Code:
ComboFix 14-10-27.01 - Asus 28.10.2014 21:20:54.1.2 - x64
Microsoft Windows 8 6.2.9200.0.1252.49.1031.18.3980.2467 [GMT 1:00]
ausgeführt von:: F:\ComboFix.exe
AV: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Browsers+Apps+1.1\45a2385e-4baa-493c-ad51-c0df4833fd6c.dll
c:\program files (x86)\Browsers+Apps+1.1\cdc412ab-112e-4df3-b7b0-89539cc30d3b.dll
c:\program files (x86)\Easy Speed Check
c:\program files (x86)\Easy Speed Check\cwebpage.dll
c:\program files (x86)\Easy Speed Check\easyspeedcheck.exe
c:\program files (x86)\Easy Speed Check\esc.ico
c:\program files (x86)\Easy Speed Check\libcurl.dll
c:\program files (x86)\Easy Speed Check\libeay32.dll
c:\program files (x86)\Easy Speed Check\libgcc_s_dw2-1.dll
c:\program files (x86)\Easy Speed Check\libidn-11.dll
c:\program files (x86)\Easy Speed Check\libstdc++-6.dll
c:\program files (x86)\Easy Speed Check\ssleay32.dll
c:\program files (x86)\Easy Speed Check\uninstall.exe
c:\program files (x86)\Easy Speed Check\zlib1.dll
c:\program files (x86)\MyPC Backup
c:\program files (x86)\MyPC Backup\aff.conf
c:\program files (x86)\MyPC Backup\AlphaVSS.51.x86.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.52.x64.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.52.x86.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.60.x64.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.60.x86.dll
c:\program files (x86)\MyPC Backup\AlphaVSS.Common.dll
c:\program files (x86)\MyPC Backup\AWSSDK.dll
c:\program files (x86)\MyPC Backup\BackupStack.exe
c:\program files (x86)\MyPC Backup\Configuration Updater.exe
c:\program files (x86)\MyPC Backup\Crypto32.dll
c:\program files (x86)\MyPC Backup\Crypto64.dll
c:\program files (x86)\MyPC Backup\Database\mpcb_backup_conf.db
c:\program files (x86)\MyPC Backup\Database\mpcb_file_cache.db
c:\program files (x86)\MyPC Backup\Database\mpcb_queues.db
c:\program files (x86)\MyPC Backup\Database\mpcb_settings.db
c:\program files (x86)\MyPC Backup\Database\mpcb_sig_cache.db
c:\program files (x86)\MyPC Backup\de_DE.mo
c:\program files (x86)\MyPC Backup\diffstack.dll
c:\program files (x86)\MyPC Backup\es_ES.mo
c:\program files (x86)\MyPC Backup\fr_FR.mo
c:\program files (x86)\MyPC Backup\GetText.dll
c:\program files (x86)\MyPC Backup\it_IT.mo
c:\program files (x86)\MyPC Backup\LinqBridge.dll
c:\program files (x86)\MyPC Backup\log\APPLICATION.log
c:\program files (x86)\MyPC Backup\log\WAIT_HANDLES.log
c:\program files (x86)\MyPC Backup\LogicNP.EZShellExtensions.dll
c:\program files (x86)\MyPC Backup\MPCBClient.dll
c:\program files (x86)\MyPC Backup\MPCBContextMenu.dll
c:\program files (x86)\MyPC Backup\MPCBIconOverlays.dll
c:\program files (x86)\MyPC Backup\MyPC Backup.exe
c:\program files (x86)\MyPC Backup\mypcbackup.ico
c:\program files (x86)\MyPC Backup\ObjectListView.dll
c:\program files (x86)\MyPC Backup\pt_PT.mo
c:\program files (x86)\MyPC Backup\RegisterExtensionDotNet20_x64.exe
c:\program files (x86)\MyPC Backup\RegisterExtensionDotNet20_x86.exe
c:\program files (x86)\MyPC Backup\RestartExplorer.exe
c:\program files (x86)\MyPC Backup\Service Start.exe
c:\program files (x86)\MyPC Backup\Shared Stack.dll
c:\program files (x86)\MyPC Backup\Signup Wizard.exe
c:\program files (x86)\MyPC Backup\syncicon.ico
c:\program files (x86)\MyPC Backup\syncing.ico
c:\program files (x86)\MyPC Backup\tick.ico
c:\program files (x86)\MyPC Backup\uninst.exe
c:\program files (x86)\MyPC Backup\UnRegisterExtensions.exe
c:\program files (x86)\MyPC Backup\Updater.exe
c:\program files (x86)\MyPC Backup\x64\System.Data.SQLite.dll
c:\program files (x86)\MyPC Backup\x86\System.Data.SQLite.dll
c:\program files (x86)\Probit Software\Easy Speed PC
c:\program files (x86)\Probit Software\Easy Speed PC\EasySpeedPC.chm
c:\program files (x86)\Probit Software\Easy Speed PC\EasySpeedPC.exe
c:\program files (x86)\Probit Software\Easy Speed PC\esp.ico
c:\program files (x86)\Probit Software\Easy Speed PC\ESPCGuard.exe
c:\program files (x86)\Probit Software\Easy Speed PC\ESPCLauncher.exe
c:\program files (x86)\Probit Software\Easy Speed PC\ESPCReminder.exe
c:\program files (x86)\Probit Software\Easy Speed PC\ESPCSchedule.exe
c:\program files (x86)\Probit Software\Easy Speed PC\ESPCSmartScan.exe
c:\program files (x86)\Probit Software\Easy Speed PC\file_id.diz
c:\program files (x86)\Probit Software\Easy Speed PC\German.ini
c:\program files (x86)\Probit Software\Easy Speed PC\HomePage.url
c:\program files (x86)\Probit Software\Easy Speed PC\scan.gif
c:\program files (x86)\Probit Software\Easy Speed PC\sqlite3.dll
c:\program files (x86)\Probit Software\Easy Speed PC\uninstall.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\MYBESTOFFERSTODAY
c:\programdata\Microsoft\Windows\Start Menu\Programs\MYBESTOFFERSTODAY\MyBestOffersToday.lnk
c:\programdata\SetStretch.exe
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica129e.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica129f.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica1550.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica1551.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica18d3.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica18d4.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica1962.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica1963.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica273a.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica273b.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica2b76.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica2b77.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica4839.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica483a.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica8e32.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\ica8e33.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\icaa2f2.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\icaa2f3.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\icab9cd.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\icaf0f3.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\icaf41.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\icaf42.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\icaf78e.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\icaf78f.ica
c:\users\Asus\AppData\Local\Microsoft\Windows\Temporary Internet Files\icafa1d.ica
c:\users\Asus\AppData\Local\nsj5925.tmp
c:\users\Asus\AppData\Roaming\Microsoft\Windows\Recent\Thumbs.db
.
.
((((((((((((((((((((((((((((((((((((((( Treiber/Dienste )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_globalUpdate
-------\Legacy_BackupStack
-------\Legacy_BackupStack
-------\Service_BackupStack
-------\Service_BackupStack
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-09-28 bis 2014-10-28 ))))))))))))))))))))))))))))))
.
.
2014-10-28 20:30 . 2014-10-28 20:30 -------- d-----w- c:\users\Asus\AppData\Local\temp
2014-10-28 20:30 . 2014-10-28 20:30 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-10-28 20:21 . 2014-10-28 20:21 -------- d-----w- c:\program files (x86)\Enigma Software Group
2014-10-28 20:19 . 2014-10-28 20:21 -------- d-----w- c:\windows\0028CB34D5D3460FB308A39A095A5E01.TMP
2014-10-28 20:02 . 2014-08-07 08:59 11319200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2EE56F4E-116F-46FB-840E-047D02189EF6}\mpengine.dll
2014-10-28 18:41 . 2012-06-22 11:01 22704 ----a-w- c:\windows\system32\drivers\EsgScanner.sys
2014-10-28 18:40 . 2014-10-28 18:41 -------- d-----w- C:\sh4ldr
2014-10-28 18:40 . 2014-10-28 18:40 -------- d-----w- c:\program files\Enigma Software Group
2014-10-28 18:39 . 2014-10-28 18:41 -------- d-----w- c:\windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP
2014-10-28 18:39 . 2014-10-28 20:19 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-10-26 15:51 . 2014-10-28 20:09 -------- d-----w- c:\users\Asus\AppData\Roaming\Systweak
2014-10-26 15:51 . 2014-08-05 18:14 20328 ----a-w- c:\windows\system32\roboot64.exe
2014-10-26 15:50 . 2014-10-26 15:50 -------- d-----w- c:\users\Asus\AppData\Local\LPT
2014-10-26 15:50 . 2014-10-26 15:50 -------- d-----w- c:\users\Asus\AppData\Local\Smartbar
2014-10-20 14:53 . 2014-10-20 14:53 -------- d-----w- c:\users\Asus\AppData\Roaming\Probit Software
2014-10-19 20:08 . 2014-10-19 20:08 -------- d-----w- c:\program files (x86)\AnyProtectEx
2014-10-19 20:08 . 2014-10-19 20:08 -------- d-sh--w- c:\users\Asus\AppData\Roaming\AnyProtectEx
2014-10-19 19:45 . 2014-10-19 05:20 48784 ----a-w- c:\windows\system32\drivers\{6eaeb8af-e4d9-4df5-b9d7-815f2928cdf7}Gw64.sys
2014-10-19 18:48 . 2014-10-19 18:48 -------- d-----w- c:\users\Asus\AppData\Roaming\InetStat
2014-10-19 18:43 . 2014-10-20 13:09 -------- d-----w- c:\program files (x86)\Krab Web
2014-10-19 18:41 . 2014-10-19 18:41 -------- d-----w- c:\users\Asus\AppData\Roaming\Optimizer Pro
2014-10-19 18:38 . 2014-10-19 18:38 -------- d-----w- c:\users\Asus\AppData\Local\com
2014-10-19 18:38 . 2014-10-19 18:38 1512848 ----a-w- c:\users\Asus\AppData\Roaming\MQQ.exe
2014-10-19 18:37 . 2014-10-26 15:39 -------- d--h--w- c:\users\Public\Temp
2014-10-19 18:37 . 2014-10-19 18:37 -------- d-----w- c:\programdata\IePluginServices
2014-10-19 18:37 . 2014-10-19 18:37 -------- d-----w- c:\program files (x86)\SupTab
2014-10-19 18:37 . 2014-10-19 18:37 -------- d-----w- c:\users\Asus\AppData\Local\fastplayer
2014-10-19 18:37 . 2014-10-19 18:37 2001296 ----a-w- c:\users\Asus\AppData\Roaming\TSLPBY.exe
2014-10-19 18:37 . 2014-10-19 18:37 -------- d-----w- c:\programdata\WindowsMangerProtect
2014-10-19 18:36 . 2014-10-19 18:36 -------- d-----w- c:\program files (x86)\globalUpdate
2014-10-19 18:36 . 2014-10-19 18:36 -------- d-----w- c:\users\Asus\AppData\Local\globalUpdate
2014-10-19 18:36 . 2014-10-28 20:29 -------- d-----w- c:\program files (x86)\Browsers+Apps+1.1
2014-10-19 18:36 . 2014-10-19 18:36 -------- d-----w- c:\users\Asus\AppData\Roaming\omiga-plus
2014-10-19 18:35 . 2014-10-19 18:36 -------- d-----w- c:\program files (x86)\FastPlayer
2014-10-19 18:35 . 2014-10-19 18:35 -------- d-----w- c:\program files (x86)\Optimizer Pro
2014-10-19 18:35 . 2014-10-28 20:40 -------- d-----w- c:\users\Asus\AppData\Local\mbot_de_176
2014-10-19 18:35 . 2014-10-19 18:35 -------- d-----w- c:\program files (x86)\mbot_de_176
2014-10-19 18:35 . 2014-10-18 21:00 1318912 ----a-w- c:\windows\rcore.exe
2014-10-19 18:34 . 2014-10-19 18:34 -------- d-----w- c:\program files (x86)\ver1NewPlayer
2014-10-19 18:34 . 2014-10-19 18:34 -------- d-----w- c:\users\Asus\AppData\Local\Weather_Protector_LLC
2014-10-19 18:34 . 2014-10-19 18:34 -------- d-----w- c:\users\Asus\AppData\Roaming\VOPackage
2014-10-19 18:34 . 2014-10-28 20:29 -------- d-----w- c:\program files (x86)\Probit Software
2014-10-19 18:34 . 2014-10-19 18:34 -------- d-----w- c:\program files (x86)\PepperZip
2014-10-19 18:34 . 2014-10-19 18:34 -------- d-----w- c:\users\Asus\AppData\Local\StormWatch
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-26 15:39 . 2012-11-28 20:03 500 ----a-w- c:\users\Asus\AppData\Roaming\sp_data.sys
2014-09-21 19:56 . 2012-07-26 08:13 23256 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{11111111-1111-1111-1111-110611501155}]
2014-10-19 18:38 580496 ----a-w- c:\program files (x86)\Browsers+Apps+1.1\Browsers+Apps+1.1-bho.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]
2012-06-02 20:25 298568 ----a-w- c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
2014-10-19 18:37 515464 ----a-w- c:\program files (x86)\SupTab\SupTab.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}]
2013-08-15 08:08 314264 ----a-w- c:\program files (x86)\Delta\delta\1.8.24.5\bh\delta.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{feadf62f-aec2-46a1-a087-40149f311df9}]
2014-10-19 18:43 250096 ----a-w- c:\program files (x86)\Krab Web\KrabWebbho.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KiesPreload"="c:\program files (x86)\Samsung\Kies\Kies.exe" [2012-11-12 968120]
"KiesAirMessage"="c:\program files (x86)\Samsung\Kies\KiesAirMessage.exe" [2012-11-01 577536]
"InetStat"="c:\users\Asus\AppData\Roaming\InetStat\inetstat.exe" [2014-10-19 702478]
"Browser Infrastructure Helper"="c:\users\Asus\AppData\Local\Smartbar\Application\Smartbar.exe" [2014-08-27 28192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2013-12-18 40312]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2012-08-16 5264016]
"RemoteControl10"="c:\program files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" [2012-03-28 91432]
"ASUSWebStorage"="c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe" [2012-08-28 3417984]
"KiesTrayAgent"="c:\program files (x86)\Samsung\Kies\KiesTrayAgent.exe" [2012-11-12 309688]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2012-12-14 383544]
"BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"iTunesHelper"="C:\iTunesHelper.exe" [2013-11-01 152392]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]
"mbot_de_176"="c:\program files (x86)\mbot_de_176\mbot_de_176.exe" [2014-10-17 3976616]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"upmbot_de_176.exe"="c:\users\Asus\AppData\Local\mbot_de_176\upmbot_de_176.exe" [2014-10-17 3338720]
.
c:\users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
StormWatch.lnk - c:\users\Asus\AppData\Local\StormWatch\StormWatch.exe /restart [2014-8-21 160936]
StormWatchApp.lnk - c:\users\Asus\AppData\Local\StormWatch\StormWatchApp.exe [2014-9-29 1147416]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\StartUp\
AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe /start [2012-10-28 549040]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.8.150\SSScheduler.exe [2014-4-9 332016]
t@x aktuell.lnk - c:\program files (x86)\Buhl finance\tax Steuersoftware 2014\taxaktuell.exe [2014-10-19 587856]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"EnableUIADesktopToggle"= 0 (0x0)
"EnableCursorSuppression"= 1 (0x1)
"ConsentPromptBehaviorUser"= 3 (0x3)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
2;2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x]
R3 EsgScanner;EsgScanner;c:\windows\system32\DRIVERS\EsgScanner.sys;c:\windows\SYSNATIVE\DRIVERS\EsgScanner.sys [x]
R3 globalUpdatem;globalUpdate Update Service (globalUpdatem);c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe;c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe;c:\program files\McAfee Security Scan\3.8.150\McCHSvc.exe [x]
R3 RTL8168;Realtek 8168 NT-Treiber;c:\windows\system32\DRIVERS\Rt630x64.sys;c:\windows\SYSNATIVE\DRIVERS\Rt630x64.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\System32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
S0 iaStorA;iaStorA;c:\windows\System32\drivers\iaStorA.sys;c:\windows\SYSNATIVE\drivers\iaStorA.sys [x]
S1 {6eaeb8af-e4d9-4df5-b9d7-815f2928cdf7}Gw64;{6eaeb8af-e4d9-4df5-b9d7-815f2928cdf7}Gw64;c:\windows\system32\drivers\{6eaeb8af-e4d9-4df5-b9d7-815f2928cdf7}Gw64.sys;c:\windows\SYSNATIVE\drivers\{6eaeb8af-e4d9-4df5-b9d7-815f2928cdf7}Gw64.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys;c:\windows\SYSNATIVE\DRIVERS\ctxusbm.sys [x]
S2 70e6ca8c;Optimizer Pro Crash Monitor;c:\windows\system32\rundll32.exe;c:\windows\SYSNATIVE\rundll32.exe [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 ASUS InstantOn;ASUS InstantOn Service;c:\program files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe;c:\program files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 FastPlayerUpdaterService;FastPlayer Updater Service;c:\program files (x86)\FastPlayer\FastPlayerUpdaterService.exe;c:\program files (x86)\FastPlayer\FastPlayerUpdaterService.exe [x]
S2 IePluginServices;IePlugin Services;c:\programdata\IePluginServices\PluginService.exe;c:\programdata\IePluginServices\PluginService.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 NewPlayer;NewPlayer;c:\program files (x86)\ver1NewPlayer\a6Ff180.exe;c:\program files (x86)\ver1NewPlayer\a6Ff180.exe [x]
S2 rcores;rcores;c:\windows\rcore.exe;c:\windows\rcore.exe [x]
S2 servervo;VO Service component;c:\users\Asus\AppData\Roaming\VOPackage\VOsrv.exe;c:\users\Asus\AppData\Roaming\VOPackage\VOsrv.exe [x]
S2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE;c:\progra~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE [x]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [x]
S2 Update Krab Web;Update Krab Web;c:\program files (x86)\Krab Web\updateKrabWeb.exe;c:\program files (x86)\Krab Web\updateKrabWeb.exe [x]
S2 Util Krab Web;Util Krab Web;c:\program files (x86)\Krab Web\bin\utilKrabWeb.exe;c:\program files (x86)\Krab Web\bin\utilKrabWeb.exe [x]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe;c:\windows\SYSNATIVE\viakaraokesrv.exe [x]
S2 WindowsMangerProtect;WindowsMangerProtect Service;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe;c:\programdata\WindowsMangerProtect\ProtectWindowsManager.exe [x]
S2 ZAtheros Bt and Wlan Coex Agent;ZAtheros Bt and Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [x]
S3 AiCharger;ASUS Charger Driver;c:\windows\system32\DRIVERS\AiCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AiCharger.sys [x]
S3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 ATP;ASUS PS/2 Port Input Device;c:\windows\System32\drivers\AsusTP.sys;c:\windows\SYSNATIVE\drivers\AsusTP.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;c:\windows\system32\drivers\btath_avdt.sys;c:\windows\SYSNATIVE\drivers\btath_avdt.sys [x]
S3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;c:\windows\System32\drivers\btath_bus.sys;c:\windows\SYSNATIVE\drivers\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\System32\drivers\btath_hcrp.sys;c:\windows\SYSNATIVE\drivers\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\System32\drivers\btath_rcp.sys;c:\windows\SYSNATIVE\drivers\btath_rcp.sys [x]
S3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
S3 BthLEEnum;Treiber für energiearme Bluetooth-Geräte;c:\windows\system32\DRIVERS\BthLEEnum.sys;c:\windows\SYSNATIVE\DRIVERS\BthLEEnum.sys [x]
S3 HIDSwitch;ASUS Wireless Radio Control;c:\windows\System32\drivers\AsHIDSwitch64.sys;c:\windows\SYSNATIVE\drivers\AsHIDSwitch64.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 L1C;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C63x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C63x64.sys [x]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys;c:\program files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
S3 WUDFWpdMtp;WUDFWpdMtp;c:\windows\system32\DRIVERS\WUDFRd.sys;c:\windows\SYSNATIVE\DRIVERS\WUDFRd.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2014-10-28 c:\windows\Tasks\6d786e30-4981-463b-9e25-28967b78032e-1.job
- c:\program files (x86)\Browsers+Apps+1.1\Browsers+Apps+1.1-codedownloader.exe [2014-10-19 18:38]
.
2014-10-28 c:\windows\Tasks\6d786e30-4981-463b-9e25-28967b78032e-11.job
- c:\program files (x86)\Browsers+Apps+1.1\6d786e30-4981-463b-9e25-28967b78032e-11.exe [2014-10-19 18:37]
.
2014-10-28 c:\windows\Tasks\6d786e30-4981-463b-9e25-28967b78032e-2.job
- c:\program files (x86)\Browsers+Apps+1.1\6d786e30-4981-463b-9e25-28967b78032e-2.exe [2014-10-19 18:38]
.
2014-10-28 c:\windows\Tasks\6d786e30-4981-463b-9e25-28967b78032e-3.job
- c:\program files (x86)\Browsers+Apps+1.1\6d786e30-4981-463b-9e25-28967b78032e-3.exe [2014-10-19 18:36]
.
2014-10-28 c:\windows\Tasks\6d786e30-4981-463b-9e25-28967b78032e-4.job
- c:\program files (x86)\Browsers+Apps+1.1\6d786e30-4981-463b-9e25-28967b78032e-4.exe [2014-10-19 18:37]
.
2014-10-28 c:\windows\Tasks\6d786e30-4981-463b-9e25-28967b78032e-5.job
- c:\program files (x86)\Browsers+Apps+1.1\6d786e30-4981-463b-9e25-28967b78032e-5.exe [2014-10-19 18:38]
.
2014-10-28 c:\windows\Tasks\6d786e30-4981-463b-9e25-28967b78032e-5_user.job
- c:\program files (x86)\Browsers+Apps+1.1\6d786e30-4981-463b-9e25-28967b78032e-5.exe [2014-10-19 18:38]
.
2014-10-28 c:\windows\Tasks\6d786e30-4981-463b-9e25-28967b78032e-6.job
- c:\program files (x86)\Browsers+Apps+1.1\6d786e30-4981-463b-9e25-28967b78032e-6.exe [2014-10-19 18:37]
.
2014-10-28 c:\windows\Tasks\6d786e30-4981-463b-9e25-28967b78032e-7.job
- c:\program files (x86)\Browsers+Apps+1.1\6d786e30-4981-463b-9e25-28967b78032e-7.exe [2014-10-19 18:37]
.
2014-10-28 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-12 16:21]
.
2014-10-28 c:\windows\Tasks\globalUpdateUpdateTaskMachineCore.job
- c:\program files (x86)\globalUpdate\Update\GoogleUpdate.exe [2014-10-19 18:36]
.
2014-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-480692169-2859508237-3514454044-1001Core1ce0d4ca69a01c8.job
- c:\users\Asus\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-03 20:18]
.
2014-10-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-480692169-2859508237-3514454044-1001UA.job
- c:\users\Asus\AppData\Local\Google\Update\GoogleUpdate.exe [2012-12-03 20:18]
.
2014-10-28 c:\windows\Tasks\MQQ.job
- c:\users\Asus\AppData\Roaming\MQQ.exe [2014-10-19 18:38]
.
2014-10-28 c:\windows\Tasks\NewPlayer Update.job
- c:\program files (x86)\ver1NewPlayer\t0NewPlayerW38.exe [2014-10-19 18:34]
.
2014-10-28 c:\windows\Tasks\TSLPBY.job
- c:\users\Asus\AppData\Roaming\TSLPBY.exe [2014-10-19 18:37]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2012-03-13 09:23 1500672 ----a-w- c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2012-03-13 09:23 1500672 ----a-w- c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_U]
@="{1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D}"
[HKEY_CLASSES_ROOT\CLSID\{1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D}]
2012-03-13 09:23 1500672 ----a-w- c:\program files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSShellExt64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-08-16 170304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-08-16 398656]
"BtPreLoad"="c:\program files (x86)\Bluetooth Suite\BtPreLoad.exe" [2012-09-14 64640]
"ASUSQuickGesture(x86)"="c:\program files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe" [2012-09-11 20352]
"ASUSTPLoader(x64)"="c:\program files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe" [2012-09-11 169856]
"ASUSQuickGesture(x64)"="c:\program files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe" [2012-09-11 22400]
"ACMON"="c:\program files (x86)\ASUS\Splendid\ACMON.exe" [2012-08-24 107192]
"IntelliType Pro"="c:\program files\Microsoft Mouse and Keyboard Center\itype.exe" [2012-11-02 1464944]
"IntelliPoint"="c:\program files\Microsoft Mouse and Keyboard Center\ipoint.exe" [2012-11-02 2076272]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mDefault_Search_URL = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1413743725&from=tugs&uid=HitachiXHTS545050A7E380_TEJ51139JDBGMHJDBGMHX&q={searchTerms}
mDefault_Page_URL = hxxp://isearch.omiga-plus.com/?type=hp&ts=1413743725&from=tugs&uid=HitachiXHTS545050A7E380_TEJ51139JDBGMHJDBGMHX
mStart Page = hxxp://isearch.omiga-plus.com/?type=hp&ts=1413743725&from=tugs&uid=HitachiXHTS545050A7E380_TEJ51139JDBGMHJDBGMHX
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1413743725&from=tugs&uid=HitachiXHTS545050A7E380_TEJ51139JDBGMHJDBGMHX&q={searchTerms}
uInternet Settings,ProxyServer = http=127.0.0.1:13837;https=127.0.0.1:13837
uSearchAssistant = hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmy1jzOTjU3bh2prfgUVUg89mWqEo_izsgD9G5gZgHZ3xz3xamVKY4k88ocCFW1Hz75gPImXzxdzBgrBG0npbToyj6nR2zjGwMI0HuQ-I9yI7CmJPtDYiYQvOfxqFcUbROsQWuUs0KlSNfULqSBEA,,&q={searchTerms}
IE: An OneNote s&enden - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: Nach Microsoft &Excel exportieren - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: Nach Microsoft E&xcel exportieren - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: {{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\
FF - prefs.js: browser.search.selectedEngine - Web Search
FF - prefs.js: browser.startup.homepage - hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmy1jzOTjU3bh2prfgUVUg89mWqEo_izsgD9G5gZgHZ3xz3xamVKY4k88ocCFW1Hz75gPImXzxdzBgrBG0npbTkNfh76aYBltDownxJuQwt1TOHBdCuVnkWkN9Cj7JHXcqxx5uweIAQRUEv53BOEw,,
FF - prefs.js: keyword.URL - hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmy1jzOTjU3bh2prfgUVUg89mWqEo_izsgD9G5gZgHZ3xz3xamVKY4k88ocCFW1Hz75gPImXzxdzBgrBG0npbToyj6nR2zjGwMI0HuQ-I9yI7CmJPtDYiYQvOfxqFcUbROsQWuUs0KlSNfULqSBEw,,&q=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-Easy Speed PC - c:\program files (x86)\Probit Software\Easy Speed PC\ESPCLauncher.exe
Wow6432Node-HKCU-Run-EasySpeedCheck - c:\program files (x86)\Easy Speed Check\easyspeedcheck.exe
c:\users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk - c:\program files (x86)\MyPC Backup\MyPC Backup.exe
Toolbar-Locked - (no file)
AddRemove-Delta Chrome Toolbar - c:\users\Asus\AppData\Roaming\BabSolution\Shared\GUninstaller.exe
AddRemove-Easy Speed Check - c:\program files (x86)\Easy Speed Check\uninstall.exe
AddRemove-Easy Speed PC - c:\program files (x86)\Probit Software\Easy Speed PC\uninstall.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
@SACL=(02 0000)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
c:\program files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
c:\program files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
c:\program files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
c:\program files (x86)\Enigma Software Group\SpyHunter\Spyhunter4.exe
c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
c:\program files (x86)\ver1NewPlayer\M7S.exe
c:\program files (x86)\SupTab\HpUI.exe
c:\program files (x86)\SupTab\Loader32.exe
c:\program files (x86)\Optimizer Pro\OptProSmartScan.exe
c:\program files (x86)\Optimizer Pro\OptProReminder.exe
c:\program files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\windows\SysWOW64\ACEngSvr.exe
c:\program files (x86)\Citrix\Receiver\Receiver.exe
c:\program files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
c:\program files (x86)\Citrix\ICA Client\wfcrun32.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-10-28 21:46:34 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-10-28 20:46
.
Vor Suchlauf: 14 Verzeichnis(se), 121.144.606.720 Bytes frei
Nach Suchlauf: 18 Verzeichnis(se), 124.979.265.536 Bytes frei
.
- - End Of File - - D3A86A29088209EF8CEE5C3374E032F5 Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.21.2014:1)
OS: Windows 8 x64
Ran by Asus on 28.10.2014 at 21:52:52,47
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
Successfully stopped: [Service] 70e6ca8c
Successfully deleted: [Service] 70e6ca8c
Successfully stopped: [Service] iepluginservices
Successfully deleted: [Service] iepluginservices
Successfully stopped: [Service] servervo
Successfully deleted: [Service] servervo
Successfully stopped: [Service] windowsmangerprotect
Successfully deleted: [Service] windowsmangerprotect
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\browser infrastructure helper
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{ae07101b-46d4-4a98-af68-0333ea26e113}
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\Default_Search_URL
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL\\Default
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\searchURL\\Default
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\\SearchAssistant
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110611501155}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220622502255}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655505555}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666506655}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611501155}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622502255}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655505555}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666506655}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655505555}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666506655}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655505555}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666506655}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611501155}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
~~~ Files
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\bprotector web data"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\bprotectorpreferences"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_static.betterdeals00.betterdeals.co_0.localstorage"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_www.golsearch.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_www.golsearch.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_www.triple-search.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_www.triple-search.com_0.localstorage-journal"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_www1.delta-search.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Asus\appdata\local\google\chrome\user data\default\local storage\http_www1.delta-search.com_0.localstorage-journal"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\iepluginservices"
Successfully deleted: [Folder] "C:\ProgramData\windowsmangerprotect"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\delta"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\dvdvideosoftiehelpers"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\optimizer pro"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\vopackage"
Successfully deleted: [Folder] "C:\Users\Asus\appdata\local\apn"
Successfully deleted: [Folder] "C:\Users\Asus\appdata\local\globalupdate"
Successfully deleted: [Folder] "C:\Users\Asus\appdata\local\lpt"
Successfully deleted: [Folder] "C:\Users\Asus\appdata\local\onlysearch"
Successfully deleted: [Folder] "C:\Users\Asus\appdata\local\smartbar"
Successfully deleted: [Folder] "C:\Users\Asus\appdata\locallow\delta"
Successfully deleted: [Folder] "C:\Users\Asus\appdata\locallow\smartbar"
Successfully deleted: [Folder] "C:\Program Files (x86)\anyprotectex"
Successfully deleted: [Folder] "C:\Program Files (x86)\delta"
Failed to delete: [Folder] "C:\Program Files (x86)\globalupdate"
Successfully deleted: [Folder] "C:\Program Files (x86)\optimizer pro"
Failed to delete: [Folder] "C:\Program Files (x86)\suptab"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\microsoft\windows\start menu\programs\anyprotect pc backup"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\microsoft\windows\start menu\programs\mypc backup"
Successfully deleted: [Folder] "C:\Users\Asus\AppData\Roaming\microsoft\windows\start menu\programs\vopackage"
Successfully deleted: [Folder] "C:\Users\Asus\documents\optimizer pro"
~~~ FireFox
Successfully deleted: [File] C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\g1duac04.default\bprotector_extensions.sqlite
Successfully deleted: [File] C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\g1duac04.default\bprotector_prefs.js
Successfully deleted: [File] C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\g1duac04.default\searchplugins\web search.xml
Successfully deleted: [Folder] C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\g1duac04.default\extensions\faststartff@gmail.com
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions\\faststartff@gmail.com
Successfully deleted the following from C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\g1duac04.default\prefs.js
user_pref("browser.newtab.url", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmy1jzOTjU3bh2prfgUVUg89mWqEo_izsgD9G5gZgHZ3xz3xamVKY4k88ocCFW1Hz75gPIm
user_pref("browser.search.defaultenginename", "Web Search");
user_pref("browser.search.order.1", "Ask.com");
user_pref("browser.search.selectedEngine", "Web Search");
user_pref("browser.startup.homepage", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmy1jzOTjU3bh2prfgUVUg89mWqEo_izsgD9G5gZgHZ3xz3xamVKY4k88ocCFW1Hz
user_pref("extensions.awrigtdamonyahoocom65055.65055.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssfiles.com%22%5D%7D%2C%22d
user_pref("extensions.crossrider.bic", "14929b63cf5313b1e9d55e600306196d");
user_pref("extensions.delta.admin", false);
user_pref("extensions.delta.aflt", "babsst");
user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
user_pref("extensions.delta.autoRvrt", "false");
user_pref("extensions.delta.dfltLng", "de");
user_pref("extensions.delta.excTlbr", false);
user_pref("extensions.delta.ffxUnstlRst", true);
user_pref("extensions.delta.id", "ac971a95000000000000dc85de7829e6");
user_pref("extensions.delta.instlDay", "15933");
user_pref("extensions.delta.instlRef", "sst");
user_pref("extensions.delta.newTab", false);
user_pref("extensions.delta.prdct", "delta");
user_pref("extensions.delta.prtnrId", "delta");
user_pref("extensions.delta.rvrt", "false");
user_pref("extensions.delta.smplGrp", "none");
user_pref("extensions.delta.tlbrId", "base");
user_pref("extensions.delta.tlbrSrchUrl", "");
user_pref("extensions.delta.vrsn", "1.8.24.5");
user_pref("extensions.delta.vrsnTs", "1.8.24.522:49:07");
user_pref("extensions.delta.vrsni", "1.8.24.5");
user_pref("extensions.delta_i.babExt", "");
user_pref("extensions.delta_i.babTrack", "affID=121564&tsp=4976");
user_pref("extensions.delta_i.srcExt", "ss");
user_pref("extensions.helperbar.SmartbarDisabled", false);
user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
user_pref("extensions.helperbar.externalJsFiles", "{\"d\":\"[{\\\"ExcludeDomains\\\":[\\\"snap.do\\\",\\\"snapdo.com\\\",\\\".search.yahoo.com\\\\\\/yhs\\\\\\/search?hspart=lk
user_pref("keyword.URL", "hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJ_Xmy1jzOTjU3bh2prfgUVUg89mWqEo_izsgD9G5gZgHZ3xz3xamVKY4k88ocCFW1Hz75gPImXzxdzBg
Emptied folder: C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\g1duac04.default\minidumps [1 files]
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Asus\appdata\local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Failed to delete: [Folder] C:\Users\Asus\appdata\local\Google\Chrome\User Data\Default\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\pelmeidfhdlhlbjimpabfcbnnojbboma
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.10.2014 at 21:59:33,68
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.10.2014
Suchlauf-Zeit: 11:23:17
Logdatei: Malwarebytes Anti-Malware.txt
Administrator: Ja
Version: 2.00.3.1025
Malware Datenbank: v2014.10.29.03
Rootkit Datenbank: v2014.10.22.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Asus
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 331825
Verstrichene Zeit: 56 Min, 29 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 4
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, , [ef8865b5c8b4eb4b504f80a232d1e020],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [651248d290ec38fe6040f82a649f29d7],
PUP.Optional.Score.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RCORES, , [9dda5ac0a0dcff37fd2e5a4006fe956b],
PUP.Optional.StormWatchApp.A, HKU\S-1-5-21-480692169-2859508237-3514454044-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\StormWatchApp, , [492e1cfe106cf73f995528fb937029d7],
Registrierungswerte: 1
PUP.Optional.Score.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RCORES|ImagePath, C:\Windows\rcore.exe, , [9dda5ac0a0dcff37fd2e5a4006fe956b]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 32
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch, , [4a2d8c8e4e2ee254f893f99f8b79eb15],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\userCode, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\actions, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\popupResource, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_hoidflomjnnnbiemmkjdjkkialmhbago_0, , [1067130776060c2a0245021c44bf23dd],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\defaults, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\defaults\preferences, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\userCode, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\locale, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\locale\en-US, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\Weather_Protector_LLC, , [d1a69d7d225a47ef9773a47c1fe4cb35],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\Weather_Protector_LLC\StormWatch.exe_Url_yxyfyjwhicejy2vn4ggzx12etuvuscrn, , [d1a69d7d225a47ef9773a47c1fe4cb35],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\Weather_Protector_LLC\StormWatch.exe_Url_yxyfyjwhicejy2vn4ggzx12etuvuscrn\1.5.0.0, , [d1a69d7d225a47ef9773a47c1fe4cb35],
PUP.Optional.KrabWeb.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdijnalfcndckfbhkjakjoekpfojjilg, , [66111802512be0567aeb041d748f3ac6],
PUP.Optional.KrabWeb.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdijnalfcndckfbhkjakjoekpfojjilg\1.0.1_0, , [66111802512be0567aeb041d748f3ac6],
Dateien: 199
PUP.Optional.DomaIQ, C:\Users\Asus\AppData\Local\temp\pyxKYXXz.exe.part, , [6b0cd04a423aec4a0f4c510a2cd49868],
PUP.Optional.DomaIQ, C:\Users\Asus\Downloads\Player.exe, , [d5a28d8da7d5c373e97c5801f9078878],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormUpdater.exe, , [b5c28298700ca690944dfbd5ba47dd23],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormWatch.exe, , [d99e4ecce29afc3aa5e496bfee129967],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormWatchappuninstall.exe, , [d6a1dc3e39439c9af693d283c83818e8],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk, , [e592b763d7a50a2c053528fd72918f71],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormWatch.exe.config, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\ICSharpCode.SharpZipLib.dll, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormUpdater.exe.config, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormWatchApp.dat, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\uninstall.exe, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk, , [d1a6cc4ef488da5ce2a856423ec6cc34],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch\Uninstall StormWatch.lnk, , [4a2d8c8e4e2ee254f893f99f8b79eb15],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch\StormWatch.lnk, , [4a2d8c8e4e2ee254f893f99f8b79eb15],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hoidflomjnnnbiemmkjdjkkialmhbago_0.localstorage, , [2552d347136992a4aa4a4157af5517e9],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hoidflomjnnnbiemmkjdjkkialmhbago_0.localstorage-journal, , [db9cd44690ec95a1c232bcdcc34102fe],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\background.html, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\chromeCoreFilesIndex.txt, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\manifest.json, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\popup.html, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\Settings.json, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\manifest.xml, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins.json, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\102.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\104.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\13.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\14.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\17.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\180.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\184.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\19.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\192.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\195.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\220.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\221.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\223.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\233.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\242.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\246.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\260.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\262.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\263.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\267.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\273.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\275.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\281.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\289.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\300.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\4.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\47.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\64.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\7.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\78.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\80.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\9.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\93.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\97.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\userCode\background.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\userCode\extension.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\icon128.png, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\icon16.png, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\icon48.png, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\actions\1.png, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\8c38b1867e7a37eb2684f1ff8c9e6f74.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\9849bad535bb0d405e7cd6bd6e642679.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\main.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\373b2b81a61dfc1707c7d3360da5cb7b.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\91d9e73e3608bbabdfdc5d2407460922.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\be843d0f3c49a76ff54544af0d380d5e.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\dab6a662633f5bedbd1992cc32995a33.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\e401a0135cedf4309c27e0331fcca8be.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\pageAction.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\1b773165715b8c7c195d7705997c01c2.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\2b317f6dbd559ee8ebd0aa114195a2c9.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\44f21bacb6ecdd692f5574eb37c36fd1.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\68196d985e8b168b43b13825b87f2129.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\9c39e0d976d8c35a221a00f999eea6ce.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\a5ca420d400d950dfb575b5290b97aa0.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\app_api.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\b71a2d619545ba9175802831e4bd97af.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\b75a2fe3e23126cfb5fdd73f0b67b0c0.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\ba6f62b0cf7f33d6dd0b67437c4f14aa.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\cfbf0f2dc714391170ec8e45b34217d9.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\f05a46c37b33f0a6d98e34d82fae3afa.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\f08519958e5bd4b96da840c5dccf0684.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\fadc6ffa5b59ea8a20242fc0a87ec1c6.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\ff9108979296864c705905ed5d2f2118.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\installer.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\popupResource\newPopup.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\popupResource\popup.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_hoidflomjnnnbiemmkjdjkkialmhbago_0\4, , [1067130776060c2a0245021c44bf23dd],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome.manifest, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\install.rdf, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\0717e7e0a4796065d2c6905204e074a2.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\50f49305954b10ced99018695c7ff2b1.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\5770a55e13ea7d3c118e8e70ecba3f46.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\77f17b8a0f525767928a7b22111456f2.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\b3414637c8ae06d3de06ff9547fd460c.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\background.html, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\browser.xul, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\dialog.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\f6471e91327a08e669aa0713d5495fde.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\ffCoreFilesIndex.txt, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\options.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\options.xul, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\search_dialog.xul, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\23730203d1e06c43d8947bbe9cf9e496.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\24e66c5d62cd16c5bf37eb4a58c81033.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\3b0e136ea10e2bef5876669b1ad4991f.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\4ce00da023f15c6e9fd132deb89c78eb.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\504a83c95c4afa9b4c4c135ff0183138.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\64aab36458ccb8adbd305c78d33e92ea.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\794ab3031bd0a865652a92678ffee1cc.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\798aed190c9e975c5a8bbc3d502be5b4.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\857cf623870264d7bc66aa595c4d4b9f.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\94490955d3d38d40db8155f4483b7ccb.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\94b4fed1e70ed9ecec19b6c309cb9e6c.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\9fac30a57e10a596d7b8e8f1faa38c48.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\b1de12d6c3093f68ba046f05ead5ac39.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\d3fef9606d1cfe1d163eb40acad99027.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\f00ea27489a8eb5338e8a23e139ba907.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api\fe029e65268178e261f77a8aa295f913.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\b1cb63521b3deea71e7e64419816e830.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\0aa452f3df6f3d8208869a9c55194fb5.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\1f146b5b75dfc44d262c2f1b8970dfeb.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\2543acdf7fe53ff1feb1619504bd0366.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\27156196e35b51d938835ce5ff613969.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\3fade06b37c5310027e42b2a53cc7786.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\55e348ac48decf009fc2cce03697365b.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\6389bb6fdf1c88ef3258c954daebbd7a.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\8d7615d827e4b2d68752c08a54d1314a.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\a4f0a5b79d7cd7b9294b276f83b7190c.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\aa19dd938a9e2b28a6661ee2e4c02cc6.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\ac77d29787b71986e5b140f832f64e9f.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\b1ebdda8c1acb7f2419fa555e6a131eb.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\c09515fc181084f94d1bd333df5bc8b8.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\df059e6beb77b1583bd1ca505bc2b705.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\e4f65cca16838058829fe2d6d7fac60e.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\e9c14e7e40739124a7637689f27d9b34.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\f0b5e35f956c182a437dc3bd9255d447.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\fb6c37acfc7370a149570b6b43b91db8.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\ff1af9140ef17c25231407fc679112c9.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core\installer.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\defaults\preferences\prefs.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\manifest.xml, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins.json, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\102.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\104.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\13.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\14.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\16.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\17.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\180.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\184.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\192.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\195.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\220.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\221.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\223.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\233.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\234.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\242.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\246.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\260.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\262.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\263.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\268.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\273.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\275.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\281.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\289.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\300.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\4.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\47.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\64.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\7.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\78.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\9.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins\93.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\userCode\background.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\userCode\extension.js, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\locale\en-US\translations.dtd, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\button1.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\button2.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\button3.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\button4.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\button5.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\crossrider_statusbar.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\icon128.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\icon16.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\icon24.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\icon48.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\panelarrow-up.png, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\popup.html, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\skin.css, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin\update.css, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\Weather_Protector_LLC\StormWatch.exe_Url_yxyfyjwhicejy2vn4ggzx12etuvuscrn\1.5.0.0\user.config, , [d1a69d7d225a47ef9773a47c1fe4cb35],
PUP.Optional.KrabWeb.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdijnalfcndckfbhkjakjoekpfojjilg\1.0.1_0\icon.png, , [66111802512be0567aeb041d748f3ac6],
PUP.Optional.KrabWeb.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdijnalfcndckfbhkjakjoekpfojjilg\1.0.1_0\manifest.json, , [66111802512be0567aeb041d748f3ac6],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
Teil 1
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.10.2014
Suchlauf-Zeit: 11:23:17
Logdatei: Malwarebytes Anti-Malware.txt
Administrator: Ja
Version: 2.00.3.1025
Malware Datenbank: v2014.10.29.03
Rootkit Datenbank: v2014.10.22.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Asus
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 331825
Verstrichene Zeit: 56 Min, 29 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 4
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, , [ef8865b5c8b4eb4b504f80a232d1e020],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [651248d290ec38fe6040f82a649f29d7],
PUP.Optional.Score.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RCORES, , [9dda5ac0a0dcff37fd2e5a4006fe956b],
PUP.Optional.StormWatchApp.A, HKU\S-1-5-21-480692169-2859508237-3514454044-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\StormWatchApp, , [492e1cfe106cf73f995528fb937029d7],
Registrierungswerte: 1
PUP.Optional.Score.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RCORES|ImagePath, C:\Windows\rcore.exe, , [9dda5ac0a0dcff37fd2e5a4006fe956b]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 32
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch, , [4a2d8c8e4e2ee254f893f99f8b79eb15],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\userCode, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\actions, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\popupResource, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_hoidflomjnnnbiemmkjdjkkialmhbago_0, , [1067130776060c2a0245021c44bf23dd],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\api, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\chrome\content\core, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\defaults, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\defaults\preferences, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\plugins, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\extensionData\userCode, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\locale, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\locale\en-US, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\g1duac04.default\extensions\wrigtdamon@yahoo.com\skin, , [84f3eb2f96e6a1951236de4014ef9e62],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\Weather_Protector_LLC, , [d1a69d7d225a47ef9773a47c1fe4cb35],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\Weather_Protector_LLC\StormWatch.exe_Url_yxyfyjwhicejy2vn4ggzx12etuvuscrn, , [d1a69d7d225a47ef9773a47c1fe4cb35],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\Weather_Protector_LLC\StormWatch.exe_Url_yxyfyjwhicejy2vn4ggzx12etuvuscrn\1.5.0.0, , [d1a69d7d225a47ef9773a47c1fe4cb35],
PUP.Optional.KrabWeb.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdijnalfcndckfbhkjakjoekpfojjilg, , [66111802512be0567aeb041d748f3ac6],
PUP.Optional.KrabWeb.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdijnalfcndckfbhkjakjoekpfojjilg\1.0.1_0, , [66111802512be0567aeb041d748f3ac6],
Dateien: 199
PUP.Optional.DomaIQ, C:\Users\Asus\AppData\Local\temp\pyxKYXXz.exe.part, , [6b0cd04a423aec4a0f4c510a2cd49868],
PUP.Optional.DomaIQ, C:\Users\Asus\Downloads\Player.exe, , [d5a28d8da7d5c373e97c5801f9078878],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormUpdater.exe, , [b5c28298700ca690944dfbd5ba47dd23],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormWatch.exe, , [d99e4ecce29afc3aa5e496bfee129967],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormWatchappuninstall.exe, , [d6a1dc3e39439c9af693d283c83818e8],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatch.lnk, , [e592b763d7a50a2c053528fd72918f71],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormWatch.exe.config, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\ICSharpCode.SharpZipLib.dll, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormUpdater.exe.config, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\StormWatchApp.dat, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Local\StormWatch\uninstall.exe, , [64137e9c720a6fc7f645c85d966d45bb],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\StormWatchApp.lnk, , [d1a6cc4ef488da5ce2a856423ec6cc34],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch\Uninstall StormWatch.lnk, , [4a2d8c8e4e2ee254f893f99f8b79eb15],
PUP.Optional.StormWatch.A, C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormWatch\StormWatch.lnk, , [4a2d8c8e4e2ee254f893f99f8b79eb15],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hoidflomjnnnbiemmkjdjkkialmhbago_0.localstorage, , [2552d347136992a4aa4a4157af5517e9],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_hoidflomjnnnbiemmkjdjkkialmhbago_0.localstorage-journal, , [db9cd44690ec95a1c232bcdcc34102fe],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\background.html, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\chromeCoreFilesIndex.txt, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\manifest.json, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\popup.html, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\Settings.json, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\manifest.xml, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins.json, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\102.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\104.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\13.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\14.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\17.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\180.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\184.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\19.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\192.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\195.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\220.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\221.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\223.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\233.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\242.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\246.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\260.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\262.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\263.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\267.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\273.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\275.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\281.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\289.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\300.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\4.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\47.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\64.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\7.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\78.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\80.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\9.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\93.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\plugins\97.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\userCode\background.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\extensionData\userCode\extension.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\icon128.png, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\icon16.png, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\icon48.png, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\icons\actions\1.png, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\8c38b1867e7a37eb2684f1ff8c9e6f74.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\9849bad535bb0d405e7cd6bd6e642679.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\main.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\373b2b81a61dfc1707c7d3360da5cb7b.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\91d9e73e3608bbabdfdc5d2407460922.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\be843d0f3c49a76ff54544af0d380d5e.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\dab6a662633f5bedbd1992cc32995a33.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\e401a0135cedf4309c27e0331fcca8be.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\api\pageAction.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\1b773165715b8c7c195d7705997c01c2.js, , [5c1b2ded106c91a565e0af6f61a2a55b],
PUP.Optional.CrossRider.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.12_0\js\lib\2b317f6dbd559ee8ebd0aa114195a2c9.js, , [5c1b2ded106c91a565e0af6f61a2a55b], |