Hallo schrauber,
vielen Dank für deine schnelle Antwort.
Ich habe alle deine Aufgaben durchgeführt. Hier die Ergebnisse:
mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 11.02.2015
Suchlauf-Zeit: 09:13:35
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.02.11.02
Rootkit Datenbank: v2015.02.03.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: *****
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 366239
Verstrichene Zeit: 12 Min, 31 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 11
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1420, Löschen bei Neustart, [bf6f938af79380b622a495d113ed9c64]
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, 1800, Löschen bei Neustart, [f638c35ae4a60f277cb09476020020e0]
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\a162695d-a4cd-4799-8ccf-c85d41a9164e-1-6.exe, 1260, Löschen bei Neustart, [a9855cc17f0b7fb72ba4805753ae44bc]
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\a162695d-a4cd-4799-8ccf-c85d41a9164e-6.exe, 2784, Löschen bei Neustart, [022cf12cfb8f4fe71db29443ba476799]
Adware.BackAd, C:\Users\*****\AppData\Local\wincheck\wincheck.exe, 5652, Löschen bei Neustart, [3cf24bd25b2fa19597aaa607a65f7090]
PUP.Optional.WinCheck.A, C:\Users\*****\AppData\Local\wincheck\wincheck.exe, 5652, Löschen bei Neustart, [0727859855350234d504a1eba95ae11f]
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, 3876, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8]
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\HPNotify.exe, 4516, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8]
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\Service\pfsvc.exe, 1316, Löschen bei Neustart, [36f845d8bad058de047f89013cc79a66]
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\GameHugArcade.exe, 2188, Löschen bei Neustart, [35f9170617730a2c2971f6962bd835cb]
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\GameHugArcadeApp.exe, 5644, Löschen bei Neustart, [26088f8ea6e4ee488bfcec9a41c2ef11]
Module: 10
PUP.Optional.Nova.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\17757348-a72f-46d9-b551-3912cf6c06da.dll, Löschen bei Neustart, [909eb568622885b1c722f412639fa759],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowerWatchCH.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowserAction.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\IeWatchDog.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
Registrierungsschlüssel: 61
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [bf6f938af79380b622a495d113ed9c64],
PUP.Optional.XTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, In Quarantäne, [f638c35ae4a60f277cb09476020020e0],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [8ca25ebfb3d70c2a9963897e27dcd22e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [8ca25ebfb3d70c2a9963897e27dcd22e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [8ca25ebfb3d70c2a9963897e27dcd22e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [8ca25ebfb3d70c2a9963897e27dcd22e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [8ca25ebfb3d70c2a9963897e27dcd22e],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [8ca25ebfb3d70c2a9963897e27dcd22e],
PUP.Optional.PhraseFinder.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\PhraseFinder_1.10.0.8, In Quarantäne, [a886be5f78122313e739eb311be77987],
PUP.Optional.PhraseFinder.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pfnfd_1_10_0_8, In Quarantäne, [3ef059c45a307abc95f0b7d356ad966a],
PUP.Optional.WinCheck.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\wincheck, In Quarantäne, [0727859855350234d504a1eba95ae11f],
PUP.Optional.Flashbeat.A, HKLM\SOFTWARE\Flashbeat, In Quarantäne, [ef3fd24b5139a78f7cbf8702b350649c],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [210d62bb4842ff37e125388f24df748c],
PUP.Optional.Flashbeat.A, HKLM\SOFTWARE\WOW6432NODE\Flashbeat, In Quarantäne, [dd51b469fc8ec571013a0a7ff80b49b7],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\HD-Quality-3.1V06.02, In Quarantäne, [b47aaf6ef694b383dce97c1f996a1be5],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\HD-Quality-3.1V06.02-nv, In Quarantäne, [4de1988551393bfbf3d23a61e51e4ab6],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\HD-Quality-3.1V06.02-nv-ie, In Quarantäne, [f23c1805721836006263b5e6cd36619f],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, In Quarantäne, [9599ea33b1d92214b3f5b2dcfa0955ab],
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, In Quarantäne, [ea4419041c6e4aec4a380a8c8b78fd03],
PUP.Optional.PhraseFinder.A, HKLM\SOFTWARE\WOW6432NODE\PhraseFinder_1.10.0.8, In Quarantäne, [3df1b568a4e65fd74a3c206a23e07b85],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [ad81cb52a3e7e94da36653b652b3f60a],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, In Quarantäne, [cc62ce4f6c1ef343b2a694187192a858],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [ad81d24bb8d21d195fa7289fe122cc34],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [230b28f5107a71c5d1f8f40020e4d62a],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [fb33110cd5b5c96d3396b65513f2847c],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [d35b50cd6f1b75c1efdb0308b94c28d8],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [250956c7008ae15576fe871d4cb7b34d],
PUP.Optional.PhraseFinder.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\pfsvc_1.10.0.8, In Quarantäne, [36f845d8bad058de047f89013cc79a66],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [a18d76a7c7c379bd60499801ca39649c],
PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HD-Quality-3.1V06.02-nv, In Quarantäne, [e8469489197167cf3a8ca0fbcc3747b9],
PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HD-Quality-3.1V06.02-nv-ie, In Quarantäne, [70be58c51e6c4de9f7cff4a79c67926e],
PUP.Optional.ClicUp.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\clicup, In Quarantäne, [97970419f4962115f74efe8ee41f6f91],
PUP.Optional.GameHugArcade.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GameHug, In Quarantäne, [cd613ae31b6f82b42bcdb5d617ec738d],
PUP.Optional.GameHugArcade.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GameHugArcadeApp, In Quarantäne, [2905ad702c5efb3be41699f2a85b847c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HD-Quality-3.1V06.02, In Quarantäne, [fe30b568771352e475513d5e2bd88f71],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HD-Quality-3.1V06.02-nv, In Quarantäne, [909e57c63852d462dee8742728db03fd],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\HD-Quality-3.1V06.02-nv-ie, In Quarantäne, [fd319588c6c41521d7ef7a2150b311ef],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [bb738499c1c978be9fc3f80512f25aa6],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [929c021b494144f26ac2577c06fdd52b],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [949aa578503a40f606385495a75d2cd4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [54daf12cd6b43df9801337694db6629e],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\HD-Quality-3.1V06.02, In Quarantäne, [e34baa73d0ba280ef22bf3a2af54bc44],
PUP.Optional.Qone8, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [fd3139e41971dd595b6df8fcf3113fc1],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.HDQuality.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\HD-Quality-3.1V06.02, In Quarantäne, [0c22819c4b3f52e4d8eac6a829da08f8],
PUP.Optional.GameHugArcade.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\GameHugArcade, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
Registrierungswerte: 6
Adware.BackAd, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinCheck, C:\Users\*****\AppData\Local\wincheck\wincheck.exe, In Quarantäne, [3cf24bd25b2fa19597aaa607a65f7090]
PUP.Optional.WinCheck.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|WinCheck, C:\Users\*****\AppData\Local\wincheck\wincheck.exe, In Quarantäne, [0727859855350234d504a1eba95ae11f]
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [cc62ce4f6c1ef343b2a694187192a858]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, ium6, In Quarantäne, [250956c7008ae15576fe871d4cb7b34d]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0R1F2W1N1D1S0C1F1I1R, In Quarantäne, [949aa578503a40f606385495a75d2cd4]
PUP.Optional.GameHugArcade.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|GameHug Arcade, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\GameHugArcade.exe /b, In Quarantäne, [35f9170617730a2c2971f6962bd835cb]
Registrierungsdaten: 15
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\GOOGLE CHROME\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://www.mystartsearch.com/?type=sc&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (Chrome.exe), Schlecht: ("C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://www.mystartsearch.com/?type=sc&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[e44a2cf1d8b243f3a5c26d417590cd33]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[29055fbe67234cea55106a449d68a957]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010&q={searchTerms}),Ersetzt,[aa843edfe3a70234d5da753949bc629e]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[08263ae33c4e8da9703e4e6050b5867a]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[5fcf8b923d4dc373fa3d74483dc833cd]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010&q={searchTerms}),Ersetzt,[68c667b63d4d71c5dcd4e7c7b64f2bd5]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\GOOGLE CHROME\SHELL\OPEN\COMMAND, "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://www.mystartsearch.com/?type=sc&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (Chrome.exe), Schlecht: ("C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://www.mystartsearch.com/?type=sc&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[ab83a07d7317c86edc8b604e11f4bf41]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[f43a819cd8b250e665004f5f26df857b]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010&q={searchTerms}),Ersetzt,[1f0fb667e7a3d75fcde27c3259acef11]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[4fdfac71afdbfd39208e921ca65f728e]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[7eb03be29febff37bf7855670ef70af6]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010&q={searchTerms}),Ersetzt,[d45a8f8e8901e452961a6945030223dd]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[ee407ca190facf6796e80ab06e97a15f]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[f23ca17c5634e353fe37645842c36f91]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2600528798-198841283-459962802-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010),Ersetzt,[de505ac3bcce2e08159cdad436cfb24e]
Ordner: 51
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeatData, In Quarantäne, [44ea99846f1bce687ac26c1e18eb8e72],
PUP.Optional.WinCheck.A, C:\Users\*****\AppData\Local\wincheck, Löschen bei Neustart, [0727859855350234d504a1eba95ae11f],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\image, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [78b6b16c53371323a2927eead42f9b65],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [78b6b16c53371323a2927eead42f9b65],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{91F80829-68F3-4C51-9107-89A80AE0219D}, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02, Löschen bei Neustart, [0c22819c4b3f52e4d8eac6a829da08f8],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, In Quarantäne, [56d805183b4f1e1809cb4143d1329c64],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, In Quarantäne, [56d805183b4f1e1809cb4143d1329c64],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade\locales, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade\plugin, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade, Löschen bei Neustart, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade, Löschen bei Neustart, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\toolbaricons, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameHug Arcade, In Quarantäne, [e5493fde692153e36028d9adb44f2fd1],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8, Löschen bei Neustart, [5bd349d4ddade35361e75434a75c916f],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\3rd Party Licenses, In Quarantäne, [5bd349d4ddade35361e75434a75c916f],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\Service, Löschen bei Neustart, [5bd349d4ddade35361e75434a75c916f],
Dateien: 189
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [bf6f938af79380b622a495d113ed9c64],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, Löschen bei Neustart, [f638c35ae4a60f277cb09476020020e0],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\a162695d-a4cd-4799-8ccf-c85d41a9164e-1-6.exe, Löschen bei Neustart, [a9855cc17f0b7fb72ba4805753ae44bc],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\a162695d-a4cd-4799-8ccf-c85d41a9164e-6.exe, Löschen bei Neustart, [022cf12cfb8f4fe71db29443ba476799],
PUP.Optional.Nova.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\17757348-a72f-46d9-b551-3912cf6c06da.dll, Löschen bei Neustart, [909eb568622885b1c722f412639fa759],
Adware.BackAd, C:\Users\*****\AppData\Local\wincheck\wincheck.exe, Löschen bei Neustart, [3cf24bd25b2fa19597aaa607a65f7090],
PUP.Optional.SupTab.A, C:\Program Files (x86)\XTab\SupTab.dll, In Quarantäne, [8ca25ebfb3d70c2a9963897e27dcd22e],
PUP.Optional.Nova.A, C:\Program Files (x86)\14e045d6-fe1c-4ded-abc7-9e94deb70b05\57f2b51c-bee4-416c-b34b-ee1fbc2c8d43.dll, In Quarantäne, [54dada436129b97d49a027dfc63cf30d],
PUP.Optional.Nova.A, C:\Program Files (x86)\AmIcoSingLun\775fbdf8-0715-4dab-a6f3-c846c258cdb0.dll, In Quarantäne, [58d6e43951391b1b47a222e4a85a24dc],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\a162695d-a4cd-4799-8ccf-c85d41a9164e-1-7.exe, In Quarantäne, [89a547d62466c3739c336e69f30e8a76],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\a162695d-a4cd-4799-8ccf-c85d41a9164e-10.exe, In Quarantäne, [7db175a83555c76ff2dd696eba47c838],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\a162695d-a4cd-4799-8ccf-c85d41a9164e-5.exe, In Quarantäne, [88a653ca66246dc997380ec98f72946c],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\a162695d-a4cd-4799-8ccf-c85d41a9164e-64.exe, In Quarantäne, [5dd169b4602af343d1feba1d70910ff1],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\a162695d-a4cd-4799-8ccf-c85d41a9164e-7.exe, In Quarantäne, [f23c2cf19eec0b2bc20de2f54cb58b75],
PUP.Optional.CrossRider.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\utils.exe, In Quarantäne, [1e10c459e0aa082ec0ad80ccd72948b8],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\Uninstall.exe, In Quarantäne, [a886be5f78122313e739eb311be77987],
Adware.BackAd, C:\Users\*****\AppData\Local\Temp\nst90CE.tmp, In Quarantäne, [ce601409ed9daa8c79c803aa0500639d],
PUP.Optional.PhraseFinder.A, C:\Users\*****\AppData\Local\Temp\is45637729\428650144_stp\phrasefinder-setup-1.10.0.8.exe, In Quarantäne, [0d21839acac0bc7a45dbbe5eca3858a8],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeatData\Config.bin, In Quarantäne, [44ea99846f1bce687ac26c1e18eb8e72],
PUP.Optional.PhraseFinder.A, C:\Windows\System32\drivers\pfnfd_1_10_0_8.sys, In Quarantäne, [3ef059c45a307abc95f0b7d356ad966a],
PUP.Optional.SelectNGo.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage, In Quarantäne, [9c9277a60b7f6ec89ba9513a887b50b0],
PUP.Optional.SelectNGo.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.selectgo00.selectgo.net_0.localstorage-journal, In Quarantäne, [7db1cc5196f4fe383e06612a14ef7b85],
PUP.Optional.WebsSearches.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage, In Quarantäne, [7bb324f9c4c64aecb7dccbc15ca729d7],
PUP.Optional.WebsSearches.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage-journal, In Quarantäne, [3af4d24b602a40f6f2a1424ad0333ec2],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameHugArcadeApp.lnk, In Quarantäne, [45e98d90305a13235c3ddbb18281e21e],
PUP.Optional.Patsearch.A, C:\Windows\patsearch.bin, In Quarantäne, [8ea016078dfde74fe5f07418b64dc53b],
PUP.Optional.WinCheck.A, C:\Users\*****\AppData\Local\wincheck\wincheck.exe, Löschen bei Neustart, [0727859855350234d504a1eba95ae11f],
PUP.Optional.WinCheck.A, C:\Users\*****\AppData\Local\wincheck\Uninstall.exe, In Quarantäne, [0727859855350234d504a1eba95ae11f],
PUP.Optional.WebInstr.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrT_01009.Wdf, In Quarantäne, [ca640f0e2a60ef476994bcd1e61db749],
PUP.Optional.MyStartSearch.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage, Löschen bei Neustart, [c26c17069bef69cd987babe3e81b0ef2],
PUP.Optional.MyStartSearch.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage-journal, Löschen bei Neustart, [220cd746a9e1dc5a1ff4d7b7857e2ad6],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\uninstall.exe, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowerWatchCH.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowerWatchFF.dll, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\BrowserAction.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\conf, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ffsearch_toolbar!1.0.0.1025.xpi, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\HPNotify.exe, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\IeWatchDog.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\install.data, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\searchProvider.xml, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about_bk.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn_apply.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\close.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf.xml, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf_back.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\input_bk.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\logo.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\main.xml, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_1.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_2.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\rigth_arrow.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\settings.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\data.html, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE.html, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE8.html, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\main.css, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\ver.txt, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\arrow.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo_hover.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_logo.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo2.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\google_trends.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon128.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon16.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon48.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\loading.gif, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\logo32.ico, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather\0.png, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\common.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ga.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ie8.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery.autocomplete.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\js.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\library.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit-ie8.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit2.0.js, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW\messages.json, In Quarantäne, [cc6261bc1e6c01350b9e9ef02ed558a8],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-1-6, In Quarantäne, [3bf364b9226885b1c0937a3217ec3dc3],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-1-7, In Quarantäne, [5dd1c756abdf043221321a9263a0639d],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-10_user, In Quarantäne, [72bc6bb26129132389ca8c20f40f1fe1],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-5, In Quarantäne, [250906178efc6bcbbe953874c83ba957],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-5_user, In Quarantäne, [df4f30edb1d9b97d61f2e9c3ed16ba46],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-6, In Quarantäne, [0f1f52cb0b7f5cdaf3602e7e4ab9bc44],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-7, In Quarantäne, [ac82a47999f1b6805bf8cce062a127d9],
PUP.Optional.SelectNGo.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage, Löschen bei Neustart, [a48ad34a2d5dde58f257b8004ab9d62a],
PUP.Optional.SelectNGo.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal, Löschen bei Neustart, [d15d6bb2157584b25fea1b9d40c3c33d],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-1-6.job, In Quarantäne, [e44a77a6cfbb55e11f827d8c5fa6b749],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-1-7.job, In Quarantäne, [9599001d701a61d5dac745c425e01ce4],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-10_user.job, In Quarantäne, [9f8f60bdcfbb60d6ecb506030df8837d],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-5.job, In Quarantäne, [6cc269b48bff59dd9b06dd2c58adc43c],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-5_user.job, In Quarantäne, [34fac55856343204524fb15806ffa957],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-6.job, In Quarantäne, [b27c77a6701a4aec7c25a8610ef7f709],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\a162695d-a4cd-4799-8ccf-c85d41a9164e-7.job, In Quarantäne, [2a0442dbdcaeed49366b8e7b50b55ba5],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, In Quarantäne, [c9658a934248f541ebc5cd3c0500cb35],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, In Quarantäne, [6cc24dd05a30b482228fff0a8283d32d],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, In Quarantäne, [aa8425f8028803336e448782d72ef20e],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, In Quarantäne, [c5696ab3206adf57991ad8310ef7639d],
PUP.Optional.ReMarkable.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, Löschen bei Neustart, [81ada4792862c07609d54ac339cc2fd1],
PUP.Optional.ReMarkable.A, C:\Users\*****\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, Löschen bei Neustart, [cc622cf1ddad42f46b7356b7d5300ef2],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMedia.ini, In Quarantäne, [de50011c0585ae880248e925867f926e],
PUP.Optional.ColorMedia.A, C:\Windows\System32\ColorMediaOff.ini, In Quarantäne, [51dd70adc0caef47e269af5fe81ded13],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMediaOff.ini, In Quarantäne, [37f7928b7b0f1c1a5bf049c51ee7bc44],
PUP.Optional.Vitruvian.A, C:\Users\*****\AppData\Local\Temp\vitruvian-installer-hardwareprofile-v0001, In Quarantäne, [b37bbf5e404a2610170edb3754b11de3],
PUP.Optional.Vitruvian.A, C:\Users\*****\AppData\Local\Temp\vitruvian-installer-install-v0003, In Quarantäne, [c06efc216c1e4fe7f92cbc56f213629e],
PUP.Optional.Vitruvian.A, C:\Users\*****\AppData\Local\Temp\vitruvian-installer-processes-v0002, In Quarantäne, [111d8d90f6946dc9d154b85ab253a759],
PUP.Optional.Vitruvian.A, C:\Users\*****\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, In Quarantäne, [ff2f938a5337989ed84dc34f14f1e31d],
PUP.Optional.Vitruvian.A, C:\Users\*****\AppData\Local\Temp\vitruvian-installer-softwareregkeys-v0002, In Quarantäne, [b07ea37a751563d395909c76f015659b],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\Service\pfsvc.exe, Löschen bei Neustart, [36f845d8bad058de047f89013cc79a66],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\GameHugArcade.exe, Löschen bei Neustart, [35f9170617730a2c2971f6962bd835cb],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, In Quarantäne, [2707ee2f4f3b5ed8e62088e21ae908f8],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\GoogleCrashHandler.exe, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\GoogleUpdate.exe, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\GoogleUpdateBroker.exe, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\GoogleUpdateHelper.msi, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\GoogleUpdateOnDemand.exe, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\goopdate.dll, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\goopdateres_en.dll, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\npGoogleUpdate4.dll, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\psmachine.dll, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.GlobalUpdate.A, C:\Users\*****\AppData\Local\Temp\comh.224517\psuser.dll, In Quarantäne, [ec4270ad1872f145ad7575f5ae559769],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\16643110-ba96-4570-9cda-322417ded1aa.dll, In Quarantäne, [0c22819c4b3f52e4d8eac6a829da08f8],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\bgNova.html, In Quarantäne, [0c22819c4b3f52e4d8eac6a829da08f8],
PUP.Optional.HDQuality.A, C:\Program Files (x86)\HD-Quality-3.1V06.02\Uninstall.exe, In Quarantäne, [0c22819c4b3f52e4d8eac6a829da08f8],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade\ffmpegsumo.dll, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade\GameHugArcadeApp.dat, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade\GameHugArcadeBrowser.exe, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade\icudt.dll, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade\libcef.dll, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade\locales\en-US.pak, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Local\GameHugArcade\plugin\npswf32.dll, In Quarantäne, [71bd8b92b1d9b086baccdaac28db936d],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\desktop.ico, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\GameHugArcadeApp.exe, Löschen bei Neustart, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\GameHugArcadeappuninstall.exe, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\toolbarmenu.xml, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\topwebsites.xml, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\uninstall.exe, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\toolbaricons\amazon-58x21.jpg, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\toolbaricons\amazon-58x21.jpg.valid, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\toolbaricons\logoEbay-58x21.jpg, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\GameHugArcade\GameHug Arcade\toolbaricons\logoEbay-58x21.jpg.valid, In Quarantäne, [26088f8ea6e4ee488bfcec9a41c2ef11],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameHug Arcade\GameHug Arcade.lnk, In Quarantäne, [e5493fde692153e36028d9adb44f2fd1],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameHug Arcade\Uninstall GameHugArcade.lnk, In Quarantäne, [e5493fde692153e36028d9adb44f2fd1],
PUP.Optional.GameHugArcade.A, C:\Users\*****\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameHug Arcade\www.gamehug.com.url, In Quarantäne, [e5493fde692153e36028d9adb44f2fd1],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\terms-of-service.rtf, In Quarantäne, [5bd349d4ddade35361e75434a75c916f],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\3rd Party Licenses\buildcrx-license.txt, In Quarantäne, [5bd349d4ddade35361e75434a75c916f],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\3rd Party Licenses\Info-ZIP-license.txt, In Quarantäne, [5bd349d4ddade35361e75434a75c916f],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\3rd Party Licenses\JSON-simple-license.txt, In Quarantäne, [5bd349d4ddade35361e75434a75c916f],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\3rd Party Licenses\nsJSON-license.txt, In Quarantäne, [5bd349d4ddade35361e75434a75c916f],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\3rd Party Licenses\Nustache-license.txt, In Quarantäne, [5bd349d4ddade35361e75434a75c916f],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\3rd Party Licenses\TaskScheduler-license.txt, In Quarantäne, [5bd349d4ddade35361e75434a75c916f],
PUP.Optional.PhraseFinder.A, C:\Program Files (x86)\PhraseFinder_1.10.0.8\3rd Party Licenses\UAC-license.txt, In Quarantäne, [5bd349d4ddade35361e75434a75c916f],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) awd; Code:
# AdwCleaner v4.110 - Bericht erstellt 11/02/2015 um 09:41:45
# Aktualisiert 05/02/2015 von Xplode
# Datenbank : 2015-02-05.2 [Lokal]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : ****** - ARBEITS-PC
# Gestarted von : C:\Users\******\Downloads\AdwCleaner_4.110.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\aa3dbf4110b343089a47d5931408bfc6
Ordner Gelöscht : C:\Program Files (x86)\AnyProtectEx
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Users\******\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\******\AppData\Roaming\AnyProtectEx
Ordner Gelöscht : C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyProtect PC Backup
Datei Gelöscht : C:\Users\******\AppData\Local\Temp\Uninstall.exe
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_searches.vi-view.com_0.localstorage-journal
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.select-n-go00.select-n-go.com_0.localstorage-journal
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_searches.vi-view.com_0.localstorage
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage
Datei Gelöscht : C:\Users\******\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.mystartsearch.com_0.localstorage-journal
***** [ Geplante Tasks ] *****
Task Gelöscht : APSnotifierPP1
Task Gelöscht : APSnotifierPP2
Task Gelöscht : APSnotifierPP3
Task Gelöscht : LaunchSignup
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\******\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\******\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\******\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{293B36D2-70C5-4F99-959E-3B71D65A13F3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{56A7E625-FC34-47CE-B677-585B0CD702A9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InetStat
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\SupDp
Schlüssel Gelöscht : HKLM\SOFTWARE\Tutorials
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Google Chrome v40.0.2214.111
*************************
AdwCleaner[R0].txt - [9218 Bytes] - [11/02/2015 09:38:48]
AdwCleaner[S0].txt - [8824 Bytes] - [11/02/2015 09:41:45]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8883 Bytes] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 8.1 x64
Ran by ******* on 11.02.2015 at 9:46:19,78
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\*******\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\*******\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal"
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.02.2015 at 9:48:08,47
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und ein neues FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015
Ran by ******* (administrator) on ARBEITS-PC on 11-02-2015 09:48:59
Running from C:\Users\*******\Downloads
Loaded Profiles: ******* (Available profiles: *******)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Dell) C:\Users\*******\AppData\Local\Apps\2.0\VEVVJTZO.70K\H0QG9PGA.D5W\dell..tion_e30b47f5d4a30e9e_0005.000d_4ab2a66cfade09be\DellSystemDetect.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331STI.EXE
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.26.9\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE
(PFU LIMITED) C:\Program Files (x86)\PFU\ScanSnap\SSFolder\SSFolderTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13538376 2013-05-13] (Realtek Semiconductor)
HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [373760 2012-07-20] (Alcor Micro Corp.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-01-27] (Apple Inc.)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331STI.EXE [548864 2012-08-30] (Vimicro)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-04] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [193568 2014-11-28] (Geek Software GmbH)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2600528798-198841283-459962802-1003\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2014-10-17] (Apple Inc.)
HKU\S-1-5-21-2600528798-198841283-459962802-1003\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [6501656 2014-10-23] (Piriform Ltd)
HKU\S-1-5-21-2600528798-198841283-459962802-1003\...\Run: [GoogleChromeAutoLaunch_BD891974AD4CE6B836D70E22CD229740] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-04] (Google Inc.)
HKU\S-1-5-21-2600528798-198841283-459962802-1003\...\Run: [DellSystemDetect] => C:\Users\*******\AppData\Local\Apps\2.0\VEVVJTZO.70K\H0QG9PGA.D5W\dell..tion_e30b47f5d4a30e9e_0005.000d_4ab2a66cfade09be\DellSystemDetect.exe [276776 2014-12-15] (Dell)
HKU\S-1-5-21-2600528798-198841283-459962802-1003\...\MountPoints2: {6f5b1200-7237-11e4-824f-806e6f6e6963} - "E:\Produkte-CD_Version_10_14.exe"
AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll File Not Found
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
Startup: C:\Users\*******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-2600528798-198841283-459962802-1003\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-2600528798-198841283-459962802-1003\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3331213&octid=EB_ORIGINAL_CTID&ISID=MFA23F85E-7CC6-4E75-9750-1797F939DE69&SearchSource=55&CUI=&UM=6&UP=SPEAAAD01C-C8F9-42C4-8E14-8183347D4730&SSPV=
CHR StartupUrls: Default -> "hxxp://google.de/", "hxxp://istart.webssearches.com/?type=hp&ts=1416608086&from=brd&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010", "hxxp://www.mystartsearch.com/?type=hp&ts=1423220646&from=ium6&uid=ST500LM012XHN-M500MBB_S2R7J9AD306010", "?type=hppp"
CHR DefaultSearchKeyword: Default ->
CHR DefaultSearchURL: Default -> web/?type=dspp&q={searchTerms}
CHR Profile: C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Präsentationen) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-12-01]
CHR Extension: (Google Docs) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-01]
CHR Extension: (Google Drive) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-01]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-12-01]
CHR Extension: (YouTube) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-01]
CHR Extension: (Google-Suche) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-01]
CHR Extension: (efjjgphedlaihnlgaibiaihhmhaejjdd) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\efjjgphedlaihnlgaibiaihhmhaejjdd [2015-02-10]
CHR Extension: (Google Tabellen) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-01]
CHR Extension: (Google Wallet) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-01]
CHR Extension: (20-20 3D Viewer for IKEA) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfhldcakmgpmglboaclpfdedehjblalp [2015-01-04]
CHR Extension: (Google Mail) - C:\Users\*******\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-01]
StartMenuInternet: Google Chrome - Chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [957816 2012-10-21] (Broadcom Corporation.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-01] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1854056 2012-12-07] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-11-22] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-11-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [6957744 2013-12-22] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-09-24] (Microsoft Corporation)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-11] (Malwarebytes Corporation)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2014-08-15] (Apple, Inc.) [File not signed]
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [981112 2012-09-05] (Vimicro Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-11-22] (Microsoft Corporation)
S2 DgiVecp; \??\C:\WINDOWS\system32\Drivers\DgiVecp.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-11 09:48 - 2015-02-11 09:48 - 00000920 _____ () C:\Users\*******\Desktop\JRT2.txt
2015-02-11 09:48 - 2015-02-11 09:48 - 00000920 _____ () C:\Users\*******\Desktop\JRT.txt
2015-02-11 09:45 - 2015-02-11 09:46 - 01388274 _____ (Thisisu) C:\Users\*******\Downloads\JRT.exe
2015-02-11 09:44 - 2015-02-11 09:44 - 00008967 _____ () C:\Users\*******\Desktop\AdwCleaner[S0].txt
2015-02-11 09:38 - 2015-02-11 09:38 - 00000000 ____D () C:\Users\*******\Desktop\1
2015-02-11 09:37 - 2015-02-11 09:37 - 00055670 _____ () C:\Users\*******\Desktop\mbam.txt
2015-02-11 09:16 - 2015-02-11 09:41 - 00000000 ____D () C:\AdwCleaner
2015-02-11 09:15 - 2015-02-11 09:15 - 02112512 _____ () C:\Users\*******\Downloads\AdwCleaner_4.110.exe
2015-02-11 09:08 - 2015-02-11 09:08 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\*******\Downloads\revosetup95.exe
2015-02-11 09:08 - 2015-02-11 09:08 - 00001286 _____ () C:\Users\*******\Desktop\Revo Uninstaller.lnk
2015-02-11 09:08 - 2015-02-11 09:08 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-11 06:34 - 2015-01-19 19:42 - 01487976 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2015-02-11 06:34 - 2015-01-15 23:43 - 00563504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-02-11 06:34 - 2015-01-15 23:43 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-02-11 06:34 - 2015-01-14 05:22 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-02-11 06:34 - 2015-01-14 04:53 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-02-11 06:34 - 2015-01-13 23:11 - 01762840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-02-11 06:34 - 2015-01-13 23:04 - 01489072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-02-11 06:34 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-02-11 06:34 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-02-11 06:34 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-02-11 06:34 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-02-11 06:34 - 2015-01-12 03:34 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-02-11 06:34 - 2015-01-12 03:32 - 06041088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-02-11 06:34 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-02-11 06:34 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-02-11 06:34 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-02-11 06:34 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-02-11 06:34 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-02-11 06:34 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-02-11 06:34 - 2015-01-12 02:58 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-02-11 06:34 - 2015-01-12 02:55 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-02-11 06:34 - 2015-01-12 02:51 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-02-11 06:34 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-02-11 06:34 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-02-11 06:34 - 2015-01-12 02:48 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-02-11 06:34 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-02-11 06:34 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2015-02-11 06:34 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-02-11 06:34 - 2015-01-12 02:34 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-02-11 06:34 - 2015-01-12 02:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-02-11 06:34 - 2015-01-12 02:29 - 04300800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-02-11 06:34 - 2015-01-12 02:27 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-02-11 06:34 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-02-11 06:34 - 2015-01-12 02:25 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-02-11 06:34 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-02-11 06:34 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-02-11 06:34 - 2015-01-12 02:23 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-02-11 06:34 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-02-11 06:34 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-02-11 06:34 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-02-11 06:34 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-02-11 06:34 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-02-11 06:34 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-02-11 06:34 - 2015-01-10 10:10 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-02-11 06:34 - 2015-01-10 10:10 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-02-11 06:34 - 2015-01-10 09:28 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-02-11 06:34 - 2015-01-10 09:22 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-02-11 06:34 - 2015-01-10 08:00 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-02-11 06:34 - 2015-01-10 07:38 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-02-11 06:34 - 2014-12-19 09:57 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-02-11 06:34 - 2014-12-19 09:25 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2015-02-11 06:34 - 2014-12-09 04:45 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
2015-02-11 06:34 - 2014-12-09 02:56 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-02-11 06:34 - 2014-12-09 00:12 - 00391526 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-02-11 06:34 - 2014-10-29 03:51 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msaudite.dll
2015-02-11 06:34 - 2014-10-29 03:50 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2015-02-11 06:34 - 2014-10-29 03:06 - 00736768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2015-02-11 06:34 - 2014-10-29 03:06 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msaudite.dll
2015-02-11 06:34 - 2014-10-29 03:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-02-11 06:34 - 2014-10-29 03:02 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-02-11 06:34 - 2014-10-29 02:57 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
2015-02-11 06:34 - 2014-10-29 02:31 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-02-11 06:34 - 2014-10-29 02:15 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2015-02-11 06:34 - 2014-10-29 02:15 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2015-02-11 06:34 - 2014-10-29 02:14 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2015-02-11 06:34 - 2014-10-29 02:13 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2015-02-11 06:34 - 2014-10-29 02:13 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2015-02-10 20:56 - 2015-02-10 20:58 - 00018035 _____ () C:\Users\*******\Downloads\Addition.txt
2015-02-10 20:54 - 2015-02-11 09:49 - 00018038 _____ () C:\Users\*******\Downloads\FRST.txt
2015-02-10 20:53 - 2015-02-10 20:53 - 00380416 _____ () C:\Users\*******\Downloads\4hxdczjx.exe
2015-02-10 20:52 - 2015-02-11 09:49 - 00000000 ____D () C:\FRST
2015-02-10 20:50 - 2015-02-10 20:50 - 02132992 _____ (Farbar) C:\Users\*******\Downloads\FRST64.exe
2015-02-10 20:49 - 2015-02-10 20:49 - 00000000 _____ () C:\Users\*******\defogger_reenable
2015-02-10 20:44 - 2015-02-10 20:44 - 00050477 _____ () C:\Users\*******\Downloads\Defogger.exe
2015-02-10 20:29 - 2015-02-10 20:31 - 154051656 _____ () C:\Users\*******\Downloads\avira_free_antivirus468_de.exe
2015-02-10 13:13 - 2015-02-10 13:14 - 00415638 _____ () C:\Users\*******\Desktop\Neu2.xlsm
2015-02-10 09:38 - 2015-02-10 12:56 - 00417940 _____ () C:\Users\*******\Desktop\Neu.xlsm
2015-02-09 12:54 - 2015-02-09 12:54 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2015-02-09 08:39 - 2015-02-09 08:40 - 00000000 ____D () C:\Users\*******\Desktop\Fotos Uwe Pfisterer
2015-02-09 00:40 - 2015-02-09 00:40 - 00001771 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-02-09 00:40 - 2015-02-09 00:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-02-09 00:39 - 2015-02-09 00:40 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-02-09 00:39 - 2015-02-09 00:40 - 00000000 ____D () C:\Program Files\iTunes
2015-02-09 00:39 - 2015-02-09 00:39 - 00000000 ____D () C:\Program Files\iPod
2015-02-09 00:39 - 2015-02-09 00:39 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-02-09 00:34 - 2015-02-09 00:34 - 00002523 _____ () C:\Users\Public\Desktop\Evernote.lnk
2015-02-09 00:34 - 2015-02-09 00:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2015-02-06 15:05 - 2015-02-11 09:26 - 00000000 ____D () C:\Program Files (x86)\14e045d6-fe1c-4ded-abc7-9e94deb70b05
2015-02-06 13:17 - 2015-02-06 13:17 - 00628496 _____ (CMI Limited) C:\Users\*******\AppData\Local\nsgF773.tmp
2015-02-05 17:34 - 2015-02-05 17:34 - 00731913 _____ () C:\Users\*******\Downloads\Konzeption einer Wissensdatenbank.pptx
2015-02-05 09:06 - 2015-02-05 09:06 - 00000976 _____ () C:\Users\*******\Desktop\HKGELD-2000.lnk
2015-02-05 09:06 - 2015-02-05 09:06 - 00000000 ____D () C:\Users\*******\Documents\HKGELD
2015-02-05 09:06 - 2015-02-05 09:06 - 00000000 ____D () C:\Users\*******\AppData\Roaming\dlg
2015-02-05 09:06 - 2015-02-05 09:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HKGELD-2000
2015-02-05 09:06 - 2015-02-05 09:06 - 00000000 ____D () C:\Program Files (x86)\HKGELD-2000
2015-02-05 09:03 - 2015-02-05 09:03 - 00003766 _____ () C:\WINDOWS\System32\Tasks\KTQOS
2015-02-05 09:03 - 2015-01-27 17:31 - 00344440 _____ (CartCrunch Israel Ltd.) C:\WINDOWS\system32\ColorMedia64.dll
2015-02-05 09:03 - 2015-01-27 17:31 - 00301168 _____ (CartCrunch Israel Ltd.) C:\WINDOWS\SysWOW64\ColorMedia.dll
2015-02-05 09:01 - 2015-02-05 09:01 - 00000000 ____D () C:\Users\*******\AppData\Roaming\TuneUp Software
2015-02-05 09:01 - 2015-02-05 09:01 - 00000000 ____D () C:\Users\*******\AppData\Local\TuneUp Software
2015-02-05 09:00 - 2015-02-05 09:02 - 00000000 ____D () C:\ProgramData\TuneUp Software
2015-02-05 09:00 - 2015-02-05 09:00 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2015-02-05 08:53 - 2015-02-05 08:53 - 00620008 _____ () C:\Users\*******\Downloads\hkg2000_114_CB-DL-Manager.exe
2015-01-29 09:01 - 2015-02-04 15:06 - 00014192 _____ () C:\Users\*******\Desktop\Partner Aktion.xlsx
2015-01-26 08:05 - 2015-01-26 08:05 - 00262144 ____N () C:\WINDOWS\Minidump\012615-33015-01.dmp
2015-01-22 11:13 - 2015-01-22 11:13 - 00466167 _____ () C:\Users\*******\Downloads\Analysebericht.xlsx
2015-01-19 08:36 - 2015-01-19 08:37 - 00000160 _____ () C:\Users\*******\Desktop\Code automatisches öffnen.txt
2015-01-19 08:36 - 2015-01-19 08:36 - 00000000 ___RD () C:\Users\*******\Documents\Notes
2015-01-15 15:44 - 2015-01-15 15:44 - 00069120 _____ () C:\Users\*******\Downloads\Rendite_Riester.xls
2015-01-14 09:34 - 2015-01-14 09:34 - 04972848 _____ (TeamViewer) C:\Users\*******\Downloads\TeamViewerQS_de-idcfz2ka2r.exe
2015-01-14 09:34 - 2015-01-14 09:34 - 00000000 ____D () C:\Users\*******\AppData\Roaming\TeamViewer
2015-01-14 07:46 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-01-14 07:46 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-01-14 07:46 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-01-14 07:46 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-14 07:46 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-01-14 07:46 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-01-14 07:46 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2015-01-14 07:46 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-01-14 07:46 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2015-01-14 07:46 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-01-14 07:46 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-01-14 07:46 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2015-01-14 07:46 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-01-14 07:46 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-01-14 07:46 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-01-14 07:46 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2015-01-14 07:46 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2015-01-14 07:46 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-01-14 07:46 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-01-14 07:46 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-01-14 07:46 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-01-14 07:46 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2015-01-14 07:46 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2015-01-14 07:46 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-01-14 07:46 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-01-14 07:46 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-01-14 07:46 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-01-14 07:46 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2015-01-14 07:46 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2015-01-14 07:46 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-01-14 07:46 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-11 09:46 - 2014-12-01 18:23 - 00005152 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for ARBEITS-PC-******* Arbeits-PC
2015-02-11 09:46 - 2014-11-22 12:42 - 00000000 ____D () C:\Users\*******\OneDrive
2015-02-11 09:45 - 2014-12-01 16:22 - 00001136 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-11 09:43 - 2014-12-08 08:23 - 00006998 _____ () C:\WINDOWS\setupact.log
2015-02-11 09:43 - 2014-12-08 08:22 - 00067648 _____ () C:\WINDOWS\PFRO.log
2015-02-11 09:43 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-02-11 09:42 - 2014-12-08 08:27 - 01199006 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-11 09:42 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-02-11 09:41 - 2014-12-01 16:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-11 09:41 - 2014-11-16 21:54 - 00001017 _____ () C:\Users\*******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-11 09:39 - 2014-11-16 22:02 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2600528798-198841283-459962802-1003
2015-02-11 09:36 - 2014-11-22 09:33 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-02-11 09:34 - 2014-12-01 16:22 - 00001140 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-11 09:33 - 2013-08-22 15:44 - 00482240 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-11 09:26 - 2013-12-22 13:49 - 00000000 ____D () C:\Program Files (x86)\AmIcoSingLun
2015-02-11 09:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-02-11 08:56 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-02-11 06:58 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-02-11 06:49 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-02-11 06:41 - 2014-11-18 13:28 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-02-11 06:41 - 2013-06-10 17:39 - 116773704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-02-11 06:33 - 2014-11-22 12:43 - 00003946 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A31A0F7D-2455-433A-9F54-101AC9E9F96B}
2015-02-10 21:31 - 2014-12-09 22:07 - 00139776 ___SH () C:\Users\*******\Desktop\Thumbs.db
2015-02-10 21:29 - 2014-11-22 12:18 - 00000000 ____D () C:\Users\*******
2015-02-10 09:03 - 2014-09-24 07:17 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-10 09:03 - 2014-09-24 06:43 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat
2015-02-10 09:03 - 2014-09-24 06:43 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat
2015-02-10 07:57 - 2014-12-18 09:42 - 00000000 ____D () C:\Users\*******\.freemind
2015-02-10 07:57 - 2014-12-04 14:13 - 00000072 _____ () C:\Users\Public\LMDebug.log
2015-02-09 00:39 - 2014-11-19 23:33 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-02-06 16:29 - 2014-12-01 16:22 - 00004112 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-06 16:29 - 2014-12-01 16:22 - 00003876 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-05 13:04 - 2014-11-16 21:52 - 00000000 ____D () C:\Users\*******\AppData\Local\VirtualStore
2015-02-03 20:31 - 2014-09-24 08:46 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-02-03 20:31 - 2014-09-24 08:46 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-03 16:50 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2015-02-03 16:05 - 2014-12-02 20:10 - 00155136 _____ () C:\Users\*******\Desktop\Potential-Analyse-2.xls
2015-01-31 12:31 - 2014-11-16 21:52 - 00000000 ____D () C:\Users\*******\AppData\Local\Packages
2015-01-29 15:53 - 2014-12-19 18:09 - 00000000 ____D () C:\Users\*******\Desktop\Scans Neukunden
2015-01-26 08:05 - 2014-12-08 08:23 - 00000000 ____D () C:\WINDOWS\Minidump
==================== Files in the root of some directories =======
2014-11-21 22:14 - 2014-11-21 22:13 - 0613057 _____ (CMI Limited) C:\Users\*******\AppData\Local\nscEBFA.tmp
2015-02-06 13:17 - 2015-02-06 13:17 - 0628496 _____ (CMI Limited) C:\Users\*******\AppData\Local\nsgF773.tmp
2014-11-21 22:58 - 2014-11-21 22:58 - 0613057 _____ (CMI Limited) C:\Users\*******\AppData\Local\nso7C6.tmp
2013-12-17 01:30 - 2013-12-17 01:30 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\*******\AppData\Local\Temp\CloudBackup63.exe
C:\Users\*******\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\*******\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\*******\AppData\Local\Temp\Quarantine.exe
C:\Users\*******\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\*******\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\*******\AppData\Local\Temp\SpOrder.dll
C:\Users\*******\AppData\Local\Temp\sqlite3.dll
C:\Users\*******\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-11 06:40
==================== End Of Log ============================ --- --- ---
Ich denke ich habe soweit alles nach Anleitung durchgeführt.
LG Zeus 24 |