C:\Windows\system32\drivers\msahci.sys
13:06:14.0424 0x1a64c  msahci - ok
13:06:14.0453 0x1a64c  [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm          C:\Windows\system32\drivers\msdsm.sys
13:06:14.0484 0x1a64c  msdsm - ok
13:06:14.0507 0x1a64c  [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC          C:\Windows\System32\msdtc.exe
13:06:14.0569 0x1a64c  MSDTC - ok
13:06:14.0626 0x1a64c  [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs            C:\Windows\system32\drivers\Msfs.sys
13:06:14.0679 0x1a64c  Msfs - ok
13:06:14.0697 0x1a64c  [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf      C:\Windows\System32\drivers\mshidkmdf.sys
13:06:14.0760 0x1a64c  mshidkmdf - ok
13:06:14.0795 0x1a64c  [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
13:06:14.0826 0x1a64c  msisadrv - ok
13:06:14.0876 0x1a64c  [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI        C:\Windows\system32\iscsiexe.dll
13:06:14.0935 0x1a64c  MSiSCSI - ok
13:06:14.0943 0x1a64c  msiserver - ok
13:06:14.0980 0x1a64c  [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV        C:\Windows\system32\drivers\MSKSSRV.sys
13:06:15.0028 0x1a64c  MSKSSRV - ok
13:06:15.0055 0x1a64c  [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
13:06:15.0103 0x1a64c  MSPCLOCK - ok
13:06:15.0124 0x1a64c  [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM          C:\Windows\system32\drivers\MSPQM.sys
13:06:15.0219 0x1a64c  MSPQM - ok
13:06:15.0258 0x1a64c  [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC          C:\Windows\system32\drivers\MsRPC.sys
13:06:15.0293 0x1a64c  MsRPC - ok
13:06:15.0330 0x1a64c  [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
13:06:15.0358 0x1a64c  mssmbios - ok
13:06:15.0383 0x1a64c  [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE          C:\Windows\system32\drivers\MSTEE.sys
13:06:15.0436 0x1a64c  MSTEE - ok
13:06:15.0453 0x1a64c  [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
13:06:15.0501 0x1a64c  MTConfig - ok
13:06:15.0526 0x1a64c  [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup            C:\Windows\system32\Drivers\mup.sys
13:06:15.0559 0x1a64c  Mup - ok
13:06:15.0600 0x1a64c  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent        C:\Windows\system32\qagentRT.dll
13:06:15.0663 0x1a64c  napagent - ok
13:06:15.0712 0x1a64c  [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP    C:\Windows\system32\DRIVERS\nwifi.sys
13:06:15.0760 0x1a64c  NativeWifiP - ok
13:06:15.0814 0x1a64c  [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS            C:\Windows\system32\drivers\ndis.sys
13:06:15.0868 0x1a64c  NDIS - ok
13:06:15.0898 0x1a64c  [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap        C:\Windows\system32\DRIVERS\ndiscap.sys
13:06:15.0958 0x1a64c  NdisCap - ok
13:06:15.0995 0x1a64c  [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
13:06:16.0058 0x1a64c  NdisTapi - ok
13:06:16.0097 0x1a64c  [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio        C:\Windows\system32\DRIVERS\ndisuio.sys
13:06:16.0145 0x1a64c  Ndisuio - ok
13:06:16.0178 0x1a64c  [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan        C:\Windows\system32\DRIVERS\ndiswan.sys
13:06:16.0239 0x1a64c  NdisWan - ok
13:06:16.0272 0x1a64c  [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy        C:\Windows\system32\drivers\NDProxy.sys
13:06:16.0328 0x1a64c  NDProxy - ok
13:06:16.0376 0x1a64c  [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS        C:\Windows\system32\DRIVERS\netbios.sys
13:06:16.0443 0x1a64c  NetBIOS - ok
13:06:16.0482 0x1a64c  [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT          C:\Windows\system32\DRIVERS\netbt.sys
13:06:16.0536 0x1a64c  NetBT - ok
13:06:16.0556 0x1a64c  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] Netlogon        C:\Windows\system32\lsass.exe
13:06:16.0589 0x1a64c  Netlogon - ok
13:06:16.0622 0x1a64c  [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman          C:\Windows\System32\netman.dll
13:06:16.0703 0x1a64c  Netman - ok
13:06:16.0750 0x1a64c  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:06:16.0785 0x1a64c  NetMsmqActivator - ok
13:06:16.0798 0x1a64c  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:06:16.0835 0x1a64c  NetPipeActivator - ok
13:06:16.0871 0x1a64c  [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm        C:\Windows\System32\netprofm.dll
13:06:16.0949 0x1a64c  netprofm - ok
13:06:16.0962 0x1a64c  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:06:17.0001 0x1a64c  NetTcpActivator - ok
13:06:17.0018 0x1a64c  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
13:06:17.0053 0x1a64c  NetTcpPortSharing - ok
13:06:17.0092 0x1a64c  [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960        C:\Windows\system32\DRIVERS\nfrd960.sys
13:06:17.0123 0x1a64c  nfrd960 - ok
13:06:17.0157 0x1a64c  [ 374071043F9E4231EE43BE2BB48DD36D, C4FA3FC40CC49DBBB91901D14210A55D3831FAC9F9B3FF45FCA7F5CF242C9E92 ] NlaSvc          C:\Windows\System32\nlasvc.dll
13:06:17.0223 0x1a64c  NlaSvc - ok
13:06:17.0252 0x1a64c  [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
13:06:17.0301 0x1a64c  Npfs - ok
13:06:17.0326 0x1a64c  [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi            C:\Windows\system32\nsisvc.dll
13:06:17.0375 0x1a64c  nsi - ok
13:06:17.0396 0x1a64c  [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
13:06:17.0448 0x1a64c  nsiproxy - ok
13:06:17.0526 0x1a64c  [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
13:06:17.0616 0x1a64c  Ntfs - ok
13:06:17.0641 0x1a64c  [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null            C:\Windows\system32\drivers\Null.sys
13:06:17.0703 0x1a64c  Null - ok
13:06:17.0742 0x1a64c  [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
13:06:17.0775 0x1a64c  nvraid - ok
13:06:17.0806 0x1a64c  [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
13:06:17.0840 0x1a64c  nvstor - ok
13:06:17.0865 0x1a64c  [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
13:06:17.0897 0x1a64c  nv_agp - ok
13:06:17.0928 0x1a64c  [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
13:06:17.0969 0x1a64c  ohci1394 - ok
13:06:18.0002 0x1a64c  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
13:06:18.0090 0x1a64c  p2pimsvc - ok
13:06:18.0129 0x1a64c  [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc          C:\Windows\system32\p2psvc.dll
13:06:18.0190 0x1a64c  p2psvc - ok
13:06:18.0237 0x1a64c  [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport        C:\Windows\system32\DRIVERS\parport.sys
13:06:18.0278 0x1a64c  Parport - ok
13:06:18.0305 0x1a64c  [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr        C:\Windows\system32\drivers\partmgr.sys
13:06:18.0336 0x1a64c  partmgr - ok
13:06:18.0353 0x1a64c  [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
13:06:18.0387 0x1a64c  Parvdm - ok
13:06:18.0422 0x1a64c  [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc          C:\Windows\System32\pcasvc.dll
13:06:18.0469 0x1a64c  PcaSvc - ok
13:06:18.0490 0x1a64c  [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci            C:\Windows\system32\drivers\pci.sys
13:06:18.0526 0x1a64c  pci - ok
13:06:18.0553 0x1a64c  [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide          C:\Windows\system32\drivers\pciide.sys
13:06:18.0583 0x1a64c  pciide - ok
13:06:18.0612 0x1a64c  [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
13:06:18.0647 0x1a64c  pcmcia - ok
13:06:18.0667 0x1a64c  [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw            C:\Windows\system32\drivers\pcw.sys
13:06:18.0702 0x1a64c  pcw - ok
13:06:18.0752 0x1a64c  [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
13:06:18.0839 0x1a64c  PEAUTH - ok
13:06:18.0948 0x1a64c  [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc    C:\Windows\system32\peerdistsvc.dll
13:06:19.0371 0x1a64c  PeerDistSvc - ok
13:06:19.0645 0x1a64c  [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla            C:\Windows\system32\pla.dll
13:06:19.0793 0x1a64c  pla - ok
13:06:19.0856 0x1a64c  [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
13:06:19.0931 0x1a64c  PlugPlay - ok
13:06:19.0961 0x1a64c  [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg    C:\Windows\system32\pnrpauto.dll
13:06:20.0045 0x1a64c  PNRPAutoReg - ok
13:06:20.0082 0x1a64c  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc        C:\Windows\system32\pnrpsvc.dll
13:06:20.0126 0x1a64c  PNRPsvc - ok
13:06:20.0174 0x1a64c  [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent    C:\Windows\System32\ipsecsvc.dll
13:06:20.0259 0x1a64c  PolicyAgent - ok
13:06:20.0302 0x1a64c  [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power          C:\Windows\system32\umpo.dll
13:06:20.0357 0x1a64c  Power - ok
13:06:20.0394 0x1a64c  [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
13:06:20.0447 0x1a64c  PptpMiniport - ok
13:06:20.0467 0x1a64c  [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor      C:\Windows\system32\DRIVERS\processr.sys
13:06:20.0528 0x1a64c  Processor - ok
13:06:20.0572 0x1a64c  [ CADEFAC453040E370A1BDFF3973BE00D, 2E3DD8DA702468D8AB0F3CE27188B1991D4CB015FB36BAE4C6E7996B61CF49B8 ] ProfSvc        C:\Windows\system32\profsvc.dll
13:06:20.0615 0x1a64c  ProfSvc - ok
13:06:20.0629 0x1a64c  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] ProtectedStorage C:\Windows\system32\lsass.exe
13:06:20.0666 0x1a64c  ProtectedStorage - ok
13:06:20.0698 0x1a64c  [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
13:06:20.0765 0x1a64c  Psched - ok
13:06:20.0855 0x1a64c  [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
13:06:20.0957 0x1a64c  ql2300 - ok
13:06:20.0978 0x1a64c  [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
13:06:21.0012 0x1a64c  ql40xx - ok
13:06:21.0040 0x1a64c  [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE          C:\Windows\system32\qwave.dll
13:06:21.0101 0x1a64c  QWAVE - ok
13:06:21.0130 0x1a64c  [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
13:06:21.0184 0x1a64c  QWAVEdrv - ok
13:06:21.0208 0x1a64c  [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
13:06:21.0259 0x1a64c  RasAcd - ok
13:06:21.0298 0x1a64c  [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn    C:\Windows\system32\DRIVERS\AgileVpn.sys
13:06:21.0348 0x1a64c  RasAgileVpn - ok
13:06:21.0372 0x1a64c  [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto        C:\Windows\System32\rasauto.dll
13:06:21.0429 0x1a64c  RasAuto - ok
13:06:21.0451 0x1a64c  [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp        C:\Windows\system32\DRIVERS\rasl2tp.sys
13:06:21.0518 0x1a64c  Rasl2tp - ok
13:06:21.0562 0x1a64c  [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan          C:\Windows\System32\rasmans.dll
13:06:21.0629 0x1a64c  RasMan - ok
13:06:21.0662 0x1a64c  [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
13:06:21.0714 0x1a64c  RasPppoe - ok
13:06:21.0753 0x1a64c  [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp        C:\Windows\system32\DRIVERS\rassstp.sys
13:06:21.0819 0x1a64c  RasSstp - ok
13:06:21.0868 0x1a64c  [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss          C:\Windows\system32\DRIVERS\rdbss.sys
13:06:21.0927 0x1a64c  rdbss - ok
13:06:21.0947 0x1a64c  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
13:06:21.0985 0x1a64c  rdpbus - ok
13:06:22.0009 0x1a64c  [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
13:06:22.0066 0x1a64c  RDPCDD - ok
13:06:22.0109 0x1a64c  [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR          C:\Windows\system32\drivers\rdpdr.sys
13:06:22.0158 0x1a64c  RDPDR - ok
13:06:22.0182 0x1a64c  [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
13:06:22.0245 0x1a64c  RDPENCDD - ok
13:06:22.0260 0x1a64c  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
13:06:22.0315 0x1a64c  RDPREFMP - ok
13:06:22.0377 0x1a64c  [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
13:06:22.0418 0x1a64c  RdpVideoMiniport - ok
13:06:22.0464 0x1a64c  [ F031683E6D1FEA157ABB2FF260B51E61, 83B552819A5964152882C527E1421DBCEAACC74DEB897E3C4B53F52F1467FED3 ] RDPWD          C:\Windows\system32\drivers\RDPWD.sys
13:06:22.0535 0x1a64c  RDPWD - ok
13:06:22.0583 0x1a64c  [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
13:06:22.0621 0x1a64c  rdyboost - ok
13:06:22.0652 0x1a64c  [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess    C:\Windows\System32\mprdim.dll
13:06:22.0747 0x1a64c  RemoteAccess - ok
13:06:22.0793 0x1a64c  [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry  C:\Windows\system32\regsvc.dll
13:06:22.0862 0x1a64c  RemoteRegistry - ok
13:06:22.0889 0x1a64c  [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
13:06:22.0946 0x1a64c  RpcEptMapper - ok
13:06:22.0975 0x1a64c  [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator      C:\Windows\system32\locator.exe
13:06:23.0013 0x1a64c  RpcLocator - ok
13:06:23.0051 0x1a64c  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs          C:\Windows\system32\rpcss.dll
13:06:23.0115 0x1a64c  RpcSs - ok
13:06:23.0150 0x1a64c  [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
13:06:23.0216 0x1a64c  rspndr - ok
13:06:23.0249 0x1a64c  [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap          C:\Windows\system32\drivers\vms3cap.sys
13:06:23.0314 0x1a64c  s3cap - ok
13:06:23.0334 0x1a64c  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] SamSs          C:\Windows\system32\lsass.exe
13:06:23.0371 0x1a64c  SamSs - ok
13:06:23.0403 0x1a64c  [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
13:06:23.0440 0x1a64c  sbp2port - ok
13:06:23.0473 0x1a64c  [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
13:06:23.0535 0x1a64c  SCardSvr - ok
13:06:23.0566 0x1a64c  [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
13:06:23.0627 0x1a64c  scfilter - ok
13:06:23.0707 0x1a64c  [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule        C:\Windows\system32\schedsvc.dll
13:06:23.0803 0x1a64c  Schedule - ok
13:06:24.0044 0x1a64c  [ 43BB01FA6B3E6E4D4343BDEAB3EC56B7, 535B392580D77EEAED3647836A8567223D44A7ADD629BA457D117F3C584D7120 ] scores          C:\Windows\score.exe
13:06:24.0348 0x1a64c  scores - detected UnsignedFile.Multi.Generic ( 1 )
13:06:27.0236 0x1a64c  scores ( UnsignedFile.Multi.Generic ) - warning
13:06:27.0236 0x1a64c  Force sending object to P2P due to detect: scores
13:06:30.0130 0x1a64c  Object send P2P result: true
13:06:32.0910 0x1a64c  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc    C:\Windows\System32\certprop.dll
13:06:32.0963 0x1a64c  SCPolicySvc - ok
13:06:32.0997 0x1a64c  [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
13:06:33.0042 0x1a64c  SDRSVC - ok
13:06:33.0083 0x1a64c  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
13:06:33.0146 0x1a64c  secdrv - ok
13:06:33.0188 0x1a64c  [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon        C:\Windows\system32\seclogon.dll
13:06:33.0243 0x1a64c  seclogon - ok
13:06:33.0260 0x1a64c  [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS            C:\Windows\system32\sens.dll
13:06:33.0324 0x1a64c  SENS - ok
13:06:33.0335 0x1a64c  [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
13:06:33.0442 0x1a64c  SensrSvc - ok
13:06:33.0473 0x1a64c  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum        C:\Windows\system32\DRIVERS\serenum.sys
13:06:33.0525 0x1a64c  Serenum - ok
13:06:33.0573 0x1a64c  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial          C:\Windows\system32\DRIVERS\serial.sys
13:06:33.0724 0x1a64c  Serial - ok
13:06:33.0821 0x1a64c  [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
13:06:33.0892 0x1a64c  sermouse - ok
13:06:33.0951 0x1a64c  [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv      C:\Windows\system32\sessenv.dll
13:06:34.0034 0x1a64c  SessionEnv - ok
13:06:34.0082 0x1a64c  [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk        C:\Windows\system32\drivers\sffdisk.sys
13:06:34.0134 0x1a64c  sffdisk - ok
13:06:34.0144 0x1a64c  [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
13:06:34.0205 0x1a64c  sffp_mmc - ok
13:06:34.0259 0x1a64c  [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd        C:\Windows\system32\drivers\sffp_sd.sys
13:06:34.0300 0x1a64c  sffp_sd - ok
13:06:34.0329 0x1a64c  [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy        C:\Windows\system32\DRIVERS\sfloppy.sys
13:06:34.0366 0x1a64c  sfloppy - ok
13:06:34.0424 0x1a64c  [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess    C:\Windows\System32\ipnathlp.dll
13:06:34.0502 0x1a64c  SharedAccess - ok
13:06:34.0547 0x1a64c  [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
13:06:34.0629 0x1a64c  ShellHWDetection - ok
13:06:34.0662 0x1a64c  [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp          C:\Windows\system32\drivers\sisagp.sys
13:06:34.0694 0x1a64c  sisagp - ok
13:06:34.0729 0x1a64c  [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
13:06:34.0780 0x1a64c  SiSRaid2 - ok
13:06:34.0801 0x1a64c  [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
13:06:34.0835 0x1a64c  SiSRaid4 - ok
13:06:34.0877 0x1a64c  [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb            C:\Windows\system32\DRIVERS\smb.sys
13:06:34.0957 0x1a64c  Smb - ok
13:06:35.0012 0x1a64c  [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
13:06:35.0052 0x1a64c  SNMPTRAP - ok
13:06:35.0095 0x1a64c  [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr          C:\Windows\system32\drivers\spldr.sys
13:06:35.0126 0x1a64c  spldr - ok
13:06:35.0171 0x1a64c  [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler        C:\Windows\System32\spoolsv.exe
13:06:35.0250 0x1a64c  Spooler - ok
13:06:35.0424 0x1a64c  [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc          C:\Windows\system32\sppsvc.exe
13:06:35.0681 0x1a64c  sppsvc - ok
13:06:35.0739 0x1a64c  [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify    C:\Windows\system32\sppuinotify.dll
13:06:35.0797 0x1a64c  sppuinotify - ok
13:06:35.0823 0x1a64c  sptd - ok
13:06:35.0865 0x1a64c  [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv            C:\Windows\system32\DRIVERS\srv.sys
13:06:35.0950 0x1a64c  srv - ok
13:06:35.0978 0x1a64c  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
13:06:36.0040 0x1a64c  srv2 - ok
13:06:36.0080 0x1a64c  [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
13:06:36.0132 0x1a64c  srvnet - ok
13:06:36.0175 0x1a64c  [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV        C:\Windows\System32\ssdpsrv.dll
13:06:36.0236 0x1a64c  SSDPSRV - ok
13:06:36.0262 0x1a64c  [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc        C:\Windows\system32\sstpsvc.dll
13:06:36.0330 0x1a64c  SstpSvc - ok
13:06:36.0384 0x1a64c  [ E5C796B621F6FBA8616511063D7F0FFE, 447FA64F552D4B04AD029E01485B4438A70D9B9B98EB49A883D5B17ED4C1D52F ] StarWindServiceAE C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
13:06:36.0416 0x1a64c  StarWindServiceAE - detected UnsignedFile.Multi.Generic ( 1 )
13:06:39.0199 0x1a64c  Detect skipped due to KSN trusted
13:06:39.0199 0x1a64c  StarWindServiceAE - ok
13:06:39.0223 0x1a64c  [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
13:06:39.0255 0x1a64c  stexstor - ok
13:06:39.0301 0x1a64c  [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc          C:\Windows\System32\wiaservc.dll
13:06:39.0378 0x1a64c  StiSvc - ok
13:06:39.0422 0x1a64c  [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt        C:\Windows\system32\drivers\vmstorfl.sys
13:06:39.0455 0x1a64c  storflt - ok
13:06:39.0497 0x1a64c  [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc        C:\Windows\system32\drivers\storvsc.sys
13:06:39.0528 0x1a64c  storvsc - ok
13:06:39.0554 0x1a64c  [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum          C:\Windows\system32\drivers\swenum.sys
13:06:39.0585 0x1a64c  swenum - ok
13:06:39.0635 0x1a64c  [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv          C:\Windows\System32\swprv.dll
13:06:39.0706 0x1a64c  swprv - ok
13:06:39.0736 0x1a64c  Synth3dVsc - ok
13:06:39.0813 0x1a64c  [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain        C:\Windows\system32\sysmain.dll
13:06:39.0899 0x1a64c  SysMain - ok
13:06:39.0937 0x1a64c  [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
13:06:40.0012 0x1a64c  TabletInputService - ok
13:06:40.0067 0x1a64c  [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv        C:\Windows\System32\tapisrv.dll
13:06:40.0129 0x1a64c  TapiSrv - ok
13:06:40.0162 0x1a64c  [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS            C:\Windows\System32\tbssvc.dll
13:06:40.0220 0x1a64c  TBS - ok
13:06:40.0300 0x1a64c  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip          C:\Windows\system32\drivers\tcpip.sys
13:06:40.0399 0x1a64c  Tcpip - ok
13:06:40.0484 0x1a64c  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
13:06:40.0564 0x1a64c  TCPIP6 - ok
13:06:40.0605 0x1a64c  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
13:06:40.0643 0x1a64c  tcpipreg - ok
13:06:40.0682 0x1a64c  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
13:06:40.0749 0x1a64c  TDPIPE - ok
13:06:40.0766 0x1a64c  [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP          C:\Windows\system32\drivers\tdtcp.sys
13:06:40.0802 0x1a64c  TDTCP - ok
13:06:40.0833 0x1a64c  [ B459575348C20E8121D6039DA063C704, 1B4328A9EA39FF5A57F258E02254D04B73455F1DF7C997C13702A8B2F12D0347 ] tdx            C:\Windows\system32\DRIVERS\tdx.sys
13:06:40.0891 0x1a64c  tdx - ok
13:06:41.0165 0x1a64c  [ 3438EFDC30F7A41D3598ED60BBF6CF2A, 342B8E78DF6B4BA641C5CCB5B1343B363B770681F0794A809728789E3BE56E46 ] TeamViewer9    C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
13:06:41.0426 0x1a64c  TeamViewer9 - ok
13:06:41.0473 0x1a64c  [ 9101FFFCFCCD1A30E870A5B8A9091B10, 58AAB0F6FF78FD0ECDD8D9DA1B6852E9E57E3DAA39489ABDDBA106ECE0B3BCA7 ] teamviewervpn  C:\Windows\system32\DRIVERS\teamviewervpn.sys
13:06:41.0537 0x1a64c  teamviewervpn - ok
13:06:41.0564 0x1a64c  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD          C:\Windows\system32\drivers\termdd.sys
13:06:41.0595 0x1a64c  TermDD - ok
13:06:41.0653 0x1a64c  [ 382C804C92811BE57829D8E550A900E2, 5F52C2E7902024CF1C9CC0069F411C3F19CCA3DB209F437FA0F3932D4898EB50 ] TermService    C:\Windows\System32\termsrv.dll
13:06:41.0758 0x1a64c  TermService - ok
13:06:41.0799 0x1a64c  [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes          C:\Windows\system32\themeservice.dll
13:06:41.0856 0x1a64c  Themes - ok
13:06:41.0873 0x1a64c  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER    C:\Windows\system32\mmcss.dll
13:06:41.0934 0x1a64c  THREADORDER - ok
13:06:41.0949 0x1a64c  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks          C:\Windows\System32\trkwks.dll
13:06:42.0019 0x1a64c  TrkWks - ok
13:06:42.0080 0x1a64c  [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
13:06:42.0145 0x1a64c  TrustedInstaller - ok
13:06:42.0188 0x1a64c  [ B37B08F2E5EEB1A37E448E09BACE1101, 32CC9E06B88BAB6FAB4696B744548DFCE9199A7FD2BA8B019F269CA75895852C ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
13:06:42.0248 0x1a64c  tssecsrv - ok
13:06:42.0280 0x1a64c  [ 9CE253214ACAA5A7D323327D2055EFAA, 15E7DB578EDF36DD2FD5BA960C3941B2353037323B6B96702CDCDC07588EA724 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
13:06:42.0327 0x1a64c  TsUsbFlt - ok
13:06:42.0336 0x1a64c  tsusbhub - ok
13:06:42.0384 0x1a64c  [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
13:06:42.0451 0x1a64c  tunnel - ok
13:06:42.0499 0x1a64c  [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
13:06:42.0530 0x1a64c  uagp35 - ok
13:06:42.0567 0x1a64c  [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
13:06:42.0638 0x1a64c  udfs - ok
13:06:42.0692 0x1a64c  [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect      C:\Windows\system32\UI0Detect.exe
13:06:42.0740 0x1a64c  UI0Detect - ok
13:06:42.0777 0x1a64c  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
13:06:42.0808 0x1a64c  uliagpkx - ok
13:06:42.0850 0x1a64c  [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus          C:\Windows\system32\drivers\umbus.sys
13:06:42.0890 0x1a64c  umbus - ok
13:06:42.0916 0x1a64c  [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
13:06:42.0964 0x1a64c  UmPass - ok
13:06:43.0012 0x1a64c  [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService    C:\Windows\System32\umrdp.dll
13:06:43.0118 0x1a64c  UmRdpService - ok
13:06:43.0171 0x1a64c  [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost        C:\Windows\System32\upnphost.dll
13:06:43.0248 0x1a64c  upnphost - ok
13:06:43.0297 0x1a64c  [ A1977C315BF5691DA99235AA4A6907AF, 34B52FBA83F0E1C6B001D0AD1808B00152F731D18AAECC3C53B9918AA89BACEC ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
13:06:43.0369 0x1a64c  usbaudio - ok
13:06:43.0400 0x1a64c  [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp        C:\Windows\system32\DRIVERS\usbccgp.sys
13:06:43.0449 0x1a64c  usbccgp - ok
13:06:43.0470 0x1a64c  [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir          C:\Windows\system32\drivers\usbcir.sys
13:06:43.0519 0x1a64c  usbcir - ok
13:06:43.0558 0x1a64c  [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci        C:\Windows\system32\DRIVERS\usbehci.sys
13:06:43.0604 0x1a64c  usbehci - ok
13:06:43.0653 0x1a64c  [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
13:06:43.0708 0x1a64c  usbhub - ok
13:06:43.0736 0x1a64c  [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci        C:\Windows\system32\drivers\usbohci.sys
13:06:43.0776 0x1a64c  usbohci - ok
13:06:43.0819 0x1a64c  [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
13:06:43.0860 0x1a64c  usbprint - ok
13:06:43.0893 0x1a64c  [ FC6B21DB4B5B398AB93DBE59CBF11036, A94094C208F376405C07822A6143001EF1B12AE93205CD8002E87F6EB45F6374 ] usbscan        C:\Windows\system32\DRIVERS\usbscan.sys
13:06:43.0957 0x1a64c  usbscan - ok
13:06:43.0979 0x1a64c  [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR        C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:06:44.0029 0x1a64c  USBSTOR - ok
13:06:44.0068 0x1a64c  [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci        C:\Windows\system32\DRIVERS\usbuhci.sys
13:06:44.0106 0x1a64c  usbuhci - ok
13:06:44.0142 0x1a64c  [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms          C:\Windows\System32\uxsms.dll
13:06:44.0224 0x1a64c  UxSms - ok
13:06:44.0255 0x1a64c  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] VaultSvc        C:\Windows\system32\lsass.exe
13:06:44.0292 0x1a64c  VaultSvc - ok
13:06:44.0323 0x1a64c  [ FCE98C43B5C5DB8E0DA8EA0E2B45E044, 0F6F3FF106015580009776A1F91FD10371BAF229A2A773436A5783F142CC1A0C ] VClone          C:\Windows\system32\DRIVERS\VClone.sys
13:06:44.0384 0x1a64c  VClone - ok
13:06:44.0417 0x1a64c  [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
13:06:44.0453 0x1a64c  vdrvroot - ok
13:06:44.0505 0x1a64c  [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds            C:\Windows\System32\vds.exe
13:06:44.0587 0x1a64c  vds - ok
13:06:44.0630 0x1a64c  [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga            C:\Windows\system32\DRIVERS\vgapnp.sys
13:06:44.0678 0x1a64c  vga - ok
13:06:44.0707 0x1a64c  [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave        C:\Windows\System32\drivers\vga.sys
13:06:44.0767 0x1a64c  VgaSave - ok
13:06:44.0785 0x1a64c  VGPU - ok
13:06:44.0820 0x1a64c  [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp          C:\Windows\system32\drivers\vhdmp.sys
13:06:44.0856 0x1a64c  vhdmp - ok
13:06:44.0886 0x1a64c  [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
13:06:44.0923 0x1a64c  viaagp - ok
13:06:44.0950 0x1a64c  [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7          C:\Windows\system32\DRIVERS\viac7.sys
13:06:45.0000 0x1a64c  ViaC7 - ok
13:06:45.0044 0x1a64c  [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide          C:\Windows\system32\drivers\viaide.sys
13:06:45.0075 0x1a64c  viaide - ok
13:06:45.0113 0x1a64c  [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus          C:\Windows\system32\drivers\vmbus.sys
13:06:45.0150 0x1a64c  vmbus - ok
13:06:45.0184 0x1a64c  [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
13:06:45.0227 0x1a64c  VMBusHID - ok
13:06:45.0253 0x1a64c  [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
13:06:45.0285 0x1a64c  volmgr - ok
13:06:45.0326 0x1a64c  [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx        C:\Windows\system32\drivers\volmgrx.sys
13:06:45.0366 0x1a64c  volmgrx - ok
13:06:45.0397 0x1a64c  [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap        C:\Windows\system32\drivers\volsnap.sys
13:06:45.0436 0x1a64c  volsnap - ok
13:06:45.0469 0x1a64c  [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid        C:\Windows\system32\DRIVERS\vsmraid.sys
13:06:45.0504 0x1a64c  vsmraid - ok
13:06:45.0570 0x1a64c  [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS            C:\Windows\system32\vssvc.exe
13:06:45.0699 0x1a64c  VSS - ok
13:06:45.0731 0x1a64c  [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
13:06:45.0787 0x1a64c  vwifibus - ok
13:06:45.0841 0x1a64c  [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time        C:\Windows\system32\w32time.dll
13:06:45.0923 0x1a64c  W32Time - ok
13:06:45.0970 0x1a64c  [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
13:06:46.0025 0x1a64c  WacomPen - ok
13:06:46.0061 0x1a64c  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
13:06:46.0125 0x1a64c  WANARP - ok
13:06:46.0135 0x1a64c  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
13:06:46.0193 0x1a64c  Wanarpv6 - ok
13:06:46.0275 0x1a64c  [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine        C:\Windows\system32\wbengine.exe
13:06:46.0426 0x1a64c  wbengine - ok
13:06:46.0466 0x1a64c  [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
13:06:46.0536 0x1a64c  WbioSrvc - ok
13:06:46.0583 0x1a64c  [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc        C:\Windows\System32\wcncsvc.dll
13:06:46.0663 0x1a64c  wcncsvc - ok
13:06:46.0692 0x1a64c  [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
13:06:46.0811 0x1a64c  WcsPlugInService - ok
13:06:46.0836 0x1a64c  [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd              C:\Windows\system32\DRIVERS\wd.sys
13:06:46.0868 0x1a64c  Wd - ok
13:06:46.0922 0x1a64c  [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
13:06:46.0982 0x1a64c  Wdf01000 - ok
13:06:47.0002 0x1a64c  [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost  C:\Windows\system32\wdi.dll
13:06:47.0074 0x1a64c  WdiServiceHost - ok
13:06:47.0085 0x1a64c  [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost  C:\Windows\system32\wdi.dll
13:06:47.0133 0x1a64c  WdiSystemHost - ok
13:06:47.0173 0x1a64c  [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient      C:\Windows\System32\webclnt.dll
13:06:47.0257 0x1a64c  WebClient - ok
13:06:47.0293 0x1a64c  [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc          C:\Windows\system32\wecsvc.dll
13:06:47.0358 0x1a64c  Wecsvc - ok
13:06:47.0384 0x1a64c  [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport  C:\Windows\System32\wercplsupport.dll
13:06:47.0446 0x1a64c  wercplsupport - ok
13:06:47.0475 0x1a64c  [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc          C:\Windows\System32\WerSvc.dll
13:06:47.0542 0x1a64c  WerSvc - ok
13:06:47.0591 0x1a64c  [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
13:06:47.0648 0x1a64c  WfpLwf - ok
13:06:47.0671 0x1a64c  [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
13:06:47.0702 0x1a64c  WIMMount - ok
13:06:47.0772 0x1a64c  [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend      C:\Program Files\Windows Defender\mpsvc.dll
13:06:47.0865 0x1a64c  WinDefend - ok
13:06:47.0903 0x1a64c  WinHttpAutoProxySvc - ok
13:06:47.0960 0x1a64c  [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt        C:\Windows\system32\wbem\WMIsvc.dll
13:06:48.0041 0x1a64c  Winmgmt - ok
13:06:48.0129 0x1a64c  [ 1B91CD34EA3A90AB6A4EF0550174F4CC, 5B6618615EBFBA594C945AD35F5C68DA8C6053892B6D12D626BB6120910D80DC ] WinRM          C:\Windows\system32\WsmSvc.dll
13:06:48.0274 0x1a64c  WinRM - ok
13:06:48.0359 0x1a64c  [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc        C:\Windows\System32\wlansvc.dll
13:06:48.0473 0x1a64c  Wlansvc - ok
13:06:48.0519 0x1a64c  [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi        C:\Windows\system32\drivers\wmiacpi.sys
13:06:48.0570 0x1a64c  WmiAcpi - ok
13:06:48.0617 0x1a64c  [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
13:06:48.0662 0x1a64c  wmiApSrv - ok
13:06:48.0761 0x1a64c  [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc  C:\Program Files\Windows Media Player\wmpnetwk.exe
13:06:48.0856 0x1a64c  WMPNetworkSvc - ok
13:06:48.0895 0x1a64c  [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
13:06:48.0993 0x1a64c  WPCSvc - ok
13:06:49.0019 0x1a64c  [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
13:06:49.0092 0x1a64c  WPDBusEnum - ok
13:06:49.0121 0x1a64c  [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl        C:\Windows\system32\drivers\ws2ifsl.sys
13:06:49.0184 0x1a64c  ws2ifsl - ok
13:06:49.0235 0x1a64c  [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc          C:\Windows\system32\wscsvc.dll
13:06:49.0295 0x1a64c  wscsvc - ok
13:06:49.0307 0x1a64c  WSearch - ok
13:06:49.0425 0x1a64c  [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv        C:\Windows\system32\wuaueng.dll
13:06:49.0560 0x1a64c  wuauserv - ok
13:06:49.0598 0x1a64c  [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
13:06:49.0646 0x1a64c  WudfPf - ok
13:06:49.0684 0x1a64c  [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
13:06:49.0730 0x1a64c  WUDFRd - ok
13:06:49.0770 0x1a64c  [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc        C:\Windows\System32\WUDFSvc.dll
13:06:49.0823 0x1a64c  wudfsvc - ok
13:06:49.0870 0x1a64c  [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc        C:\Windows\System32\wwansvc.dll
13:06:50.0022 0x1a64c  WwanSvc - ok
13:06:50.0058 0x1a64c  ================ Scan global ===============================
13:06:50.0085 0x1a64c  [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
13:06:50.0120 0x1a64c  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
13:06:50.0136 0x1a64c  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
13:06:50.0167 0x1a64c  [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
13:06:50.0190 0x1a64c  [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
13:06:50.0200 0x1a64c  [ Global ] - ok
13:06:50.0201 0x1a64c  ================ Scan MBR ==================================
13:06:50.0219 0x1a64c  [ 72B8CE41AF0DE751C946802B3ED844B4 ] \Device\Harddisk0\DR0
13:06:50.0334 0x1a64c  \Device\Harddisk0\DR0 - ok
13:06:50.0350 0x1a64c  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
13:06:51.0005 0x1a64c  \Device\Harddisk1\DR1 - ok
13:06:51.0005 0x1a64c  ================ Scan VBR ==================================
13:06:51.0009 0x1a64c  [ 3CCF6D1DD38D5040E6F07A3440ED27DE ] \Device\Harddisk0\DR0\Partition1
13:06:51.0013 0x1a64c  \Device\Harddisk0\DR0\Partition1 - ok
13:06:51.0018 0x1a64c  [ 255CE30F0C04D9F85495FF5D20CD23A1 ] \Device\Harddisk1\DR1\Partition1
13:06:51.0022 0x1a64c  \Device\Harddisk1\DR1\Partition1 - ok
13:06:51.0027 0x1a64c  [ D5C7A561AED06E32B1A159B4066E408B ] \Device\Harddisk1\DR1\Partition2
13:06:51.0029 0x1a64c  \Device\Harddisk1\DR1\Partition2 - ok
13:06:51.0031 0x1a64c  ================ Scan generic autorun ======================
13:06:51.0072 0x1a64c  [ 68239842340DDFF8993DFD9127553EDA, 9FEC34A35D5A91FEF1C4859AFD0C2538C5CD3E1792FB118487368CFDF66CBCA0 ] C:\Windows\system32\igfxtray.exe
13:06:51.0102 0x1a64c  IgfxTray - ok
13:06:51.0125 0x1a64c  [ 004763BDF8E48244DBB9FDFDE3065EBC, AA88911C51D73C501C67F62A907425EF91D1820D3ED581F0952619EBB6216F14 ] C:\Windows\system32\hkcmd.exe
13:06:51.0173 0x1a64c  HotKeysCmds - ok
13:06:51.0196 0x1a64c  [ CD1102E5D340216138C7F56FA8D26998, 805BE128B6A52E304A91AD44B6A7322BAD5F72CD400DB5E74D8EF47424894266 ] C:\Windows\system32\igfxpers.exe
13:06:51.0229 0x1a64c  Persistence - ok
13:06:51.0295 0x1a64c  [ 048EA4B978851788E9F5E8E4F081DF7A, EB62719AC0DCC18FF056F2CD84438BF14B61E38F0619617C81961C6257BDFCEC ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
13:06:51.0354 0x1a64c  Adobe ARM - ok
13:06:51.0405 0x1a64c  [ 2A21FE60A9BC5247BD8C57409A2B97F8, 6C9851684FB90AB6038A326F4B362C1948DF2173063CA198DCEAEA6BFAC636E0 ] C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
13:06:51.0434 0x1a64c  VirtualCloneDrive - ok
13:06:51.0564 0x1a64c  [ AABF93F351E17EA4D42EE028A905AF45, E9F26573AF7C02240F4C587F4C6003761268697D07A3098DF3CD03C5749C06B2 ] C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
13:06:51.0651 0x1a64c  Wondershare Helper Compact.exe - ok
13:06:51.0777 0x1a64c  [ 5E5EF857D545E8B9268B4DE377F32177, B8FFDA7D82F2B911B6E40D5B2C2B5B23AE3EEE813DB615B2A955F1E05F1E492B ] C:\ProgramData\Wondershare\Player\DelayPluginI.exe
13:06:51.0899 0x1a64c  DelaypluginInstall - ok
13:06:52.0389 0x1a64c  [ 1A536B01E64D26BED151C9BFA3EDCEB2, 776D8426D031C18B7C495F8D3B7896BF08E07859F2937D5B45FC57E8327B6D6C ] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
13:06:52.0929 0x1a64c  RTHDVCPL - ok
13:06:52.0994 0x1a64c  fst_de_122 - ok
13:06:53.0441 0x1a64c  [ A8B68D4A0B815294819E2647D54A7686, 6FA0527939753D52AB259D13B515A50BBCC9248900C88F2B2582282961BD844E ] C:\Program Files\AVG\AVG2014\avgui.exe
13:06:53.0924 0x1a64c  AVG_UI - ok
13:06:54.0029 0x1a64c  [ 1DB3300FE6EF0D52ECABBB903FCA6A41, 574D0CA9CDA56CD8DD6398BAF3E1CDCF56E9CA4F71D85D9155FAC4325444EA25 ] C:\Users\HomeBasic1\AppData\Roaming\DRPSu\DrvUpdater.exe
13:06:54.0211 0x1a64c  DrvUpdater - ok
13:06:54.0273 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:06:55.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:06:56.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:06:57.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:06:58.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:06:59.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:07:00.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:07:01.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:07:02.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:07:03.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:07:04.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:07:05.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:07:06.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:07:07.0274 0x1a64c  Waiting for KSN requests completion. In queue: 106
13:07:08.0450 0x1a64c  AV detected via SS2: AVG AntiVirus Free Edition 2014, C:\Program Files\AVG\AVG2014\avgwsc.exe ( 14.0.0.4714 ), 0x41000 ( enabled : updated )
13:07:08.0562 0x1a64c  Win FW state via NFP2: enabled
13:07:11.0273 0x1a64c  ============================================================
13:07:11.0273 0x1a64c  Scan finished
13:07:11.0273 0x1a64c  ============================================================
13:07:11.0289 0x1a294  Detected object count: 1
13:07:11.0289 0x1a294  Actual detected object count: 1
13:07:56.0004 0x1a294  scores ( UnsignedFile.Multi.Generic ) - skipped by user
13:07:56.0005 0x1a294  scores ( UnsignedFile.Multi.Generic ) - User select action: Skip


cosinus 05.08.2014 12:44

Zitat:

C:\Windows\score.exe
Bitte diese Datei bei Virustotal auswerten lassen und den Ergebnislink posten. Falls Du die Datei nicht siehst, musst Du sie evtl. vorher sichtbar machen.
Wenn die Datei schon ausgewertet sein sollte, bitte eine weitere Auswertung starten.

TOMROSSI 05.08.2014 12:51

https://www.virustotal.com/de/file/535b392580d77eeaed3647836a8567223d44a7add629ba457d117f3c584d7120/analysis/1407239313/

cosinus 05.08.2014 12:56

Hm, nur ein Fund, die Datei ist mir aber trotzdem zu verdächtig.

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Windows\score.exe

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


TOMROSSI 05.08.2014 13:16

Fixlog
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:31-07-2014 02
Ran by HomeBasic1 at 2014-08-05 14:15:30 Run:1
Running from C:\Users\HomeBasic1\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
C:\Windows\score.exe
*****************

C:\Windows\score.exe => Moved successfully.

==== End of Fixlog ====


cosinus 05.08.2014 13:49

Okay, dann Kontrollscans mit MBAM und ESET bitte:

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


TOMROSSI 05.08.2014 19:24

Bin jetzt 2 Tage nicht onlen, hier die logs

Malware
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 05.08.2014
Suchlauf-Zeit: 15:08:13
Logdatei: Malware.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.08.05.03
Rootkit Datenbank: v2014.08.04.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: HomeBasic1

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 296344
Verstrichene Zeit: 1 Std, 33 Min, 58 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 1
Adware.EoRezo, HKLM\SOFTWARE\FREESOFTTODAY, In Quarantäne, [f502d7ebafcc2c0a33ee55c50cf8ce32],

Registrierungswerte: 1
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_de_122, "C:\Program Files\fst_de_122\fst_de_122.exe", In Quarantäne, [9a5d8d3527542115fac4d21892706e92]

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 3
Adware.EoRezo, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREESOFTTODAY, In Quarantäne, [f9fe863c3546072f0ccaefc0966c946c],
PUP.Optional.FreeSoftToday.A, C:\Users\HomeBasic1\AppData\Local\fst_de_122, In Quarantäne, [3abdd5ed3e3d3ff74e616a5e0ff34fb1],
PUP.Optional.FreeSoftToday.A, C:\Program Files\fst_de_122, In Quarantäne, [a2554c76d2a98bab88286f59d42e47b9],

Dateien: 6
PUP.Optional.SkyTech.A, C:\Users\HomeBasic1\AppData\Local\Temp\0E901CE5-A42A-4039-AB6E-A58C1E4A551A[z]\1.zip, In Quarantäne, [40b7972b59224cea3df90032bf41817f],
PUP.Optional.SkyTech.A, C:\Users\HomeBasic1\AppData\Local\Temp\0E901CE5-A42A-4039-AB6E-A58C1E4A551A[z]\1.zipDir\alilog.dll, In Quarantäne, [10e7ad15512a60d641f5f14138c808f8],
Adware.EoRezo, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FREESOFTTODAY\Freesofttoday.lnk, In Quarantäne, [f9fe863c3546072f0ccaefc0966c946c],
PUP.Optional.FreeSoftToday.A, C:\Program Files\fst_de_122\predm.exe, In Quarantäne, [a2554c76d2a98bab88286f59d42e47b9],
PUP.Optional.FreeSoftToday.A, C:\Program Files\fst_de_122\unins000.dat, In Quarantäne, [a2554c76d2a98bab88286f59d42e47b9],
PUP.Optional.FreeSoftToday.A, C:\Program Files\fst_de_122\unins000.msg, In Quarantäne, [a2554c76d2a98bab88286f59d42e47b9],

Physische Sektoren: 0
(No malicious items detected)


(end)

ESET
Code:

C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6AHA6BG\nteworks_5171[1].exe        Win32/InstallMonetizer.BC evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6AHA6BG\SpeedUpMyPC-standalone-setup[1].exe        Win32/SpeedUpMyPC evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BE6JUKIE\speedupmypc[1].exe        Win32/SpeedUpMyPC.A evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2YM75BQ\lly_webssearches[1].exe        Variante von Win32/ELEX.AT evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2YM75BQ\NewVideoPlayerSetup[1].exe        MSIL/NewPlayer.A evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2YM75BQ\setup_fst_de[1].exe        Mehrere Bedrohungen
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2YM75BQ\swa1_23[1].exe        Variante von MSIL/Adware.StrongVault.A Anwendung
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2YM75BQ\WajamChecker[1].exe        Win32/Wajam.F evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZYK0YIQR\spidentifierimpl[1].exe        Win32/Conduit.SearchProtect.Q evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Temp\1E38tmp\newvideoplayersetup.exe        MSIL/NewPlayer.A evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Temp\1F64tmp\freesofttoday.exe        Mehrere Bedrohungen
C:\Users\HomeBasic1\AppData\Local\Temp\2060tmp\lly_webssearches.exe        Variante von Win32/ELEX.AT evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Temp\20FDtmp\speedupmypc.exe        Win32/SpeedUpMyPC.A evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\AppData\Local\Temp\is-C6KCT.tmp\SpeedUpMyPC-standalone-setup.exe        Win32/SpeedUpMyPC evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\Downloads\Passwd25FinderInstaller.exe        Win32/OpenCandy potenziell unsichere Anwendung
C:\Users\HomeBasic1\Downloads\PicPick-3.4.0.exe        Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung
C:\Users\HomeBasic1\Downloads\vlc-2.1.1-win32.exe        NSIS/StartPage.CC Trojaner
C:\Users\HomeBasic1\Downloads\GrabIt Downloads\getsolar\Hottgenroth Software GetSolar Professional v10.rar        Variante von MSIL/Injector.DTY Trojaner
C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw\1.1.0.0__84542ff99aed6a4d\Interop.SHDocVw.dll        Variante von Win32/Toolbar.Linkury.G evtl. unerwünschte Anwendung
C:\Windows\Installer\b389a.msi        Variante von Win32/Toolbar.Linkury.G evtl. unerwünschte Anwendung
D:\HOMEBASIC1-PC\Backup Set 2014-08-03 194322\Backup Files 2014-08-03 194322\Backup files 1.zip        Variante von Win32/Toolbar.Linkury.E evtl. unerwünschte Anwendung
D:\HOMEBASIC1-PC\Backup Set 2014-08-03 194322\Backup Files 2014-08-03 194322\Backup files 10.zip        Variante von Win32/HackTool.Patcher.AD potenziell unsichere Anwendung
D:\HOMEBASIC1-PC\Backup Set 2014-08-03 194322\Backup Files 2014-08-03 194322\Backup files 2.zip        Win32/OpenCandy potenziell unsichere Anwendung
D:\HOMEBASIC1-PC\Backup Set 2014-08-03 194322\Backup Files 2014-08-03 194322\Backup files 3.zip        NSIS/StartPage.CC Trojaner
D:\HOMEBASIC1-PC\Backup Set 2014-08-03 194322\Backup Files 2014-08-03 194322\Backup files 50.zip        Win32/HackTool.WinActivator.I potenziell unsichere Anwendung


cosinus 06.08.2014 00:18

Zitat:

C:\Users\HomeBasic1\Downloads\GrabIt Downloads\getsolar\Hottgenroth Software GetSolar Professional v10.rar
Lass mich raten...hast du natürlich auch nicht runtergeladen, sondern war der, der dir den Cracky-PC gegeben hat?

Außerdem wunder ich mich über soviele MBAM Funde...hast du ohne Absprache was installiert? Einen Tag zuvor hast du MBAM schonmal ausgeführt...

TOMROSSI 07.08.2014 18:44

Ich habe ein Freeware installiert, die PicPick um Screenshots machen zu können.
Aber kann das mit der MBAM zu tun haben?

Den GrabIt Ordner habe ich gelöscht

cosinus 07.08.2014 21:17

Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BE6JUKIE
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2YM75BQ
D:\HOMEBASIC1-PC\Backup Set 2014-08-03 194322
C:\Windows\Installer\b389a.msi
C:\Users\HomeBasic1\Downloads\Passwd25FinderInstaller.exe
C:\Users\HomeBasic1\Downloads\PicPick-3.4.0.exe
C:\Users\HomeBasic1\Downloads\vlc-2.1.1-win32.exe
C:\Users\HomeBasic1\Downloads\GrabIt Downloads
C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw
C:\Users\HomeBasic1\AppData\Local\Temp\1F64tmp
C:\Users\HomeBasic1\AppData\Local\Temp\2060tmp
C:\Users\HomeBasic1\AppData\Local\Temp\20FDtmp
C:\Users\HomeBasic1\AppData\Local\Temp\is-C6KCT.tmp


Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.


TOMROSSI 08.08.2014 07:22

FRST Fixlog
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version:31-07-2014 02
Ran by HomeBasic1 at 2014-08-08 08:05:01 Run:2
Running from C:\Users\HomeBasic1\Downloads
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BE6JUKIE
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2YM75BQ
D:\HOMEBASIC1-PC\Backup Set 2014-08-03 194322
C:\Windows\Installer\b389a.msi
C:\Users\HomeBasic1\Downloads\Passwd25FinderInstaller.exe
C:\Users\HomeBasic1\Downloads\PicPick-3.4.0.exe
C:\Users\HomeBasic1\Downloads\vlc-2.1.1-win32.exe
C:\Users\HomeBasic1\Downloads\GrabIt Downloads
C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw
C:\Users\HomeBasic1\AppData\Local\Temp\1F64tmp
C:\Users\HomeBasic1\AppData\Local\Temp\2060tmp
C:\Users\HomeBasic1\AppData\Local\Temp\20FDtmp
C:\Users\HomeBasic1\AppData\Local\Temp\is-C6KCT.tmp
*****************

C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BE6JUKIE => Moved successfully.
C:\Users\HomeBasic1\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q2YM75BQ => Moved successfully.
D:\HOMEBASIC1-PC\Backup Set 2014-08-03 194322 => Moved successfully.
C:\Windows\Installer\b389a.msi => Moved successfully.
C:\Users\HomeBasic1\Downloads\Passwd25FinderInstaller.exe => Moved successfully.
C:\Users\HomeBasic1\Downloads\PicPick-3.4.0.exe => Moved successfully.
C:\Users\HomeBasic1\Downloads\vlc-2.1.1-win32.exe => Moved successfully.
C:\Users\HomeBasic1\Downloads\GrabIt Downloads => Moved successfully.
C:\Windows\assembly\GAC_MSIL\Interop.SHDocVw => Moved successfully.
C:\Users\HomeBasic1\AppData\Local\Temp\1F64tmp => Moved successfully.
C:\Users\HomeBasic1\AppData\Local\Temp\2060tmp => Moved successfully.
C:\Users\HomeBasic1\AppData\Local\Temp\20FDtmp => Moved successfully.
C:\Users\HomeBasic1\AppData\Local\Temp\is-C6KCT.tmp => Moved successfully.

==== End of Fixlog ====


cosinus 08.08.2014 09:13

Neuen Kontrollscan mit MBAM bitte, dann sollten wir so langsam durch sein...

TOMROSSI 08.08.2014 11:37

Hat nix gefunden

Wars das?
Macht es Sinn ein Antimalware Programm zu installierren?

cosinus 08.08.2014 11:39

Log bitte posten!

TOMROSSI 08.08.2014 11:42

Malware
Code:

Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlauf Datum: 08.08.2014
Suchlauf-Zeit: 10:35:57
Logdatei: Malware.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.08.08.01
Rootkit Datenbank: v2014.08.04.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: HomeBasic1

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 298347
Verstrichene Zeit: 1 Std, 59 Min, 1 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlüssel: 0
(No malicious items detected)

Registrierungswerte: 0
(No malicious items detected)

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 0
(No malicious items detected)

Dateien: 0
(No malicious items detected)

Physische Sektoren: 0
(No malicious items detected)


(end)


cosinus 08.08.2014 11:43

Gut, du hast auch an die Signaturenupdates gedacht!

TFC - Temp File Cleaner

Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
  • Öffne die TFC.exe.
    Vista und Win 7 User mit Rechtsklick "als Administrator starten".
  • Schließe alle anderen Programme.
  • Drücke auf den Button Start.
  • Falls du zu einem Neustart aufgefordert wirst, bestätige diesen.




Sieht soweit ok aus :daumenhoc

Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Ist aber nur optional. Um Usertracking zu verhindern kann man gut die Firefox-Erweiterung Ghostery verwenden.

Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie )

Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller
Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird.

Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?

TOMROSSI 08.08.2014 12:41

Hi
so wie es aussieht ist alles bereinigt, danke für Deine Mühen und Geduld.

Werde das mit dem Firefox auf alle Fälle machen.

Vielen Danke nochmald
Besten Gruss

cosinus 08.08.2014 13:02

Dann wären wir durch! :daumenhoc


Falls du noch Lob oder Kritik loswerden möchtest => Lob, Kritik und Wünsche - Trojaner-Board

Die Programme, die hier zum Einsatz kamen, können alle deinstalliert werden. Es empfiehlt sich Malwarebytes Anti-Malware zu behalten und damit wöchentlich nach Malware zu scannen.

Helfen kann dir dabei delfix:


Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.






Bitte abschließend noch die Updates prüfen, unten mein Leitfaden dazu. Um in Zukunft die Aktualität der installierten Programme besser im Überblick zu halten, kannst du zB Secunia PSI verwenden.
Für noch mehr Sicherheit solltest Du nach der beseitigten Infektion auch möglichst alle Passwörter ändern.


Microsoftupdate
Windows XP:Besuch mit dem IE die MS-Updateseite und lass Dir alle wichtigen Updates installieren.
Windows Vista/7: Start, Systemsteuerung, Windows-Update


PDF-Reader aktualisieren
Ein veralteter AdobeReader stellt ein großes Sicherheitsrisiko dar. Du solltest daher besser alte Versionen vom AdobeReader über Systemsteuerung => Software bzw. Programme und Funktionen deinstallieren, indem Du dort auf "Adobe Reader x.0" klickst und das Programm entfernst. (falls du AdobeReader installiert hast)

Ich empfehle einen alternativen PDF-Reader wie PDF Xchange Viewer, SumatraPDF oder Foxit PDF Reader, die sind sehr viel schlanker und flotter als der AdobeReader.

Bitte überprüf bei der Gelegenheit auch die Aktualität des Flashplayers:
Prüfen => Adobe - Flash Player
Downloadlinks findest du hier => Browsers and Plugins - FilePony.de

Alle Plugins im Firefox-Browser kannst du auch ganz einfach hier auf Aktualität prüfen => https://www.mozilla.org/de/plugincheck

Natürlich auch darauf achten, dass andere installierte Browser wie zB Firefox, Opera oder Chrome aktuell sind.


Java-Update
Veraltete Java-Installationen sind ein großes Sicherheitsrisiko, daher solltest Du die alten Versionen deinstallieren. Beende dazu alle Programme (v.a. die Browser), klick danach auf Start, Systemsteuerung, Software (bzw. Programme und Funktionen) und deinstalliere darüber alle aufgelisteten Java-Versionen. Lad Dir danach von hier das aktuelle Java SE Runtime Environment (JRE) herunter und installiere es.


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:27 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131