madlein84 | 26.02.2015 14:09 | Hat alles Problemlos funktioniert,... Code:
# AdwCleaner v4.111 - Bericht erstellt 26/02/2015 um 13:43:34
# Aktualisiert 18/02/2015 von Xplode
# Datenbank : 2015-02-18.3 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Karin - KARIN-PC
# Gestarted von : C:\Users\Karin\Downloads\AdwCleaner_4.111.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : ReimageRealTimeProtector
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Reimage Protector
Ordner Gelöscht : C:\Program Files\Reimage
Ordner Gelöscht : C:\Users\Karin\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Karin\AppData\Local\SwvUpdater
Ordner Gelöscht : C:\Users\Karin\AppData\Local\CrashRpt
Ordner Gelöscht : C:\Users\Karin\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Allmyapps
Ordner Gelöscht : C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\Reimage.ini
***** [ Geplante Tasks ] *****
Task Gelöscht : ReimageUpdater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3279141
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{462862BE-9A5C-49A5-9CBD-A649EAC63645}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{0113A098-06EA-4776-A011-D75590778F1E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{BEAA0C04-ED15-4C17-800B-28716025A4E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{462862BE-9A5C-49A5-9CBD-A649EAC63645}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Schlüssel Gelöscht : HKCU\Software\AVG Nation toolbar
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\UpToDown
Schlüssel Gelöscht : HKCU\Software\Reimage
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\AVG Nation toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Better-Surf
Schlüssel Gelöscht : HKLM\SOFTWARE\SPPDCOM
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Reimage
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Reimage Repair
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17631
-\\ Mozilla Firefox v35.0.1 (x86 de)
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("CT3279141.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279141&SearchSource=2&CUI=UN11539237281698714&q=");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("CT3279141.installType", "conduitnsisintegration");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("CT3279141.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3279141&octid=CT3279141&SearchSource=15&CUI=UN11539237281698714&SSPV=EB_SSPV&Lay=1&UM=U[...]
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("CT3279141.smartbar.CTID", "CT3279141");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("CT3279141.smartbar.Uninstall", "0");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("CT3279141.smartbar.homepage", "true");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("CT3279141.smartbar.toolbarName", "WhiteSmoke B ");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.ConduitHomepagesList", "");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.ConduitSearchEngineList", "WhiteSmoke B Customized Web Search");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279141&SearchSource=2&CUI=UN11539237281698714&q=");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("Smartbar.keywordURLSelectedCTID", "CT3279141");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=M5044C56D-8E26-4F2A-A65C-1A8BDDF11976&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SPFD2727B3-AB7B-437[...]
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaultthis.engineName", "WhiteSmoke B Customized Web Search");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279141&SearchSource=3&q={searchTerms}&CUI=UN11539237281698714");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.order.1", "default-search.net");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "default-search.net");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=146&itype=n&ver=15586&tm=615&src=ds&p=");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("smartBar.searchInNewTabOwner", "CT3279141");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3279141&SearchSource=13&CUI=UN11539237281698714");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279141&SearchSource=2&CUI=UN11539237281698714&q=,hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3[...]
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.machineId", "YO6RCMEAUIOC6SEXZF//2+4DFMQU1052W5OYQ5TWXJIXDS0YECXTFNE2GXDUMUZB9NK/41GHS+SNZTZNSGY/KA");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.originalHomepage", "about:home");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.originalSearchAddressUrl", "");
[ho6ojs3q.default\prefs.js] - Zeile Gelöscht : user_pref("smartbar.originalSearchEngine", "");
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [8113 Bytes] - [26/02/2015 13:38:56]
AdwCleaner[S0].txt - [7640 Bytes] - [26/02/2015 13:43:34]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7699 Bytes] ########## Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 26.02.2015
Suchlauf-Zeit: 13:15:44
Logdatei: Logfile MBAM.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.02.26.02
Rootkit Datenbank: v2015.02.25.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Karin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 351395
Verstrichene Zeit: 13 Min, 50 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
RiskWare.Tool.CK, C:\Windows\KMService.exe, 2280, Löschen bei Neustart, [d931cf54395148ee59779ddb966c40c0]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 14
PUP.Optional.Snapdo.T, HKU\S-1-5-21-3892461942-2112615261-3819026985-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [df2b90935c2ebd797056f05efc07f20e],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [df2b90935c2ebd797056f05efc07f20e],
PUP.Optional.WhiteSmoke, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{f0e59437-6148-4a98-b0a6-60d557ef57f4}, In Quarantäne, [67a35fc4bbcf1422d03d1d2fb152bd43],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\LINKEY, In Quarantäne, [d634c2612f5b10268d11b1298d76c53b],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, In Quarantäne, [2fdb56cd870379bd7f2124fc996c2fd1],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [ec1e01227b0f0b2bbee1b16faf56669a],
PUP.Optional.DealPly.A, HKLM\SOFTWARE\WOW6432NODE\DealPlyLive, In Quarantäne, [b357e0430e7c1125341d09f558ac49b7],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SmdmF, In Quarantäne, [52b80d16167489adf22e8535669d5aa6],
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD, In Quarantäne, [44c648dbc1c9a09640b05c6118eb4fb1],
PUP.Optional.DealPly.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DealPlyLive, In Quarantäne, [a2685bc8fa902a0c5afac93548bc1be5],
PUP.Optional.ConduitSearch.A, HKU\S-1-5-21-3892461942-2112615261-3819026985-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Conduit_Search_Protect, In Quarantäne, [9674160d07835bdb072e8d124bb853ad],
PUP.Optional.DealPly.A, HKU\S-1-5-21-3892461942-2112615261-3819026985-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DealPlyLive, In Quarantäne, [cd3d44dff1992f07193b14eac63e4db3],
PUP.Optional.Softonic.A, HKU\S-1-5-21-3892461942-2112615261-3819026985-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, In Quarantäne, [17f3e73c28623501889cbdea34cf0000],
PUP.Optional.PriceGong.A, HKU\S-1-5-21-3892461942-2112615261-3819026985-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [15f5f3301575f83eddfbdcced42f01ff],
Registrierungswerte: 10
PUP.Optional.WhiteSmoke, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{F0E59437-6148-4A98-B0A6-60D557EF57F4}, In Quarantäne, [67a35fc4bbcf1422d03d1d2fb152bd43],
PUP.Optional.WhiteSmoke, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{f0e59437-6148-4a98-b0a6-60d557ef57f4}, In Quarantäne, [47c31d06f793e155a865da727f8408f8],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\LINKEY|ie_jsurl, hxxp://app.linkeyproject.com/popup/IE/background.js, In Quarantäne, [d634c2612f5b10268d11b1298d76c53b]
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [9179f82b7515a39324ef7a3dd72cc739]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [b5552bf84248ee48c44f3285fa09ae52]
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|xz123@ya456.com, C:\Program Files (x86)\BetterSurf\ff, In Quarantäne, [2edcc95a503a3303b4b7b80daf54a060]
PUP.Optional.BetterSurf.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|12x3q@3244516.com, C:\Program Files (x86)\Better-Surf\ff, In Quarantäne, [1bef8a99880276c0b13357c60401b14f]
PUP.Optional.FreeMakeConverter.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|fmconverter@gmail.com, C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\, In Quarantäne, [6aa064bf0684f93d138205a728db18e8]
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD|ImagePath, \??\C:\Windows\system32\drivers\SPPD.sys, In Quarantäne, [44c648dbc1c9a09640b05c6118eb4fb1]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-3892461942-2112615261-3819026985-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [41c9c65d4d3da591113f516f9370659b]
Registrierungsdaten: 1
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-3892461942-2112615261-3819026985-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.default-search.net?sid=476&aid=146&itype=n&ver=15586&tm=615&src=hmp, Gut: (www.google.com), Schlecht: (hxxp://www.default-search.net?sid=476&aid=146&itype=n&ver=15586&tm=615&src=hmp),Ersetzt,[9278c95aed9dc86e3c949630c3422bd5]
Ordner: 65
Stolen.Data, C:\Users\Karin\AppData\Roaming\Imminent\Logs, In Quarantäne, [b55535ee7d0db0868f2dc107847fcf31],
PUP.Optional.SpeedTestAnalysis.A, C:\Users\Karin\AppData\Roaming\SpeedTestAnalysis, In Quarantäne, [71993ce781097eb8299311d361a20af6],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive, In Quarantäne, [ae5c4bd87218d066b17f49167b8830d0],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update, In Quarantäne, [ae5c4bd87218d066b17f49167b8830d0],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update\Log, In Quarantäne, [ae5c4bd87218d066b17f49167b8830d0],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive, In Quarantäne, [9773ab7882083df93101ed725ea5bf41],
PUP.Optional.DealPly.A, C:\Program Files (x86)\DealPlyLive\CrashReports, In Quarantäne, [9773ab7882083df93101ed725ea5bf41],
PUP.Optional.OpenCandy, C:\Users\Karin\AppData\Roaming\OpenCandy, In Quarantäne, [cc3e78ab8802a591bca62c3358ab10f0],
PUP.Optional.OpenCandy, C:\Users\Karin\AppData\Roaming\OpenCandy\71E8819086994B9FAFA9D06DB522780F, In Quarantäne, [cc3e78ab8802a591bca62c3358ab10f0],
PUP.Optional.OpenCandy, C:\Users\Karin\AppData\Roaming\OpenCandy\B0D24D0DD2314E758C66A29C73ABB069, In Quarantäne, [cc3e78ab8802a591bca62c3358ab10f0],
PUP.Optional.DealPly.A, C:\Users\Karin\AppData\Local\DealPlyLive, In Quarantäne, [8486160d8307d3634f31550a3bc80bf5],
PUP.Optional.DealPly.A, C:\Users\Karin\AppData\Local\DealPlyLive\CrashReports, In Quarantäne, [8486160d8307d3634f31550a3bc80bf5],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.SearchProtect.A, C:\Users\Karin\AppData\Local\SearchProtect, In Quarantäne, [9b6f9b8851392e08bda4e292867df30d],
PUP.Optional.IBUpdater.A, C:\ProgramData\IBUpdaterService, In Quarantäne, [10faf92a5a30cc6ae7de8befe61deb15],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\AddedAppDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\DefualtImages, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\DetectedAppDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\EngineFirstTimeDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\NewSearchProtectorDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\NewSearchProtectorDialog\images, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog\images, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorDialog\Images, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog\Images, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarUntrustedAppsApprovalDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UninstallDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UntrustedAddedAppDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UntrustedAppApprovalDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UntrustedAppPendingDialog, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\EmailNotifier, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ExternalComponent, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Logs, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\MyStuffApps, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\RadioPlayer, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\AppsMetaData, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\DynamicDialogs, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\ToolbarHiddenSettings, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\ToolbarLogin, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\ToolbarSettings, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_en, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_en\ToolbarTranslation, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\SearchInNewTab, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\skin, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\skin\classic, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\modules, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
Dateien: 209
RiskWare.Tool.CK, C:\Windows\KMService.exe, Löschen bei Neustart, [d931cf54395148ee59779ddb966c40c0],
PUP.Optional.Installcore, C:\Users\Karin\Downloads\civilization-iv.exe, In Quarantäne, [eb1f3ee5f199fd393627b8bc5ea7ad53],
Stolen.Data, C:\Users\Karin\AppData\Roaming\Imminent\Logs\18-02-2015, In Quarantäne, [b55535ee7d0db0868f2dc107847fcf31],
Stolen.Data, C:\Users\Karin\AppData\Roaming\Imminent\Logs\19-02-2015, In Quarantäne, [b55535ee7d0db0868f2dc107847fcf31],
Stolen.Data, C:\Users\Karin\AppData\Roaming\Imminent\Logs\20-02-2015, In Quarantäne, [b55535ee7d0db0868f2dc107847fcf31],
Stolen.Data, C:\Users\Karin\AppData\Roaming\Imminent\Logs\21-02-2015, In Quarantäne, [b55535ee7d0db0868f2dc107847fcf31],
Stolen.Data, C:\Users\Karin\AppData\Roaming\Imminent\Logs\22-02-2015, In Quarantäne, [b55535ee7d0db0868f2dc107847fcf31],
Malware.Trace.E, C:\Users\Karin\AppData\Roaming\Imminent\Path.dat, In Quarantäne, [21e96fb4305ae74f932a15b3a360f10f],
PUP.Optional.Trovi.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\searchplugins\trovi-search.xml, In Quarantäne, [e8223ae994f643f34737dcf3719243bd],
PUP.Optional.DefaultSearch.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\searchplugins\default-search.xml, In Quarantäne, [8b7ffc276c1e7bbb978af6e4be459868],
PUP.Optional.DefaultSearch.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml, In Quarantäne, [8b7f3ee5e9a14ee80b175b7fe41fee12],
PUP.Optional.SpeedTestAnalysis.A, C:\Users\Karin\AppData\Roaming\SpeedTestAnalysis\speedtestanalysis.crx, In Quarantäne, [71993ce781097eb8299311d361a20af6],
PUP.Optional.SpeedTestAnalysis.A, C:\Users\Karin\AppData\Roaming\SpeedTestAnalysis\DeskTopIcon.ico, In Quarantäne, [71993ce781097eb8299311d361a20af6],
PUP.Optional.SpeedTestAnalysis.A, C:\Users\Karin\AppData\Roaming\SpeedTestAnalysis\install_helper.exe, In Quarantäne, [71993ce781097eb8299311d361a20af6],
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [000a0221206adb5b673cd24e6e97e51b],
PUP.Optional.DealPly.A, C:\ProgramData\DealPlyLive\Update\Log\DealPlyLive.log, In Quarantäne, [ae5c4bd87218d066b17f49167b8830d0],
PUP.Optional.OpenCandy, C:\Users\Karin\AppData\Roaming\OpenCandy\B0D24D0DD2314E758C66A29C73ABB069\TuneUpUtilities2014_de-DE.exe, In Quarantäne, [cc3e78ab8802a591bca62c3358ab10f0],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\1.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\371.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\4489.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\a.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\b.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\c.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\d.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\e.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\f.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\g.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\h.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\i.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\j.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\k.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\l.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\m.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\n.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\o.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\p.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\q.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\r.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\s.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\t.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\u.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\v.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\w.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\wlu.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\x.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\y.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.PriceGong.A, C:\Users\Karin\AppData\LocalLow\PriceGong\Data\z.txt, In Quarantäne, [b852b66d6d1d52e4bc0bc0a2fb08b848],
PUP.Optional.IBUpdater.A, C:\ProgramData\IBUpdaterService\repository.xml, In Quarantäne, [10faf92a5a30cc6ae7de8befe61deb15],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\hk64tbWhi0.dll, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\hktbWhi0.dll, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ldrtbWhi0.dll, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ldrtbWhit.dll, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\tbWhi0.dll, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\tbWhi1.dll, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\tbWhit.dll, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ThirdPartyComponents.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\toolbar.cfg, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_94_300_CT3007394_images_634650152257339187_20PX_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_94_300_CT3007394_Skins_634650129545916287_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_About_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Browse_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Contact_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Hide_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_LikeIcon_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_MoreFromPublisher_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_More_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Options_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Privacy_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_main_menu_shrink_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_main_menu_tell_a_friend_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_main_menu_upgrade_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_Menu_uninstall-icon_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_SearchEngines_images_search_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_MarketPlace_97_5e6_9739aadc-99e3-4b66-8c1e-bc6ae6cd55e6_Appearance_634165981520378434_24x24_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_MarketPlace_d2_909_d2d47f0a-2c1d-48a1-8dba-fdebac043909_Appearance_634726116365249321_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_94_300_CT3007394_Images_634650152028270822_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Refresh_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_main_menu_refresh_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_85_319_CT3198785_images_634921255359427985_24PX_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_94_300_CT3007394_Images_633317530166393750_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_94_300_CT3007394_Images_633317530254831250_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_94_300_CT3007394_Images_633317540102175000_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_94_300_CT3007394_Images_633317621550925000_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_94_300_CT3007394_Images_633863768206468750_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_94_300_CT3007394_Images_634121172080562500_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_Conduit_com_bankImages_ConduitEngine_ContextMenu_Upgrade_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_ClientImages_radio_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_eula_png.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_main_menu_about_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_main_menu_clear_history_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_main_menu_help_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_main_menu_options_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\CacheIcons\http___storage_conduit_com_images_main_menu_privacy_gif.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\RoundedCornersIE9.css, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\DialogsAPI.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\excanvas.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\generalDialogStyle.css, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\PIE.htc, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\RoundedCorners.css, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\settings.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\version.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\AddedAppDialog\app-added.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\AddedAppDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\DefualtImages\icon.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\DetectedAppDialog\app-2go.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\DetectedAppDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\EngineFirstTimeDialog\EngineFirstTimeDialog.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\EngineFirstTimeDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\EngineFirstTimeDialog\right-click.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\NewSearchProtectorDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\NewSearchProtectorDialog\SearchProtector.css, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\NewSearchProtectorDialog\SearchProtector.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\NewSearchProtectorDialog\images\ok-button.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\NewSearchProtectorDialog\images\separation-line.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\NewSearchProtectorDialog\images\warning.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog\bubble.css, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog\bubble.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog\images\information.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog\images\x-default-LTR.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog\images\x-default-RTL.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-LTR.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-RTL.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorDialog\SearchProtector.css, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorDialog\SearchProtector.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorDialog\Images\info.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorDialog\Images\ok-on.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorDialog\Images\ok.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.css, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.jpg, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog\Images\info.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog\Images\ok-on.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\SearchProtectorRetakeoverDialog\Images\ok.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.css, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images\app-store-icon.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images\arrow.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images\divider.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images\emailNotifier.gif, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images\facebook.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images\radio.GIF, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images\Thumbs.db, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images\truste_welcome.GIF, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarFirstTimeDialog\images\weather.GIF, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarUntrustedAppsApprovalDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\ToolbarUntrustedAppsApprovalDialog\ToolbarUntrustedAppsApprovalDialog.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UntrustedAddedAppDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UntrustedAddedAppDialog\UT-app-dialog-added.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UntrustedAppApprovalDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UntrustedAppApprovalDialog\UT-app-dialog-needs-your-approval.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UntrustedAppPendingDialog\main.html, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Dialogs\UntrustedAppPendingDialog\UT-app-dialog-is-waiting.js, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=OtherApps&locale=en.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=GottenApps&locale=en&ctid=CT3279141.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=GottenApps&locale=en.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=OtherApps&locale=en&ctid=CT3279141.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=SharedApps&locale=en&ctid=CT3279141.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=SharedApps&locale=en.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=Toolbar&locale=en&ctid=CT3279141.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\ExternalComponent\http___contextmenu_toolbar_conduit-services_com__name=Toolbar&locale=en.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\manifest.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin\PriceGong_16.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGongIE.dll, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.6.12\bin\PriceGong_16.png, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\RadioPlayer\IP_Stations_Media_List.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\RadioPlayer\Predefined_Media_List.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\AppsMetaData\data.bck.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\AppsMetaData\data.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\DynamicDialogs\data.bck.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\DynamicDialogs\data.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\ToolbarHiddenSettings\data.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\ToolbarLogin\data.bck.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\ToolbarLogin\data.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\ToolbarSettings\data.bck.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_CT3279141\ToolbarSettings\data.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_en\ToolbarTranslation\data.bck.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\Repository\conduit_CT3279141_en\ToolbarTranslation\data.txt, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.WhiteSmoke.A, C:\Users\Karin\AppData\LocalLow\WhiteSmoke_B\SearchInNewTab\SearchInNewTabContent.xml, In Quarantäne, [a466a380b4d6ca6c0b002b5ed13237c9],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome.manifest, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\install.rdf, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content\aff.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content\jquery-1.8.3.min.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content\mo.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content\overlay.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content\overlay.xul, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content\popup.html, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content\popup.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content\tools.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\content\tr.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\skin\classic\button.png, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\skin\classic\icon.png, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\skin\classic\main.css, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\chrome\skin\classic\overlay.css, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\modules\AddonInfo.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\modules\FileCacher.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\modules\PrefMan.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\modules\TimePassed.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.BetterFoxFinder.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\extensions\{113c6a96-cbc4-4248-bc8a-c05e9ec4b669}\modules\XCipher.js, In Quarantäne, [ec1ee43f6f1bc96dd5b1fa9c8f747789],
PUP.Optional.DefaultSearch, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.selectedEngine", "default-search.net");), Ersetzt,[9a70869d8a0088ae69c6e02d2ed8ee12]
PUP.Optional.Trovi.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=M5044C56D-8E26-4F2A-A65C-1A8BDDF11976&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5&UP=SPFD2727B3-AB7B-4376-817B-07726AAD4623");), Ersetzt,[02089d867c0e95a127baa766b45214ec]
PUP.Optional.DefaultSearch.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://www.default-search.net/search?sid=476&aid=146&itype=n&ver=15586&tm=615&src=ds&p=");), Ersetzt,[8c7e978c9ceec47268c0ae6037cf649c]
PUP.Optional.Conduit.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279141&SearchSource=3&q={searchTerms}&CUI=UN11539237281698714");), Ersetzt,[b8522af923673df9b2e1dc320ef89070]
PUP.Optional.Conduit.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\prefs.js, Gut: (), Schlecht: (user_pref("CT3279141.SearchFromAddressBarUrl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3279141&SearchSource=2&CUI=UN11539237281698714&q=");), Ersetzt,[26e45ac9d8b250e6ade71ef0f80ea759]
PUP.Optional.Conduit.A, C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\prefs.js, Gut: (), Schlecht: (user_pref("CT3279141.lastNewTabSettings", "{\"isEnabled\":true,\"newTabUrl\":\"hxxp://search.conduit.com/?ctid=CT3279141&octid=CT3279141&SearchSource=15&CUI=UN11539237281698714&SSPV=EB_SSPV&Lay=1&UM=UM_ID\"}");), Ersetzt,[d238a67d6e1c41f5653d5bb3bc4a44bc]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt) Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Karin on 26.02.2015 at 13:48:53,52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\reimage repair"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Karin\AppData\Roaming\mozilla\firefox\profiles\ho6ojs3q.default\smartbar
Successfully deleted the following from C:\Users\Karin\AppData\Roaming\mozilla\firefox\profiles\ho6ojs3q.default\prefs.js
user_pref("CT3279141.1000082.isPlayDisplay", "true");
user_pref("CT3279141.1000082.state", "{\"state\":\"stopped\",\"text\":\"Californi...\",\"description\":\"California Rock\",\"url\":\"hxxp://feedlive.net/california.asx\"}");
user_pref("CT3279141.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3279141.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3279141.FirstTime", "true");
user_pref("CT3279141.FirstTimeFF3", "true");
user_pref("CT3279141.LoginRevertSettingsEnabled", true);
user_pref("CT3279141.PG_ENABLE.enc", "dHJ1ZQ==");
user_pref("CT3279141.RevertSettingsEnabled", true);
user_pref("CT3279141.UserID", "UN11539237281698714");
user_pref("CT3279141.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT3279141.autoDisableScopes", -1);
user_pref("CT3279141.browser.search.defaultthis.engineName", "true");
user_pref("CT3279141.cbfirsttime.enc", "V2VkIEphbiAzMCAyMDEzIDIxOjUxOjQzIEdNVCswMTAw");
user_pref("CT3279141.defaultSearch", "true");
user_pref("CT3279141.enableAlerts", "always");
user_pref("CT3279141.enableFix404ByUser", "TRUE");
user_pref("CT3279141.enableSearchFromAddressBar", "true");
user_pref("CT3279141.firstTimeDialogOpened", "true");
user_pref("CT3279141.fixPageNotFoundError", "true");
user_pref("CT3279141.fixPageNotFoundErrorByUser", "true");
user_pref("CT3279141.fixPageNotFoundErrorInHidden", "true");
user_pref("CT3279141.fixUrls", true);
user_pref("CT3279141.homepageuserchanged", true);
user_pref("CT3279141.hxxp___api18_starwebnet_com.pid2.enc", "Nzg0ZGQ3NjU0ZDg5ODc5Yw==");
user_pref("CT3279141.hxxp___api21_starwebnet_com.pid2.enc", "Nzg0ZGQ3NjU0ZDg5ODc5Yw==");
user_pref("CT3279141.installDate", "30/1/2013 21:51:08");
user_pref("CT3279141.installId", "9818");
user_pref("CT3279141.isCheckedStartAsHidden", true);
user_pref("CT3279141.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3279141.isFirstTimeToolbarLoading", "false");
user_pref("CT3279141.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT3279141.keyword", "true");
user_pref("CT3279141.lastVersion", "10.14.65.43");
user_pref("CT3279141.mam_gk_CouponBuddy_appState.enc", "b24=");
user_pref("CT3279141.mam_gk_PriceGong_appState.enc", "b24=");
user_pref("CT3279141.mam_gk_appsData.enc", "eyJhcHBzIjpbeyJpZCI6IlByaWNlR29uZyIsInVybCI6Imh0dHA6Ly9zdG9yYWdlLmNvbmR1aXQuY29tL21hbS8zcmRwYXJ0eWFwcHMvcGcvcGcuaHRtbCIsIm9wdGlvbnN
user_pref("CT3279141.mam_gk_appsDefaultEnabled.enc", "dHJ1ZQ==");
user_pref("CT3279141.mam_gk_configuration.enc", "eyJjb25maWd1cmF0aW9uIjpbeyJpZCI6IlByaWNlR29uZyIsImNyaXRlcmlhcyI6W3siY3JpdGVyaWFJZCI6IjQzZmVjMDg1LWNkMzktNGQyZi05MDZhLTAyNTdkZj
user_pref("CT3279141.mam_gk_currentVersion.enc", "MS4yLjAuMTA=");
user_pref("CT3279141.mam_gk_first_time.enc", "MQ==");
user_pref("CT3279141.mam_gk_installer_preapproved.enc", "ZmFsc2U=");
user_pref("CT3279141.mam_gk_lastLoginTime.enc", "MTM1OTU3OTEwMDQ4Mw==");
user_pref("CT3279141.mam_gk_localization.enc", "eyJnYWRnZXRDb250ZW50UG9saWN5Ijp7IlRleHQiOiJDb250ZW50IFBvbGljeSJ9LCJnYWRnZXREZXNjcmlwdGlvblByaW1hcnkiOnsiVGV4dCI6IlZhbHVlIEFwcHM
user_pref("CT3279141.mam_gk_pgUnloadedOnce.enc", "dHJ1ZQ==");
user_pref("CT3279141.mam_gk_settings1.2.0.10.enc", "eyJTdGF0dXMiOiJzdWNjZWVkZWQiLCJEYXRhIjp7ImludGVydmFsIjoyNDAsInN0YW1wIjoiNjFfLTEiLCJpc1Rlc3QiOmZhbHNlLCJpc1dlbGNvbWVFeHBlcml
user_pref("CT3279141.mam_gk_showCloseButton.enc", "dHJ1ZQ==");
user_pref("CT3279141.mam_gk_showWelcomeGadget.enc", "ZmFsc2U=");
user_pref("CT3279141.mam_gk_userId.enc", "ZDIzYjljNWQtODkxNy00NzBmLWFjMGUtMzgzZGQ1ZDk1MDIz");
user_pref("CT3279141.mam_gk_user_apps_selection.enc", "");
user_pref("CT3279141.migrateAppsAndComponents", true);
user_pref("CT3279141.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.krone.at%2FOesterreich%2FSpitalspatient_per_Blutkonserve_mit_HI-Virus_infiziert-Sind_ti
user_pref("CT3279141.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3279141.openThankYouPage", "false");
user_pref("CT3279141.openUninstallPage", "false");
user_pref("CT3279141.price-gong.isManagedApp", "true");
user_pref("CT3279141.revertSettingsEnabled", "true");
user_pref("CT3279141.search.searchAppId", "130028020976478709");
user_pref("CT3279141.search.searchCount", "0");
user_pref("CT3279141.searchInNewTabEnabledByUser", "true");
user_pref("CT3279141.searchInNewTabEnabledInHidden", "true");
user_pref("CT3279141.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3279141.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT3279141.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT3279141.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT3279141\"}");
user_pref("CT3279141.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://WhiteSmokeB.OurToolbar.com//xpi\"}");
user_pref("CT3279141.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"WhiteSmoke B\"}");
user_pref("CT3279141.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT3279141.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1359579074975");
user_pref("CT3279141.serviceLayer_services_appsMetadata_lastUpdate", "1359579074718");
user_pref("CT3279141.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1359579074726");
user_pref("CT3279141.serviceLayer_services_login_10.14.42.7_lastUpdate", "1360703676307");
user_pref("CT3279141.serviceLayer_services_login_10.14.65.43_lastUpdate", "1362052108009");
user_pref("CT3279141.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1359579074766");
user_pref("CT3279141.serviceLayer_services_searchAPI_lastUpdate", "1359579072938");
user_pref("CT3279141.serviceLayer_services_serviceMap_lastUpdate", "1361989376743");
user_pref("CT3279141.serviceLayer_services_toolbarContextMenu_lastUpdate", "1359579074659");
user_pref("CT3279141.serviceLayer_services_toolbarSettings_lastUpdate", "1362052107822");
user_pref("CT3279141.serviceLayer_services_translation_lastUpdate", "1361990536968");
user_pref("CT3279141.settingsINI", true);
user_pref("CT3279141.shouldFirstTimeDialog", "false");
user_pref("CT3279141.startPage", "true");
user_pref("CT3279141.toolbarBornServerTime", "30-1-2013");
user_pref("CT3279141.toolbarCurrentServerTime", "28-2-2013");
user_pref("CT3279141.toolbarDisabled", "true");
user_pref("CT3279141_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1362051987218,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}
user_pref("ct3279141.UserID", "UN11539237281698714");
Emptied folder: C:\Users\Karin\AppData\Roaming\mozilla\firefox\profiles\ho6ojs3q.default\minidumps [557 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26.02.2015 at 13:54:43,91
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-02-2015 01
Ran by Karin (administrator) on KARIN-PC on 26-02-2015 13:58:16
Running from C:\Users\Karin\Downloads
Loaded Profiles: Karin (Available profiles: Karin)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Atheros) C:\Program Files (x86)\Dell Wireless\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Synaptics Incorporated) C:\Windows\System32\valWBFPolicyService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(mquadr.at software engineering and consulting GmbH, web: www.mquadr.at, mail: office@mquadr.at) C:\Program Files (x86)\A1 Dashboard\Dashboard.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-26] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-02-22] (AVAST Software)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3892461942-2112615261-3819026985-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3892461942-2112615261-3819026985-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Adobe PDF Reader -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\..\Interfaces\{72E0DF5A-8A31-45EA-987F-9D4F925A8679}: [NameServer] 194.48.128.199 194.48.139.254
FireFox:
========
FF ProfilePath: C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default
FF Homepage: https://www.google.at/
FF NetworkProxy: "autoconfig_url", "https://secure.premiumize.me/1f04ae9a2719f64033f3dd8b9f9eec77/proxy.pac"
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.10.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.10.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.10.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @protectdisc.com/NPMPDRM -> C:\Program Files (x86)\Common Files\mpDRM\NPMPDRM.dll ( )
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3892461942-2112615261-3819026985-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Karin\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Premiumize.me - C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\Extensions\jid1-sirVJT0BXhkuJg@jetpack.xpi [2014-01-27]
FF Extension: Adblock Plus - C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-01-02]
FF Extension: Adblock Edge - C:\Users\Karin\AppData\Roaming\Mozilla\Firefox\Profiles\ho6ojs3q.default\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2014-01-27]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-02-22]
Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-22]
CHR Extension: (Google Drive) - C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-22]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-22]
CHR Extension: (YouTube) - C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-22]
CHR Extension: (Google Search) - C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-22]
CHR Extension: (Avast Online Security) - C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-02-22]
CHR Extension: (Google Wallet) - C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-22]
CHR Extension: (Gmail) - C:\Users\Karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-22]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-02-22]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Dell Wireless\Ath_CoexAgent.exe [151552 2010-10-01] (Atheros) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [53920 2010-12-17] (Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-02-22] (AVAST Software)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2015-02-22] (Avast Software)
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2014-05-27] (Freemake) [File not signed]
S2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2013-12-01] () [File not signed]
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [49040 2014-07-24] (Synaptics Incorporated)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S1 acedrv05; C:\Windows\system32\drivers\acedrv05.sys [136192 2013-07-14] () [File not signed]
S1 acedrv07; C:\Windows\system32\drivers\acedrv07.sys [125440 2015-01-06] () [File not signed]
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-02-22] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [87912 2015-02-22] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-02-22] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-02-22] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-02-22] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-02-22] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-02-22] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-02-22] ()
U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [256000 2010-08-31] (Huawei Technologies Co., Ltd.)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [117248 2010-07-27] (Huawei Technologies Co., Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2013-04-02] () [File not signed]
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2015-02-22] (Avast Software)
U3 amw8l7e1; C:\Windows\System32\Drivers\amw8l7e1.sys [0 ] (Microsoft Corporation) <==== ATTENTION (zero size file/folder)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz134; \??\C:\Users\Karin\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-26 13:57 - 2015-02-26 13:57 - 00000000 ____D () C:\Users\Karin\Downloads\FRST-OlderVersion
2015-02-26 13:48 - 2015-02-26 13:48 - 01388274 _____ (Thisisu) C:\Users\Karin\Downloads\JRT.exe
2015-02-26 13:38 - 2015-02-26 13:43 - 00000000 ____D () C:\AdwCleaner
2015-02-26 13:38 - 2015-02-26 13:38 - 02126848 _____ () C:\Users\Karin\Downloads\AdwCleaner_4.111.exe
2015-02-26 13:13 - 2015-02-26 13:34 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-26 13:12 - 2015-02-26 13:12 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-26 13:12 - 2015-02-26 13:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-26 13:12 - 2015-02-26 13:12 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-26 13:12 - 2015-02-26 13:12 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-26 13:12 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-26 13:12 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-26 13:12 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-26 13:05 - 2015-02-26 13:06 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Karin\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-25 21:55 - 2015-02-25 21:55 - 00000000 __SHD () C:\Users\Karin\AppData\Local\EmieUserList
2015-02-25 21:55 - 2015-02-25 21:55 - 00000000 __SHD () C:\Users\Karin\AppData\Local\EmieSiteList
2015-02-25 21:55 - 2015-02-25 21:55 - 00000000 __SHD () C:\Users\Karin\AppData\Local\EmieBrowserModeList
2015-02-25 17:51 - 2015-02-25 17:51 - 00028502 _____ () C:\ComboFix.txt
2015-02-25 13:26 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-25 13:26 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-25 13:26 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-25 13:26 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-25 13:26 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-25 13:26 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-25 13:26 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-25 13:26 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-25 13:25 - 2015-02-25 17:51 - 00000000 ____D () C:\ComboFix
2015-02-25 13:22 - 2015-02-25 13:22 - 00013473 _____ () C:\Users\Karin\Desktop\Combofix - Verknüpfung.lnk
2015-02-25 12:45 - 2015-01-09 00:44 - 00419936 _____ () C:\Windows\SysWOW64\locale.nls
2015-02-25 12:45 - 2015-01-09 00:43 - 00419936 _____ () C:\Windows\system32\locale.nls
2015-02-25 12:21 - 2015-02-25 12:22 - 05611903 _____ (Swearware) C:\Users\Karin\Downloads\ComboFix(1).exe
2015-02-25 12:15 - 2015-02-25 17:51 - 00000000 ____D () C:\Qoobox
2015-02-25 12:15 - 2015-02-25 17:49 - 00000000 ____D () C:\Windows\erdnt
2015-02-25 12:14 - 2015-02-25 13:17 - 05611903 ____R (Swearware) C:\Users\Karin\Downloads\ComboFix.exe
2015-02-25 07:31 - 2015-02-25 07:31 - 00001272 _____ () C:\Users\Karin\Desktop\Revo Uninstaller.lnk
2015-02-25 07:31 - 2015-02-25 07:31 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-25 07:30 - 2015-02-25 07:31 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Karin\Downloads\revosetup95.exe
2015-02-24 22:21 - 2015-02-24 22:21 - 00016853 _____ () C:\Windows\system32\ScanResults.xml
2015-02-24 22:14 - 2015-02-24 22:14 - 00000464 _____ () C:\Windows\system32\ScannerSettings
2015-02-24 17:38 - 2015-02-24 17:38 - 00040993 _____ () C:\Users\Karin\Desktop\Addition.txt
2015-02-24 17:37 - 2015-02-24 17:37 - 00046392 _____ () C:\Users\Karin\Desktop\FRST.txt
2015-02-24 17:24 - 2015-02-24 17:25 - 00040993 _____ () C:\Users\Karin\Downloads\Addition.txt
2015-02-24 17:23 - 2015-02-26 13:58 - 00013830 _____ () C:\Users\Karin\Downloads\FRST.txt
2015-02-24 17:22 - 2015-02-26 13:58 - 00000000 ____D () C:\FRST
2015-02-24 17:22 - 2015-02-26 13:57 - 02087936 _____ (Farbar) C:\Users\Karin\Downloads\FRST64.exe
2015-02-24 17:19 - 2015-02-24 17:20 - 00784872 _____ (Reimage®) C:\Users\Karin\Downloads\ReimageRepair(3).exe
2015-02-24 17:12 - 2015-02-24 17:12 - 00784872 _____ (Reimage®) C:\Users\Karin\Downloads\ReimageRepair(2).exe
2015-02-24 16:58 - 2015-02-24 16:58 - 00000197 _____ () C:\Windows\system32\2015-02-24-15-58-13.081-AvastVBoxSVC.exe-3444.log
2015-02-23 22:09 - 2015-02-23 22:10 - 00000197 _____ () C:\Windows\system32\2015-02-23-21-09-44.005-AvastVBoxSVC.exe-3348.log
2015-02-23 12:10 - 2015-02-23 12:11 - 00000197 _____ () C:\Windows\system32\2015-02-23-11-10-32.063-AvastVBoxSVC.exe-3400.log
2015-02-23 07:25 - 2015-02-23 07:25 - 00000197 _____ () C:\Windows\system32\2015-02-23-06-25-37.005-AvastVBoxSVC.exe-3604.log
2015-02-22 19:34 - 2015-02-22 19:34 - 00000247 _____ () C:\Windows\system32\2015-02-22-18-34-34.005-aswFe.exe-4436.log
2015-02-22 19:25 - 2015-02-22 19:34 - 00000247 _____ () C:\Windows\system32\2015-02-22-18-25-09.075-aswFe.exe-252.log
2015-02-22 19:25 - 2015-02-22 19:25 - 00000197 _____ () C:\Windows\system32\2015-02-22-18-25-07.020-AvastVBoxSVC.exe-3636.log
2015-02-22 18:23 - 2015-02-22 18:23 - 00000000 ____D () C:\Windows\SysWOW64\vbox
2015-02-22 18:23 - 2015-02-22 18:23 - 00000000 ____D () C:\Windows\system32\vbox
2015-02-22 18:23 - 2015-02-22 18:23 - 00000000 ____D () C:\Users\Karin\AppData\Roaming\AVAST Software
2015-02-22 18:23 - 2015-02-22 18:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-02-22 18:22 - 2015-02-26 07:25 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2015-02-22 18:21 - 2015-02-25 21:56 - 00000000 ____D () C:\Program Files (x86)\Google
2015-02-22 18:21 - 2015-02-22 18:22 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2015-02-22 18:21 - 2015-02-22 18:22 - 00087912 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2015-02-22 18:21 - 2015-02-22 18:21 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-02-22 18:21 - 2015-02-22 18:21 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-02-22 18:21 - 2015-02-22 18:21 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2015-02-22 18:21 - 2015-02-22 18:21 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2015-02-22 18:21 - 2015-02-22 18:21 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2015-02-22 18:21 - 2015-02-22 18:21 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2015-02-22 18:21 - 2015-02-22 18:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-02-22 18:21 - 2015-02-22 18:21 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2015-02-22 18:20 - 2015-02-22 18:20 - 00000000 ____D () C:\Program Files\AVAST Software
2015-02-22 18:19 - 2015-02-22 18:20 - 00000000 ____D () C:\ProgramData\AVAST Software
2015-02-22 18:19 - 2015-02-22 18:19 - 04864744 _____ (AVAST Software) C:\Users\Karin\Downloads\avast_free_antivirus_setup_online.exe
2015-02-22 18:15 - 2015-02-26 13:44 - 00000000 ____D () C:\ProgramData\Validity
2015-02-22 18:15 - 2015-02-22 18:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_wbf_vfs_lvcmn_01_09_00.Wdf
2015-02-22 18:05 - 2015-02-24 17:13 - 00000000 ____D () C:\rei
2015-02-22 18:04 - 2015-02-22 18:04 - 00779656 _____ (Reimage®) C:\Users\Karin\Downloads\ReimageRepair(1).exe
2015-02-19 19:24 - 2015-02-19 19:25 - 00852594 _____ () C:\Users\Karin\Downloads\SecurityCheck.exe
2015-02-18 10:13 - 2015-02-26 13:30 - 00000000 ____D () C:\Users\Karin\AppData\Roaming\Imminent
2015-02-12 07:38 - 2015-01-23 05:42 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-02-12 07:38 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-12 07:38 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-02-12 07:38 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-11 18:53 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-11 18:53 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-11 12:35 - 2015-02-04 04:16 - 00894976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-02-11 12:35 - 2015-02-04 04:16 - 00762368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-02-11 12:35 - 2015-02-04 04:16 - 00609280 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-02-11 12:35 - 2015-02-04 04:16 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-02-11 12:35 - 2015-02-04 04:16 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-02-11 12:35 - 2015-02-04 04:16 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-02-11 12:35 - 2015-02-04 04:13 - 01098752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-02-11 12:35 - 2015-01-28 00:36 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2015-02-11 12:35 - 2015-01-14 06:47 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-02-11 12:35 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-02-11 12:35 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-11 12:35 - 2015-01-12 04:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-11 12:35 - 2015-01-12 04:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-02-11 12:35 - 2015-01-12 03:49 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-02-11 12:35 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-11 12:35 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-11 12:35 - 2015-01-12 03:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-02-11 12:35 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-02-11 12:35 - 2015-01-12 03:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-11 12:35 - 2015-01-12 03:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-02-11 12:35 - 2015-01-12 03:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-11 12:35 - 2015-01-12 03:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-11 12:35 - 2015-01-12 03:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-02-11 12:35 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-11 12:35 - 2015-01-12 03:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-02-11 12:35 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-02-11 12:35 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-11 12:35 - 2015-01-12 03:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-02-11 12:35 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-11 12:35 - 2015-01-12 03:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-02-11 12:35 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-11 12:35 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-02-11 12:35 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-02-11 12:35 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-02-11 12:35 - 2015-01-12 03:04 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-11 12:35 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-11 12:35 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-02-11 12:35 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-02-11 12:35 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-02-11 12:35 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-11 12:35 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-11 12:35 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-02-11 12:35 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-11 12:35 - 2015-01-12 02:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-02-11 12:35 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-11 12:35 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-11 12:35 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-02-11 12:35 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-02-11 12:35 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-02-11 12:35 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-02-11 12:35 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-11 12:35 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-11 12:35 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-11 12:35 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-02-11 12:35 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-11 12:35 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-11 12:35 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-02-11 12:35 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-11 12:35 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-11 12:35 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-02-11 12:35 - 2015-01-10 07:48 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-02-11 12:35 - 2015-01-10 07:48 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-02-11 12:35 - 2015-01-10 07:48 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-02-11 12:35 - 2015-01-10 07:48 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-02-11 12:35 - 2015-01-10 07:48 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-02-11 12:35 - 2015-01-10 07:48 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-02-11 12:35 - 2015-01-10 07:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-02-11 12:35 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-02-11 12:35 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-02-11 12:35 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-02-11 12:35 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-02-11 12:35 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-02-11 12:35 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-02-11 12:35 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-02-11 12:34 - 2015-01-15 09:14 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-02-11 12:34 - 2015-01-15 09:14 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-11 12:34 - 2015-01-15 09:09 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-02-11 12:34 - 2015-01-15 09:09 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-02-11 12:34 - 2015-01-15 09:09 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-02-11 12:34 - 2015-01-15 09:09 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-02-11 12:34 - 2015-01-15 09:09 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-02-11 12:34 - 2015-01-15 09:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-02-11 12:34 - 2015-01-15 09:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-02-11 12:34 - 2015-01-15 09:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-02-11 12:34 - 2015-01-15 09:04 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-02-11 12:34 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-02-11 12:34 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-02-11 12:34 - 2015-01-15 08:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-02-11 12:34 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-02-11 12:34 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-02-11 12:34 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-02-11 12:34 - 2015-01-15 05:22 - 00458824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-02-11 12:34 - 2015-01-13 04:10 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-11 12:34 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-11 12:34 - 2014-12-12 06:31 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-02-11 12:34 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2015-02-11 12:32 - 2015-01-14 07:09 - 05554112 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-02-11 12:32 - 2015-01-14 07:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-02-11 12:32 - 2015-01-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-02-11 12:32 - 2015-01-14 07:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-02-11 12:32 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-02-11 12:32 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-02-11 12:32 - 2015-01-14 06:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-02-11 12:32 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-11 12:32 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-11 12:32 - 2014-10-04 03:10 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-02-11 12:32 - 2014-10-04 02:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-02-11 12:32 - 2014-10-04 02:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2015-02-11 12:31 - 2015-01-09 03:03 - 03201536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-10 19:43 - 2015-02-10 19:43 - 00098224 _____ () C:\Users\Karin\Desktop\Pralinenschachtel basteln.htm
2015-02-10 19:43 - 2015-02-10 19:43 - 00000000 ____D () C:\Users\Karin\Desktop\Pralinenschachtel basteln-Dateien
2015-02-09 07:36 - 2015-02-09 07:36 - 00775968 _____ (Reimage®) C:\Users\Karin\Downloads\ReimageRepair.exe
2015-02-06 16:46 - 2015-02-06 16:46 - 00000000 _____ () C:\Windows\SysWOW64\dfvp95.w95
2015-02-06 16:45 - 2015-02-06 16:45 - 00003133 _____ () C:\ST5UNST.LOG
2015-02-06 16:45 - 2015-02-06 16:45 - 00000500 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirtPet.LNK
2015-02-06 16:45 - 1998-04-21 08:19 - 00003816 _____ () C:\VirtPet.DEP
2015-02-06 16:45 - 1998-04-21 08:17 - 00096768 _____ (ISWare) C:\VirtPet.exe
2015-02-06 16:45 - 1998-04-21 08:04 - 00001966 _____ () C:\versions.txt
2015-02-06 16:45 - 1995-07-26 00:00 - 00063488 _____ (MicroHelp, Inc.) C:\Windows\SysWOW64\GAUGE32.OCX
2015-02-03 19:20 - 2015-02-03 20:29 - 00000000 ____D () C:\Program Files (x86)\Farm Frenzy 3 - Madagaskar
2015-02-03 19:20 - 2015-02-03 20:28 - 00000000 ____D () C:\ProgramData\FarmFrenzy3_Madagascar
2015-02-03 19:20 - 2015-02-03 19:20 - 00002093 _____ () C:\Users\Public\Desktop\Spiel Farm Frenzy 3 - Madagaskar.lnk
2015-02-03 19:20 - 2015-02-03 19:20 - 00000000 ____D () C:\Users\Karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Farm Frenzy 3 - Madagaskar
2015-02-03 19:20 - 2015-02-03 19:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Farm Frenzy 3 - Madagaskar
2015-02-03 19:18 - 2015-02-03 19:18 - 00237568 _____ (Big Fish Games) C:\Users\Karin\Downloads\bigfishgames_p88102461_s2_l2.exe
2015-01-27 18:57 - 2015-01-27 18:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-26 13:51 - 2009-07-14 05:45 - 00023568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-26 13:51 - 2009-07-14 05:45 - 00023568 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-26 13:48 - 2009-07-14 18:58 - 00713928 _____ () C:\Windows\system32\perfh007.dat
2015-02-26 13:48 - 2009-07-14 18:58 - 00155726 _____ () C:\Windows\system32\perfc007.dat
2015-02-26 13:48 - 2009-07-14 06:13 - 01659046 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-26 13:46 - 2015-01-21 12:24 - 00000000 ____D () C:\Users\Karin\Desktop\Münzen
2015-02-26 13:44 - 2013-05-19 18:43 - 00120668 _____ () C:\Windows\PFRO.log
2015-02-26 13:44 - 2013-04-28 18:43 - 00126978 _____ () C:\Windows\setupact.log
2015-02-26 13:44 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-26 13:43 - 2012-12-31 12:28 - 01770859 _____ () C:\Windows\WindowsUpdate.log
2015-02-26 13:31 - 2012-12-31 12:25 - 00000000 ____D () C:\Windows\Panther
2015-02-26 13:19 - 2013-01-02 11:00 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-26 12:48 - 2013-01-29 23:34 - 00000000 ____D () C:\ProgramData\TEMP
2015-02-26 12:21 - 2013-01-20 21:20 - 00000000 ____D () C:\Users\Karin\Documents\Outlook-Dateien
2015-02-25 22:39 - 2014-12-30 18:51 - 00000000 ____D () C:\Program Files (x86)\Citrix
2015-02-25 22:33 - 2009-07-14 06:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-02-25 17:48 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-02-25 12:26 - 2013-01-02 10:44 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-02-24 22:21 - 2013-10-13 21:27 - 00022367 _____ () C:\Users\Karin\Desktop\Schulpferde.xlsx
2015-02-22 22:34 - 2013-07-06 08:52 - 00000000 ____D () C:\Users\Karin\Desktop\Aktuelles
2015-02-22 22:34 - 2013-01-02 11:30 - 00000000 ____D () C:\Users\Karin\Desktop\Microsoft Office
2015-02-22 18:49 - 2013-10-06 19:57 - 00000000 ____D () C:\Red Alert 2 Yuri
2015-02-22 18:21 - 2013-07-23 17:54 - 00000000 ____D () C:\Users\Karin\AppData\Local\Google
2015-02-22 18:15 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2015-02-21 16:04 - 2013-01-26 20:43 - 00000000 ____D () C:\Users\Karin\AppData\Local\CrashDumps
2015-02-12 07:44 - 2009-07-14 04:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2015-02-11 23:21 - 2013-01-02 11:28 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-11 18:47 - 2009-07-14 05:45 - 00368368 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-11 18:46 - 2014-12-11 07:29 - 00000000 ____D () C:\Windows\system32\appraiser
2015-02-11 18:46 - 2014-05-06 22:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-02-11 18:43 - 2013-10-18 20:58 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-11 18:42 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini
2015-02-11 12:58 - 2013-10-30 21:52 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-11 12:50 - 2013-10-30 21:52 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-10 18:56 - 2014-05-29 15:22 - 00000000 ____D () C:\Users\Karin\Desktop\VERKAUF
2015-02-05 18:19 - 2013-01-02 11:00 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 18:19 - 2013-01-02 11:00 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-05 18:19 - 2013-01-02 11:00 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-03 20:29 - 2013-07-13 20:20 - 00000000 ____D () C:\BigFishCache
2015-02-01 13:12 - 2013-02-03 19:04 - 00000296 _____ () C:\Windows\Tasks\AppleSoftwareUpdate.job
2015-01-28 12:17 - 2013-01-02 11:05 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2013-10-14 18:59 - 2013-10-14 18:59 - 0000093 _____ () C:\Users\Karin\AppData\Local\fusioncache.dat
Some content of TEMP:
====================
C:\Users\Karin\AppData\Local\Temp\Quarantine.exe
C:\Users\Karin\AppData\Local\Temp\sqlite3.dll
C:\Users\Karin\AppData\Local\Temp\tempmessage.bfg
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-01 15:57
==================== End Of Log ============================ --- --- ---
DANKE! |