scooby_doo | 15.09.2014 17:06 | Hallo schrauber,
danke für die Anleitung. Habe alles durchgeführt. Nachfolgend die Log-Files.
Eine Frage hätte ich noch. Der Rechner geht über einen UMTS-Surfstick online. Könnte sich dort noch Schadsoftware eingenistet haben oder ist das entweder unmöglich bzw. wurde bei den Scans gleich mit erledigt? Sofern sich Schadsoftware auf dem Stick befinden könnte, wäre es möglich diese zu entfernen bzw. könnte der Stick auch eine Gefährdung für andere Rechner darstellen? Danke auch hierfür!
Hier die Log-Files...
MBAM Log File Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.09.2014
Suchlauf-Zeit: 16:53:49
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.09.15.07
Rootkit Datenbank: v2014.09.15.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: G6-2376
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 316647
Verstrichene Zeit: 13 Min, 35 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 12
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [0de6777686f5a4922d05c7f712f0837d],
PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [0de6777686f5a4922d05c7f712f0837d],
PUP.Optional.OfferBox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3543619C-D563-43f7-95EA-4DA7E1CC396A}, In Quarantäne, [27cc46a7e299bb7b01446b2028da24dc],
PUP.Optional.OfferBox.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3543619C-D563-43F7-95EA-4DA7E1CC396A}, In Quarantäne, [27cc46a7e299bb7b01446b2028da24dc],
PUP.Optional.OfferBox.A, HKU\S-1-5-21-907070689-3175279176-1283973887-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3543619C-D563-43F7-95EA-4DA7E1CC396A}, In Quarantäne, [27cc46a7e299bb7b01446b2028da24dc],
PUP.Optional.OfferBox.A, HKU\S-1-5-21-907070689-3175279176-1283973887-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3543619C-D563-43F7-95EA-4DA7E1CC396A}, In Quarantäne, [27cc46a7e299bb7b01446b2028da24dc],
PUP.Optional.Babylon.A, HKU\S-1-5-21-907070689-3175279176-1283973887-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [3db64aa3691242f419ab8cf8d82ae818],
PUP.Optional.Vittalia, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SoftwareUpdater, In Quarantäne, [d41f0ce198e37cbad997c2108180f709],
PUP.Optional.SoftwareUpdater.A, HKLM\SOFTWARE\WOW6432NODE\SOFTWAREUPDATER, In Quarantäne, [14df32bbcbb0c175d772d575f212e51b],
PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, In Quarantäne, [51a228c5374411251811f937a2610bf5],
PUP.Optional.PlusHD.A, HKU\S-1-5-21-907070689-3175279176-1283973887-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Plus-HD-1.7, In Quarantäne, [9162ffee4a316ec8f403c263818255ab],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-907070689-3175279176-1283973887-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\Plus HD, In Quarantäne, [22d139b446353cfaea0637cb709309f7],
Registrierungswerte: 3
PUP.Optional.SoftwareUpdater, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SOFTWAREUPDATER|UninstallString, C:\Program Files (x86)\SoftwareUpdater\uninstall.exe, In Quarantäne, [43b07479ee8d5fd79024096131d3af51]
PUP.Optional.SoftwareUpdater.A, HKLM\SOFTWARE\WOW6432NODE\SOFTWAREUPDATER|partner_keyword, EAZELDE, In Quarantäne, [14df32bbcbb0c175d772d575f212e51b]
PUP.Optional.SoftwareUpdater.A, HKLM\SOFTWARE\WOW6432NODE\SOFTWAREUPDATER|UpdaterPath, C:\Program Files (x86)\SoftwareUpdater\AppsUpdater.exe, In Quarantäne, [ea09e508bbc043f3c9fc0bf72ad94eb2]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 14
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\defaults, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\defaults\preferences, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\userCode, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\locale, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\locale\en-US, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.DSearchLink.A, C:\ProgramData\DSearchLink, In Quarantäne, [ce255598443758def40439c103ff7789],
Dateien: 137
PUP.Optional.Vittalia, C:\Program Files (x86)\SoftwareUpdater\AppsUpdater.exe, In Quarantäne, [e40f7b72ec8f7abcb03c8625d22f7789],
PUP.Optional.Vittalia, C:\Program Files (x86)\SoftwareUpdater\uninstall.exe, In Quarantäne, [d41f0ce198e37cbad997c2108180f709],
PUP.Optional.Vittalia, C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe_old, In Quarantäne, [50a33bb2314ad462707b4d5e4ab719e7],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome.manifest, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\install.rdf, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\32ca59b235baa9e6f0a955dbbb550ee9.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\647b2116d928a311ca8c93d8ebb17584.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\700ae88efa2fcee438eface545719a99.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\a6454a51986a98c3c714a4406c5a13fb.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\background.html, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\browser.xul, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\dialog.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\e3b90b590fec626ad2f1d5a84ab59aba.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\ffCoreFilesIndex.txt, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\options.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\options.xul, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\search_dialog.xul, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\ac4f760e97ec1947861ed38017e34494.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\04cba1d1fa8a7496605087bee22b1440.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\20e9c3851f766ff15e97c0bbf6d93e5e.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\40dd01edb86700f8b7959b26b2e84761.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\53e2e3427804245c7a2f81d8f508bf1c.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\6b40b1b8da70ff58b2cb0d0572c29677.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\80add444914a4bfc72f593bb89d469dc.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\9ef4a9f53488e24e464b718728bf84ad.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\a9c7992fb52b4e20a6dabfd48459f175.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\af3f99e7e058f2b96938ff23d04aeb1d.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\c520a029845196649307c27b5d791321.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\c55d77f1d18820e4bf209e9bf25ae95e.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\c9f1096a00d742ea4ee6250881eddeff.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\cb1eaa1be294ff6a9197bfdae6b0aa0b.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\d4ff7460ffd63651821080e8dcf7ce80.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\api\f5dc8e8ee49e1a9174459793fc4e6df0.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\6a994a3c97fb65a5724a71f50eff9c79.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\0115ec0bea60f798570f6f2f9ca233d2.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\076d9e7f0410c20286d8b323f917d7b7.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\0a32b9fc9fa9c5f0d0245902a80e25c3.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\11d35254796896e4a55762aaf0ab8903.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\13b0650a3a66d1634010a9eab716b49a.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\177d56ade45eb6b94a5e109e63293c42.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\1e6fbb3c8a6d0c228a1e4270e7dc01a0.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\38a467d8953a0636e0464b7d82ad4c2b.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\3b7b9f2cb377aaa3a237cbf1cef91326.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\3e48b038212da585903b1627470cdbc1.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\482ebe4854c6a2437e262758119055a2.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\518ca5c5c2c28cc543fc026ab4e591c2.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\636d1d1123e533e5bf43d7f0d1406076.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\8bf095392cb3f8494271a699b16995ab.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\a66a1206900f7b6f8eaddd2dc87c297e.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\b0c4023273ae5234b3bed2d5fbb90f8f.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\c16b2be48b6f55c3329c3a6054e91b6f.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\d9fc20aad34a65add863b855fa810490.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\de1f694dcd32cf56ce69b799928d7b98.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\chrome\content\core\installer.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\defaults\preferences\prefs.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\manifest.xml, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins.json, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\1.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\102.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\104.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\13.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\14.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\16.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\17.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\177.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\180.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\182.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\183.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\184.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\207.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\21.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\22.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\220.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\221.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\223.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\226.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\230.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\233.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\244.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\246.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\260.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\263.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\268.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\28.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\281.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\298.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\4.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\47.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\64.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\7.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\72.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\78.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\9.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\91.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\93.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\plugins\98.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\userCode\background.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\extensionData\userCode\extension.js, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\locale\en-US\translations.dtd, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\button1.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\button2.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\button3.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\button4.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\button5.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\crossrider_statusbar.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\icon128.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\icon16.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\icon24.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\icon48.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\panelarrow-up.png, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\popup.html, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\skin.css, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com\skin\update.css, In Quarantäne, [ee05b33af3880432b95ba136b250748c],
PUP.Optional.CrossRider.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "148747e6e676280adbaabe21cffef9a4");), Ersetzt,[1ad9a14cbac10432c1cc7eb3d233a55b]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.admin", false);), Ersetzt,[5a99905dafccc86e4262df5248bda45c]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.aflt", "babsst");), Ersetzt,[599a816c552647efc1e30c25c83d5ea2]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");), Ersetzt,[c42f6588d1aaf442baea5fd222e39a66]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.autoRvrt", "false");), Ersetzt,[1ad913da3a41d0669d0751e0947120e0]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.dfltLng", "de");), Ersetzt,[d122d11c94e71521752f1819c342926e]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.excTlbr", false);), Ersetzt,[1fd4c52887f496a0b5ef4ae73fc6e21e]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.ffxUnstlRst", true);), Ersetzt,[0de6fcf1df9cec4abbe9da571fe6be42]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.id", "780f8908000000000000001e101f05ea");), Ersetzt,[a94a618c4239c86e0c98aa8763a27a86]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlDay", "15979");), Ersetzt,[3eb5da13c8b3c175653f90a1e61f0000]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.instlRef", "sst");), Ersetzt,[04ef79743447b87e03a154dd3cc9827e]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.newTab", false);), Ersetzt,[c52ed11c364564d2d0d4171af213fa06]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prdct", "delta");), Ersetzt,[cc2739b43c3fe4525a4aeb460500df21]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.prtnrId", "delta");), Ersetzt,[d023fdf0017acf67356f64cd5ca947b9]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.rvrt", "false");), Ersetzt,[6e85717cdf9c3501ddc759d84bba6799]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.smplGrp", "none");), Ersetzt,[03f05f8eb3c857dff3b18fa29e67a759]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrId", "base");), Ersetzt,[5d96608d265580b6dbc9939ead583ac6]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.tlbrSrchUrl", "");), Ersetzt,[42b105e8cfac7eb8d8ccc56cd332ce32]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsn", "1.8.24.6");), Ersetzt,[28cb0be2413a54e25f45c07161a405fb]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsnTs", "1.8.24.619:31:25");), Ersetzt,[cc274ba281fa4beb653fb27f48bde41c]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta.vrsni", "1.8.24.6");), Ersetzt,[9a59638a186358dec1e334fd0cf907f9]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babExt", "");), Ersetzt,[846f3cb1afcc55e13f65929fb74e8c74]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.babTrack", "affID=119403&tsp=5022");), Ersetzt,[7a79a14c710ac670e2c248e99c69a55b]
PUP.Optional.Delta.A, C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.delta_i.srcExt", "ss");), Ersetzt,[16dd3faef3885dd96143b77a63a2d62a]
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner Log File Code:
# AdwCleaner v3.310 - Bericht erstellt am 15/09/2014 um 17:25:24
# Aktualisiert 12/09/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : G6-2376 - HPG6
# Gestartet von : C:\Users\G6-2376\Desktop\AdwCleaner_3.310.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Program Files (x86)\iMesh
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\SoftwareUpdater
Ordner Gelöscht : C:\Users\G6-2376\AppData\LocalLow\Delta
Ordner Gelöscht : C:\Users\G6-2376\AppData\Roaming\Babylon
Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk
Datei Gelöscht : C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\invalidprefs.js
Datei Gelöscht : C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\user.js
***** [ Tasks ] *****
Task Gelöscht : DealPlyUpdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671}
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\LyricsBuddy-1
Schlüssel Gelöscht : HKLM\SOFTWARE\Vittalia
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledThirdPartyPrograms
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16921
-\\ Mozilla Firefox v32.0.1 (x86 de)
[ Datei : C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.a8af2e5268c0942dc8d011001b936572c5f890a75ea4344fa9c150da08497ff9dcom41868.41868.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
Zeile gelöscht : user_pref("extensions.delta.admin", false);
Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.delta.id", "780f8908000000000000001e101f05ea");
Zeile gelöscht : user_pref("extensions.delta.instlDay", "15979");
Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.delta.newTab", false);
Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.619:31:25");
Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6");
Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=119403&tsp=5022");
Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [4795 octets] - [15/09/2014 17:20:07]
AdwCleaner[S0].txt - [4275 octets] - [15/09/2014 17:25:24]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4335 octets] ########## JRT Log-File Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by G6-2376 on 15.09.2014 at 17:36:48,05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{130A418B-405C-4D02-88B7-3634410A5AFF}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{130A418B-405C-4D02-88B7-3634410A5AFF}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\G6-2376\AppData\Roaming\mozilla\firefox\profiles\b9k8wmcx.default\minidumps [11 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.09.2014 at 17:42:58,93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und das frische FRST Log-File
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by G6-2376 (administrator) on HPG6 on 15-09-2014 17:45:07
Running from C:\Users\G6-2376\Desktop
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Program Files\McAfee\AppStats\MfeASUM.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(McAfee, Inc.) C:\Program Files\McAfee\MAT\McPvTray.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe
(IObit) C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe
(IObit) C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-07-22] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491320 2012-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [580512 2012-07-09] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008 2011-08-26] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM\...\RunOnce: [NCPluginUpdater] => C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe [21720 2014-08-19] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-907070689-3175279176-1283973887-1001\...\Run: [Advanced SystemCare 6] => C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe [491840 2013-04-18] (IObit)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {130A418B-405C-4D02-88B7-3634410A5AFF} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - {A82506F1-A7C9-410F-849A-1A4B495179B1} URL = https://de.search.yahoo.com/search?fr=mcafee&type=A011DE0&p={SearchTerms}
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Advanced SystemCare Browser Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Advanced SystemCare 6\BrowerProtect\ASCPlugin_Protection.dll (IObit)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
Tcpip\..\Interfaces\{360D081A-2333-4F80-A4FA-43CB7EBD53E9}: [NameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{616B63C0-22FB-49C7-B6AD-C00550F686A9}: [NameServer] 193.189.244.225 193.189.244.206
Tcpip\..\Interfaces\{BAC8662B-D609-4427-B6CD-AFDC5E642D8B}: [NameServer] 193.189.244.225 193.189.244.206
FireFox:
========
FF ProfilePath: C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @videolan.org/vlc,version=2.1.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Advanced SystemCare Surfing Protection - C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\Extensions\ascsurfingprotection@iobit.com [2013-10-06]
FF Extension: Adblock Plus - C:\Users\G6-2376\AppData\Roaming\Mozilla\Firefox\Profiles\b9k8wmcx.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-13]
FF HKLM-x32\...\Firefox\Extensions: [OKitSpace@Vittalia.es] - C:\Users\G6-2376\AppData\Roaming\okitspace\Firefox
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2013-10-06]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2013-10-06]
Chrome:
=======
CHR Profile: C:\Users\G6-2376\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-09-14]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2014-09-14]
CHR HKLM-x32\...\Chrome\Extension: [nfengeggddojhakldhlpjdlddgkkjkdd] - C:\Program Files (x86)\IObit\Advanced SystemCare 6\BrowerProtect\ASC_GhromePluginFor6.crx [2013-10-06]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdvancedSystemCareService6; C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe [574272 2013-04-18] (IObit)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [85504 2012-08-10] (Hewlett-Packard Company) [File not signed]
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
R2 McAfee SiteAdvisor Service; c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [156904 2014-09-02] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\McAfee\MSC\McAWFwk.exe [225216 2011-01-28] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.)
S2 McOobeSv; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 MfeASUM; C:\Program Files\McAfee\AppStats\MfeASUM.exe [335216 2013-10-16] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-03-18] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-04-03] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [189912 2014-04-03] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [321536 2012-07-22] (IDT, Inc.) [File not signed]
R2 StartMenuService; C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe [75584 2013-09-29] (IObit)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [35496 2012-07-10] (Advanced Micro Devices, Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70592 2014-04-03] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 ewusbnet; C:\Windows\system32\DRIVERS\ewusbnet.sys [246224 2009-12-07] (Huawei Technologies Co., Ltd.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
S3 hwusbdev; C:\Windows\system32\DRIVERS\ewusbdev.sys [114304 2009-10-12] (Huawei Technologies Co., Ltd.)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-15] (Malwarebytes Corporation)
R0 McPvDrv; C:\Windows\System32\drivers\McPvDrv.sys [74560 2013-09-09] (McAfee, Inc.)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [177544 2014-04-03] (McAfee, Inc.)
R1 MfeASKM; C:\Program Files\McAfee\AppStats\MfeASKM.sys [31408 2013-10-16] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311856 2014-04-03] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69352 2014-04-03] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [522360 2014-04-03] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [784760 2014-04-03] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [441264 2014-03-18] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-03-18] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [346760 2014-04-03] (McAfee, Inc.)
S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-24] (Synaptics Incorporated)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20288 2012-08-03] (Hewlett-Packard Development Company, L.P.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-15 17:42 - 2014-09-15 17:42 - 00001041 _____ () C:\Users\G6-2376\Desktop\JRT.txt
2014-09-15 17:36 - 2014-09-15 17:36 - 00000000 ____D () C:\Windows\ERUNT
2014-09-15 17:31 - 2014-09-15 17:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-09-15 17:27 - 2014-09-15 17:28 - 00004427 _____ () C:\Users\G6-2376\Desktop\AdwCleaner.txt
2014-09-15 17:19 - 2014-09-15 17:25 - 00000000 ____D () C:\AdwCleaner
2014-09-15 17:16 - 2014-09-15 17:16 - 00044186 _____ () C:\Users\G6-2376\Desktop\mbam.txt
2014-09-15 16:50 - 2014-09-15 17:14 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-15 16:49 - 2014-09-15 16:49 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-15 16:49 - 2014-09-15 16:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-15 16:49 - 2014-09-15 16:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-15 16:49 - 2014-09-15 16:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-15 16:49 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-15 16:49 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-15 16:49 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-15 16:44 - 2014-09-15 16:44 - 01016261 _____ (Thisisu) C:\Users\G6-2376\Desktop\JRT.exe
2014-09-15 16:43 - 2014-09-15 16:44 - 01373475 _____ () C:\Users\G6-2376\Desktop\AdwCleaner_3.310.exe
2014-09-14 20:43 - 2014-09-14 20:43 - 00028431 _____ () C:\ComboFix.txt
2014-09-14 20:35 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-14 20:35 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-14 20:35 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-14 20:35 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-14 20:35 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-14 20:35 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-09-14 20:35 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-14 20:35 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-14 20:35 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-14 20:32 - 2014-09-14 20:43 - 00000000 ____D () C:\Qoobox
2014-09-14 20:31 - 2014-09-14 20:41 - 00000000 ____D () C:\Windows\erdnt
2014-09-14 20:12 - 2014-09-14 20:12 - 00001264 _____ () C:\Users\G6-2376\Desktop\Revo Uninstaller.lnk
2014-09-14 20:12 - 2014-09-14 20:12 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-09-14 20:10 - 2014-09-14 20:11 - 05578360 ____R (Swearware) C:\Users\G6-2376\Desktop\ComboFix.exe
2014-09-14 17:39 - 2014-09-14 17:39 - 00004684 _____ () C:\Users\G6-2376\Desktop\gmer.log
2014-09-14 17:20 - 2014-09-14 17:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-14 17:04 - 2014-09-14 17:04 - 00034793 _____ () C:\Users\G6-2376\Desktop\Addition.txt
2014-09-14 17:03 - 2014-09-15 17:45 - 00018685 _____ () C:\Users\G6-2376\Desktop\FRST.txt
2014-09-14 17:02 - 2014-09-15 17:45 - 00000000 ____D () C:\FRST
2014-09-14 17:01 - 2014-09-14 17:01 - 00000476 _____ () C:\Users\G6-2376\Desktop\defogger_disable.log
2014-09-14 17:01 - 2014-09-14 17:01 - 00000000 _____ () C:\Users\G6-2376\defogger_reenable
2014-09-14 16:57 - 2014-09-14 16:57 - 00380416 _____ () C:\Users\G6-2376\Desktop\Gmer-19357.exe
2014-09-14 16:56 - 2014-09-14 16:56 - 02105856 _____ (Farbar) C:\Users\G6-2376\Desktop\FRST64.exe
2014-09-14 16:54 - 2014-09-14 16:54 - 00050477 _____ () C:\Users\G6-2376\Desktop\Defogger.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-15 17:45 - 2014-09-14 17:03 - 00018685 _____ () C:\Users\G6-2376\Desktop\FRST.txt
2014-09-15 17:45 - 2014-09-14 17:02 - 00000000 ____D () C:\FRST
2014-09-15 17:45 - 2013-06-15 11:43 - 01477765 _____ () C:\Windows\WindowsUpdate.log
2014-09-15 17:42 - 2014-09-15 17:42 - 00001041 _____ () C:\Users\G6-2376\Desktop\JRT.txt
2014-09-15 17:36 - 2014-09-15 17:36 - 00000000 ____D () C:\Windows\ERUNT
2014-09-15 17:34 - 2012-09-12 09:20 - 00830120 _____ () C:\Windows\system32\perfh007.dat
2014-09-15 17:34 - 2012-09-12 09:20 - 00188224 _____ () C:\Windows\system32\perfc007.dat
2014-09-15 17:34 - 2012-07-26 09:28 - 01949432 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-15 17:31 - 2014-09-15 17:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-09-15 17:31 - 2013-10-06 20:49 - 00001844 _____ () C:\Users\Public\Desktop\McAfee Total Protection.lnk
2014-09-15 17:29 - 2013-10-06 16:55 - 00000000 __RSD () C:\Users\G6-2376\Documents\McAfee-Tresore
2014-09-15 17:28 - 2014-09-15 17:27 - 00004427 _____ () C:\Users\G6-2376\Desktop\AdwCleaner.txt
2014-09-15 17:26 - 2012-08-04 00:23 - 00524726 _____ () C:\Windows\PFRO.log
2014-09-15 17:26 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-15 17:25 - 2014-09-15 17:19 - 00000000 ____D () C:\AdwCleaner
2014-09-15 17:16 - 2014-09-15 17:16 - 00044186 _____ () C:\Users\G6-2376\Desktop\mbam.txt
2014-09-15 17:14 - 2014-09-15 16:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-15 17:08 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\tracing
2014-09-15 17:06 - 2013-08-24 23:05 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-15 17:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-09-15 16:49 - 2014-09-15 16:49 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-15 16:49 - 2014-09-15 16:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-15 16:49 - 2014-09-15 16:49 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-15 16:49 - 2014-09-15 16:49 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-15 16:44 - 2014-09-15 16:44 - 01016261 _____ (Thisisu) C:\Users\G6-2376\Desktop\JRT.exe
2014-09-15 16:44 - 2014-09-15 16:43 - 01373475 _____ () C:\Users\G6-2376\Desktop\AdwCleaner_3.310.exe
2014-09-14 20:50 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-09-14 20:43 - 2014-09-14 20:43 - 00028431 _____ () C:\ComboFix.txt
2014-09-14 20:43 - 2014-09-14 20:32 - 00000000 ____D () C:\Qoobox
2014-09-14 20:41 - 2014-09-14 20:31 - 00000000 ____D () C:\Windows\erdnt
2014-09-14 20:41 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-09-14 20:26 - 2013-08-24 23:00 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-09-14 20:12 - 2014-09-14 20:12 - 00001264 _____ () C:\Users\G6-2376\Desktop\Revo Uninstaller.lnk
2014-09-14 20:12 - 2014-09-14 20:12 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-09-14 20:11 - 2014-09-14 20:10 - 05578360 ____R (Swearware) C:\Users\G6-2376\Desktop\ComboFix.exe
2014-09-14 17:41 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-09-14 17:39 - 2014-09-14 17:39 - 00004684 _____ () C:\Users\G6-2376\Desktop\gmer.log
2014-09-14 17:28 - 2013-10-06 20:47 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-09-14 17:20 - 2014-09-14 17:20 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-14 17:04 - 2014-09-14 17:04 - 00034793 _____ () C:\Users\G6-2376\Desktop\Addition.txt
2014-09-14 17:01 - 2014-09-14 17:01 - 00000476 _____ () C:\Users\G6-2376\Desktop\defogger_disable.log
2014-09-14 17:01 - 2014-09-14 17:01 - 00000000 _____ () C:\Users\G6-2376\defogger_reenable
2014-09-14 17:01 - 2013-06-15 11:43 - 00000000 ____D () C:\Users\G6-2376
2014-09-14 16:57 - 2014-09-14 16:57 - 00380416 _____ () C:\Users\G6-2376\Desktop\Gmer-19357.exe
2014-09-14 16:56 - 2014-09-14 16:56 - 02105856 _____ (Farbar) C:\Users\G6-2376\Desktop\FRST64.exe
2014-09-14 16:54 - 2014-09-14 16:54 - 00050477 _____ () C:\Users\G6-2376\Desktop\Defogger.exe
2014-09-14 16:07 - 2013-08-24 23:05 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-14 16:02 - 2014-07-13 13:10 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-09-14 16:02 - 2014-07-13 13:10 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-09-14 15:57 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
Some content of TEMP:
====================
C:\Users\G6-2376\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-14 19:19
==================== End Of Log ============================ --- --- ---
--- --- ---
Vielen Dank schon mal vorab! |