Habe bei Google einfach "Chrome" eingegeben und den ersten Link genommen, welcher laut Google direkt vom Anbieter, also Google, kommt.
Hier nochmal der Link:
hxxp://www.softwarede.net/chrome/
Die frischen FRST Logs kommen sobald ich alles durchlaufen lassen habe.
hier der Malwarebyte log Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 05.04.2015
Suchlauf-Zeit: 21:27:04
Logdatei:
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.03.09.05
Rootkit Datenbank: v2015.03.31.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Andrej
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 329131
Verstrichene Zeit: 8 Min, 54 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.LolliScan.A, C:\ProgramData\LolliScan\LolliScan.exe, 1828, Löschen bei Neustart, [f980fb48a6e430067438c4e660a36799]
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 33
PUP.Optional.LolliScan.A, HKLM\SOFTWARE\LolliScan, In Quarantäne, [bebb0a39424871c5eebfcae06f94b44c],
PUP.Optional.ICinema.A, HKLM\SOFTWARE\WOW6432NODE\I - Cinema-nv, In Quarantäne, [3544014207830c2a1abb8a3e887b7e82],
PUP.Optional.ICinema.A, HKLM\SOFTWARE\WOW6432NODE\I - Cinema-nv-ie, In Quarantäne, [ef8a55ee8a00c07626af933557acff01],
PUP.Optional.LolliScan.A, HKLM\SOFTWARE\WOW6432NODE\LolliScan, In Quarantäne, [a6d3b88b781255e14b623b6fa2617b85],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\WajIntEnhance, In Quarantäne, [ea8f340fb5d52d096165129a50b37c84],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [caafcd76a0eaf93d0c88ff2e6c991fe1],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [27523d06becc1323a6ef1e0f9273f709],
PUP.Optional.cherimoya.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\cherimoya, In Quarantäne, [eb8e370ce7a31f171314b2fd996a8080],
PUP.Optional.LolliScan.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\LolliScan, In Quarantäne, [f980fb48a6e430067438c4e660a36799],
PUP.Optional.Shopperz.A, HKU\S-1-5-18\SOFTWARE\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}, In Quarantäne, [25540b3890fa55e1c62d5a4abf449b65],
PUP.Optional.Shopperz.A, HKU\S-1-5-19\SOFTWARE\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}, In Quarantäne, [d2a7ca79f8925cda22d1daca9172d927],
PUP.Optional.Shopperz.A, HKU\S-1-5-20\SOFTWARE\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}, In Quarantäne, [c6b35be81f6be254688b1f850cf7c33d],
PUP.Optional.HomeTab.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\HomeTab, In Quarantäne, [b5c4ec57751590a639070ccd30d350b0],
PUP.Optional.ICinema.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\I - Cinema-nv, In Quarantäne, [2b4ef74cf2982313dafaf2d6fe05a65a],
PUP.Optional.ICinema.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\I - Cinema-nv-ie, In Quarantäne, [a9d0a2a1533700362ea6e9dfee15837d],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\SearchProtectWS, In Quarantäne, [80f92023375349edb8d52d7c649f22de],
PUP.Optional.TNT.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\TNT2, In Quarantäne, [691060e333571d19c0ae01aacf34d12f],
PUP.Optional.Wajam.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\WajIntEnhance, In Quarantäne, [1f5a152e06846fc702c5c1ebe51e5ba5],
PUP.Optional.Shopperz.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}, In Quarantäne, [79004bf8137777bf80733173a85b3dc3],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [3a3f2b18701a25111c1c63bcbb4a15eb],
PUP.Optional.MultiIE.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, In Quarantäne, [f980063d573339fdf05edf498a7b946c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\25257, In Quarantäne, [e297370c1e6c3006f9c2e6dca75cdf21],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\iCinema, In Quarantäne, [ccadce75385242f457a4e8c103007d83],
PUP.Optional.Qone8, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [4e2b99aabcced264415d17fff01515eb],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IMBoosterARP, In Quarantäne, [b5c44102fc8eb3832948168f010211ef],
PUP.Optional.Iminent.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IminentToolbar, In Quarantäne, [bdbc79ca1773f73f3b3762434bb816ea],
PUP.Optional.Linkey.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Linkey, In Quarantäne, [067399aa4347fc3a6e05fbaacf341be5],
PUP.Optional.Vosteran.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Vosteran.com, In Quarantäne, [da9fa69d0f7b53e3e88c9e078a792fd1],
PUP.Optional.Wajam.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WajIntEnhance, In Quarantäne, [9adfab98bcce5cda2e478d18699a738d],
PUP.Optional.Wajam.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\SIMPLYTECH\HomeTabWajIEnhance, In Quarantäne, [2b4ec87b008aa690f395dacfae55eb15],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.LolliScan.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\LolliScan, In Quarantäne, [f48523200a805dd96bf4d7cac043dd23],
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 14
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1428252179&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1428252179&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063),Ersetzt,[05749ea5ee9c7db9b70552846a9bc040]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.istartsurf.com/web/?type=dspp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=dspp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063&q={searchTerms}),Ersetzt,[fb7e52f198f2171fd6400dc8af56a957]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063),Ersetzt,[3e3bae95e3a756e0b066815442c348b8]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063),Ersetzt,[7aff8cb73159fb3b8c8ad7fe9b6a53ad]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.istartsurf.com/web/?type=dspp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=dspp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063&q={searchTerms}),Ersetzt,[94e5ec571f6b1a1c5db9eaeb58ad14ec]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[34452e15e8a2ac8a9802b62b3cc9ea16]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1428252179&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.istartsurf.com/?type=sc&ts=1428252179&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063),Ersetzt,[0f6ad86bcac020163a82a43213f2ac54]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.istartsurf.com/web/?type=dspp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=dspp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063&q={searchTerms}),Ersetzt,[1d5c4df65f2b7db90a0cd5008085966a]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063),Ersetzt,[dd9ce65d83077eb823f3884dc63fe51b]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063),Ersetzt,[b4c51132ff8be84e8e8803d2cc39e31d]
PUP.Optional.IStartSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.istartsurf.com/web/?type=dspp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/web/?type=dspp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063&q={searchTerms}),Ersetzt,[4732f64d54366acc0f078d4838cda957]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[4a2fd86b4f3b75c19a0018c93bca837d]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063),Ersetzt,[ccad68db9eec45f140d4ab2ae81dbd43]
PUP.Optional.IStartSurf.A, HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063, Gut: (www.google.com), Schlecht: (hxxp://www.istartsurf.com/?type=hppp&ts=1428252213&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063),Ersetzt,[4138b58e6822be7826eefbda58ad9f61]
Ordner: 17
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\userCode, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\icons, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\icons\actions, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\api, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\popupResource, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dimfohdigjaffdaanhmbocfkpolglnjk, In Quarantäne, [f7825ae93b4fc86e431518834db69b65],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_dimfohdigjaffdaanhmbocfkpolglnjk_0, In Quarantäne, [f78284bf9ceec076b0a9108b31d241bf],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz, In Quarantäne, [116851f2e7a3a78ff471712b3ec530d0],
PUP.Optional.LolliScan.A, C:\ProgramData\LolliScan, Löschen bei Neustart, [f48523200a805dd96bf4d7cac043dd23],
Dateien: 127
PUP.Optional.ZombieInvasion.A, C:\ProgramData\VoCsJmHm\dat\FCHoDYP.exe, In Quarantäne, [4633142f0288082ed8daf4db34cd6b95],
PUP.Optional.Somoto, C:\Users\Andrej\AppData\Local\Temp\bitool.dll, In Quarantäne, [87f2182b6c1ee056120d86c6f30f06fa],
PUP.Optional.IStartsurf.A, C:\Users\Andrej\AppData\Local\Temp\56e74239-bfb6-45fb-9e14-bd0b75774ae0\lly_istartsurf.exe, In Quarantäne, [6d0cd66d4a40a88e9a3c938712f4f709],
PUP.Optional.Clara.A, C:\Users\Andrej\AppData\Local\Temp\614f417c-7cca-46e3-b5b0-836a7a585f0c\unicobrowser.exe, In Quarantäne, [6e0bfc4725650b2b2eddce0f04fd2cd4],
PUP.Optional.CrossRider, C:\Users\Andrej\AppData\Local\Temp\DwlTempFolder\temp.exe, In Quarantäne, [0d6c02413c4e30063f346b7342bfb54b],
PUP.Optional.Tikotin.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_tikotin.com_0.localstorage, In Quarantäne, [8aef54efc4c666d0278a228433d0e61a],
PUP.Optional.Tikotin.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_tikotin.com_0.localstorage-journal, In Quarantäne, [47320043a6e4df57ffb222844db649b7],
PUP.Optional.ReMarkable.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, In Quarantäne, [2f4af54eaae0132388209e91d92cda26],
PUP.Optional.ReMarkable.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, In Quarantäne, [c8b18fb4f09a31054f594de2b94cdd23],
PUP.Optional.Vitruvian.A, C:\Users\Andrej\AppData\Local\Temp\vitruvian-installer-hardwareprofile-v0001, In Quarantäne, [2c4d77cc5b2fa78fcd240b288283fe02],
PUP.Optional.Vitruvian.A, C:\Users\Andrej\AppData\Local\Temp\vitruvian-installer-install-v0003, In Quarantäne, [11686ed5444695a1a948e84b43c2936d],
PUP.Optional.Vitruvian.A, C:\Users\Andrej\AppData\Local\Temp\vitruvian-installer-processes-v0002, In Quarantäne, [c2b7bc87bad037ff01f00e2516efd030],
PUP.Optional.Vitruvian.A, C:\Users\Andrej\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, In Quarantäne, [54253e056228eb4b3eb3290a699cb848],
PUP.Optional.Vitruvian.A, C:\Users\Andrej\AppData\Local\Temp\vitruvian-installer-softwareregkeys-v0002, In Quarantäne, [6d0c46fd0f7b8fa7fef3cc67a3624db3],
PUP.Optional.Vitruvian.A, C:\Users\Andrej\AppData\Local\Temp\vitruvian-installer-uninstall-v0002, In Quarantäne, [c0b9340f86041224866bd65d83821ee2],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dimfohdigjaffdaanhmbocfkpolglnjk_0.localstorage, In Quarantäne, [0475e45f672324126f5c64d0c93ca060],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_dimfohdigjaffdaanhmbocfkpolglnjk_0.localstorage-journal, In Quarantäne, [c8b1e45fa7e387af5378211347bee917],
PUP.Optional.LolliScan.A, C:\ProgramData\LolliScan\LolliScan.exe, Löschen bei Neustart, [f980fb48a6e430067438c4e660a36799],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\GoogleCrashHandler.exe, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\GoogleUpdate.exe, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\GoogleUpdateBroker.exe, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\GoogleUpdateHelper.msi, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\GoogleUpdateOnDemand.exe, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\goopdate.dll, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\goopdateres_en.dll, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\npGoogleUpdate4.dll, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\psmachine.dll, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.1299\psuser.dll, In Quarantäne, [58217fc47d0d84b24e3b88fa44bf4fb1],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\GoogleCrashHandler.exe, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\GoogleUpdate.exe, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\GoogleUpdateBroker.exe, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\GoogleUpdateHelper.msi, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\GoogleUpdateOnDemand.exe, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\goopdate.dll, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\goopdateres_en.dll, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\npGoogleUpdate4.dll, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\psmachine.dll, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.GlobalUpdate.A, C:\Users\Andrej\AppData\Local\Temp\comh.426243\psuser.dll, In Quarantäne, [91e8b78c7d0d3df98dfcbfc3e61daa56],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\background.html, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\chromeCoreFilesIndex.txt, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\manifest.json, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\popup.html, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\Settings.json, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\manifest.xml, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins.json, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\102.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\13.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\14.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\17.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\180.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\19.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\192.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\195.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\200.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\220.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\223.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\246.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\253.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\273.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\281.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\288.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\289.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\334.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\337.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\339.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\345.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\354.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\376.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\378.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\380.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\390.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\391.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\4.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\47.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\64.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\7.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\78.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\80.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\9.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\91.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\93.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\plugins\97.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\userCode\background.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\extensionData\userCode\extension.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\icons\icon128.png, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\icons\icon16.png, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\icons\icon48.png, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\icons\actions\1.png, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\5c6d74ad8d6c675e108170c4b4967513.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\e856e462b48330363603acd2cb73c07c.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\main.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\api\2db143a60f843918d2ab0e4f1ce91f75.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\api\3e3c870593816680231334457962535b.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\api\851abc427a2551f6fc6d58d788effbc6.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\api\d33a25ddf0d98e8f5500d5b4481c96a6.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\api\e9d9e4372c8d69de9514666454594f0e.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\api\pageAction.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\app_api.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\04d832e5acc89ad15104440e01fbffcf.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\579d66af5f4555bf4cd511ba8b5c4caa.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\6063e9a31223b1f3fb21677d25bea90e.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\704577eb69a97a11c3281a8df5b5513b.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\74808c3225ec7be48d87814f4bee39a6.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\85869ec0d13752660a17918f7a74e99f.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\8ea0f9ad513674f2d2c935e358e6039f.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\98e89fe41475555fca52aae6a246cea0.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\bf70aa0fbb5167b67e65a3edf7e5b803.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\c4d6575b0a2fc8a3840a67c28aa833d5.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\d53fe739f8aaaf950ba15f9ed3d1d309.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\df8c2785a9e7d445194bbe683d9411c3.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\ea8addb4f3d50a6c291246899d593b6f.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\fd522e2206fb881a61e8ece8338aa774.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\installer.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\popupResource\newPopup.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\dimfohdigjaffdaanhmbocfkpolglnjk\1.26.125_0\js\lib\popupResource\popup.js, In Quarantäne, [94e5b58e1179013558ffbfdc679c5fa1],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dimfohdigjaffdaanhmbocfkpolglnjk\000003.ldb, In Quarantäne, [f7825ae93b4fc86e431518834db69b65],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dimfohdigjaffdaanhmbocfkpolglnjk\000019.log, In Quarantäne, [f7825ae93b4fc86e431518834db69b65],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dimfohdigjaffdaanhmbocfkpolglnjk\CURRENT, In Quarantäne, [f7825ae93b4fc86e431518834db69b65],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dimfohdigjaffdaanhmbocfkpolglnjk\LOCK, In Quarantäne, [f7825ae93b4fc86e431518834db69b65],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dimfohdigjaffdaanhmbocfkpolglnjk\LOG, In Quarantäne, [f7825ae93b4fc86e431518834db69b65],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dimfohdigjaffdaanhmbocfkpolglnjk\LOG.old, In Quarantäne, [f7825ae93b4fc86e431518834db69b65],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dimfohdigjaffdaanhmbocfkpolglnjk\MANIFEST-000001, In Quarantäne, [f7825ae93b4fc86e431518834db69b65],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_dimfohdigjaffdaanhmbocfkpolglnjk_0\1, In Quarantäne, [f78284bf9ceec076b0a9108b31d241bf],
PUP.Optional.CrossRider.A, C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\databases\chrome-extension_dimfohdigjaffdaanhmbocfkpolglnjk_0\1-journal, In Quarantäne, [f78284bf9ceec076b0a9108b31d241bf],
PUP.Optional.Shopperz.A, C:\Program Files\shopperz\krios.dll, In Quarantäne, [116851f2e7a3a78ff471712b3ec530d0],
PUP.Optional.LolliScan.A, C:\ProgramData\LolliScan\RfndNSIS.dll, In Quarantäne, [f48523200a805dd96bf4d7cac043dd23],
PUP.Optional.LolliScan.A, C:\ProgramData\LolliScan\SoftConfigTest.exe, In Quarantäne, [f48523200a805dd96bf4d7cac043dd23],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) AdwCleaner hat sich selbst beendet nach einem Fehler, hoffe die Logs sind dennoch aussagekräftig Code:
# AdwCleaner v4.200 - Bericht erstellt 05/04/2015 um 21:49:26
# Aktualisiert 29/03/2015 von Xplode
# Datenbank : 2015-03-29.1 [Server]
# Betriebssystem : Windows 8.1 Pro (x64)
# Benutzername : Andrej - ARBEITSZIMMERPC
# Gestarted von : C:\Users\Andrej\Downloads\AdwCleaner_4.200.exe
# Option : Suchlauf
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\istartsurf.com
Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.istartsurf.com
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Google Chrome v41.0.2272.118
[C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.istartsurf.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=SAMSUNGXHD502IJ_S13TJ1BQ701063&ts=1428252222&type=default&q={searchTerms}
*************************
AdwCleaner[R0].txt - [6047 Bytes] - [05/04/2015 21:47:12]
AdwCleaner[R1].txt - [1201 Bytes] - [05/04/2015 21:49:26]
AdwCleaner[S0].txt - [4343 Bytes] - [05/04/2015 21:48:23]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [1319 Bytes] ########## Hier der JRT log Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.1 (04.02.2015:1)
OS: Windows 8.1 Pro x64
Ran by Andrej on 05.04.2015 at 21:54:34,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.04.2015 at 21:56:35,86
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und nun die frischen FRST logs:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Andrej (administrator) on ARBEITSZIMMERPC on 05-04-2015 22:00:27
Running from C:\Users\Andrej\Downloads
Loaded Profiles: Andrej (Available profiles: Andrej)
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [704512 2015-03-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\...\Run: [UnicoBrowser] => C:\Users\Andrej\AppData\Local\UnicoBrowser\Application\unicobrowser.exe [1047176 2015-03-18] (The Unico Browser Authors)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKU\S-1-5-21-3514346005-4174202986-2708488565-1004 -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll No File
FF HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\...\Firefox\Extensions: [{BAA61DC0-942D-610B-9B47-565AFC929BBD}] - C:\Program Files (x86)\version90SpeedChecker\191.xpi
Chrome:
=======
CHR Profile: C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Adblock Plus) - C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-05]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-05]
CHR Extension: (Google Wallet) - C:\Users\Andrej\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-04-05]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-17] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
S2 cysofehu; C:\Users\Andrej\AppData\Local\E423A3A0-1428260358-11D5-A383-50465D8E03F5\insp7214.tmp [156672 2015-04-05] () [File not signed]
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026432 2015-04-05] (Enigma Software Group USA, LLC.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
S2 xyhigysy; C:\Users\Andrej\AppData\Roaming\E423A3A0-1428252381-11D5-A383-50465D8E03F5\jnsfFFB4.tmp [151552 2015-04-05] () [File not signed]
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 wodugide; C:\Users\Andrej\AppData\Roaming\E423A3A0-1428252381-11D5-A383-50465D8E03F5\nswCF19.tmpfs [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132120 2015-03-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2015-03-17] (Avira Operations GmbH & Co. KG)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-04-05] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-03-17] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] ()
S3 RecFltr; C:\Windows\system32\drivers\RecFltr.sys [45440 2007-01-18] ()
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-05 22:00 - 2015-04-05 22:00 - 02095616 _____ (Farbar) C:\Users\Andrej\Downloads\FRST64.exe
2015-04-05 22:00 - 2015-04-05 22:00 - 00007517 _____ () C:\Users\Andrej\Downloads\FRST.txt
2015-04-05 21:56 - 2015-04-05 21:56 - 00000619 _____ () C:\Users\Andrej\Desktop\JRT.txt
2015-04-05 21:54 - 2015-04-05 21:54 - 02690981 _____ (Thisisu) C:\Users\Andrej\Downloads\JRT.exe
2015-04-05 21:49 - 2015-04-05 21:49 - 02208768 _____ () C:\Users\Andrej\Downloads\AdwCleaner_4.200.exe
2015-04-05 21:46 - 2015-04-05 21:49 - 00000000 ____D () C:\AdwCleaner
2015-04-05 21:26 - 2015-04-05 21:44 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-05 21:26 - 2015-04-05 21:26 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-05 21:26 - 2015-04-05 21:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-05 21:26 - 2015-04-05 21:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-05 21:26 - 2015-04-05 21:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-04-05 21:26 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-05 21:26 - 2015-03-17 06:15 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-05 21:26 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-05 21:25 - 2015-04-05 21:25 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-ARBEITSZIMMERPC-Windows-8.1-Pro-(64-bit).dat
2015-04-05 21:25 - 2015-04-05 21:25 - 00000000 ____D () C:\RegBackup
2015-04-05 21:21 - 2015-04-05 21:21 - 00001284 _____ () C:\Users\Andrej\Desktop\Revo Uninstaller.lnk
2015-04-05 21:21 - 2015-04-05 21:21 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-04-05 20:23 - 2015-04-05 22:00 - 00000000 ____D () C:\FRST
2015-04-05 20:12 - 2015-04-05 20:12 - 00000000 _____ () C:\autoexec.bat
2015-04-05 20:11 - 2015-04-05 20:11 - 00003344 _____ () C:\Windows\System32\Tasks\SpyHunter4Startup
2015-04-05 20:11 - 2015-04-05 20:11 - 00001103 _____ () C:\Users\Andrej\Desktop\SpyHunter.lnk
2015-04-05 20:11 - 2015-04-05 20:11 - 00000000 ____D () C:\Users\Andrej\AppData\Roaming\Enigma Software Group
2015-04-05 20:10 - 2015-04-05 20:11 - 00000000 ____D () C:\sh4ldr
2015-04-05 20:07 - 2015-04-05 20:07 - 00022704 _____ () C:\Windows\system32\Drivers\EsgScanner.sys
2015-04-05 20:07 - 2015-04-05 20:07 - 00000000 ____D () C:\Program Files\Enigma Software Group
2015-04-05 19:59 - 2015-04-05 19:59 - 00000000 ____D () C:\Windows\system32\appmgmt
2015-04-05 19:22 - 2015-04-05 19:22 - 00008192 __RSH () C:\BOOTSECT.BAK
2015-04-05 19:22 - 2015-04-05 19:22 - 00000004 _____ () C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-04-05 19:22 - 2015-04-05 19:22 - 00000000 _____ () C:\Windows\system32\atiicdxx.dat
2015-04-05 19:22 - 2015-04-05 19:22 - 00000000 _____ () C:\Windows\ativpsrm.bin
2015-04-05 19:19 - 2015-04-05 19:15 - 00613255 _____ (CMI Limited) C:\Users\Andrej\AppData\Local\nsn3574.tmp
2015-04-05 19:03 - 2015-04-05 19:03 - 00001270 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2015-04-05 19:03 - 2015-04-05 19:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft
2015-04-05 19:03 - 2015-04-05 18:58 - 00043576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-04-05 19:00 - 2015-04-05 19:02 - 00008592 _____ () C:\Windows\SysWOW64\VCLOff.ini
2015-04-05 19:00 - 2015-04-05 19:02 - 00008592 _____ () C:\Windows\system32\VCLOff.ini
2015-04-05 18:59 - 2015-04-05 18:59 - 00000000 ____D () C:\Users\Andrej\AppData\Local\E423A3A0-1428260358-11D5-A383-50465D8E03F5
2015-04-05 18:58 - 2015-04-05 18:58 - 00001153 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-04-05 18:58 - 2015-04-05 18:58 - 00000000 ____D () C:\Users\Andrej\AppData\Roaming\Avira
2015-04-05 18:58 - 2015-04-05 18:58 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-05 18:57 - 2015-04-05 18:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-05 18:57 - 2015-04-05 18:57 - 00002086 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2015-04-05 18:56 - 2015-04-05 18:58 - 00000000 ____D () C:\ProgramData\Avira
2015-04-05 18:56 - 2015-04-05 18:58 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-04-05 18:56 - 2015-03-17 13:01 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-04-05 18:56 - 2015-03-17 13:01 - 00128536 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-04-05 18:56 - 2015-03-17 13:01 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-04-05 18:53 - 2015-04-05 21:28 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2015-04-05 18:52 - 2015-04-05 18:55 - 165283560 _____ () C:\Users\Andrej\Downloads\avira_free_antivirus_de_15.0.9.504.exe
2015-04-05 18:51 - 2015-04-05 21:35 - 00000000 ____D () C:\Users\Andrej\AppData\Local\Battle.net
2015-04-05 18:51 - 2015-04-05 18:52 - 00000000 ____D () C:\Users\Andrej\AppData\Roaming\Battle.net
2015-04-05 18:51 - 2015-04-05 18:51 - 00001160 _____ () C:\Users\Public\Desktop\Battle.net.lnk
2015-04-05 18:51 - 2015-04-05 18:51 - 00000000 ____D () C:\Users\Andrej\AppData\Local\Blizzard Entertainment
2015-04-05 18:51 - 2015-04-05 18:51 - 00000000 ____D () C:\ProgramData\VoCsJmHm
2015-04-05 18:51 - 2015-04-05 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-04-05 18:51 - 2015-04-05 18:51 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2015-04-05 18:51 - 2015-04-05 18:51 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2015-04-05 18:50 - 2015-04-05 18:50 - 00000000 ____D () C:\ProgramData\Battle.net
2015-04-05 18:49 - 2015-04-05 19:57 - 00000000 ____D () C:\Users\Andrej\AppData\Local\E423A3A0-1428259796-11D5-A383-50465D8E03F5
2015-04-05 18:49 - 2015-04-05 18:49 - 02908728 _____ (Blizzard Entertainment) C:\Users\Andrej\Downloads\World-of-Warcraft-Setup-enGB.exe
2015-04-05 18:47 - 2015-04-05 18:47 - 00000000 ____D () C:\Users\Andrej\AppData\Local\E423A3A0-1428259641-11D5-A383-50465D8E03F5
2015-04-05 18:46 - 2015-04-05 19:59 - 00000000 ____D () C:\ProgramData\Skype
2015-04-05 18:46 - 2015-04-05 19:58 - 00000000 ____D () C:\Users\Andrej\AppData\Roaming\Opera Software
2015-04-05 18:46 - 2015-04-05 19:58 - 00000000 ____D () C:\Users\Andrej\AppData\Local\Opera Software
2015-04-05 18:46 - 2015-04-05 19:54 - 00000000 ____D () C:\Users\Andrej\AppData\Roaming\Skype
2015-04-05 18:46 - 2015-04-05 19:10 - 00000000 ____D () C:\Users\Andrej\AppData\Roaming\E423A3A0-1428252381-11D5-A383-50465D8E03F5
2015-04-05 18:46 - 2015-04-05 18:46 - 00000000 ____D () C:\Users\Andrej\AppData\Local\Skype
2015-04-05 18:45 - 2015-04-05 18:51 - 00000000 ___HD () C:\Users\Public\Temp
2015-04-05 18:45 - 2015-04-05 18:45 - 00000045 _____ () C:\user.js
2015-04-05 18:44 - 2015-04-05 21:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-04-05 18:43 - 2015-04-05 21:43 - 00001720 _____ () C:\Windows\Tasks\CKPYXOR.job
2015-04-05 18:43 - 2015-04-05 18:43 - 00004742 _____ () C:\Windows\System32\Tasks\CKPYXOR
2015-04-05 18:43 - 2015-04-05 18:43 - 00003182 _____ () C:\Windows\System32\Tasks\Run_Browser
2015-04-05 18:43 - 2015-04-05 18:43 - 00000000 ____D () C:\Users\Andrej\AppData\Local\UnicoBrowser
2015-04-05 18:42 - 2015-04-05 21:52 - 00001150 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-05 18:42 - 2015-04-05 21:43 - 00001146 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-05 18:42 - 2015-04-05 18:47 - 00004122 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-04-05 18:42 - 2015-04-05 18:47 - 00003886 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-04-05 18:42 - 2015-04-05 18:44 - 00000000 ____D () C:\Users\Andrej\AppData\Local\Google
2015-04-05 18:42 - 2015-04-05 18:43 - 00008558 _____ () C:\claraInstaller.txt
2015-04-05 18:42 - 2015-04-05 18:42 - 00003576 _____ () C:\Windows\System32\Tasks\VZZXGN
2015-04-05 18:42 - 2015-04-05 18:42 - 00000000 ____D () C:\ProgramData\7b2a98c5c3a9485689cfb0f9c7e387ba
2015-04-05 18:42 - 2015-04-05 18:42 - 00000000 ____D () C:\ProgramData\4d0801eee76440b5aa8e9e9bd8f25f47
2015-04-05 18:40 - 2015-04-05 22:00 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3514346005-4174202986-2708488565-1004
2015-04-05 18:40 - 2015-04-05 21:49 - 00000000 ____D () C:\Users\Andrej\OneDrive
2015-04-05 18:40 - 2015-04-05 18:40 - 00003962 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{F3627B61-9F12-40DD-9141-4559DE26043D}
2015-04-05 18:40 - 2015-04-05 18:40 - 00000000 __SHD () C:\Users\Andrej\AppData\Local\EmieUserList
2015-04-05 18:40 - 2015-04-05 18:40 - 00000000 __SHD () C:\Users\Andrej\AppData\Local\EmieSiteList
2015-04-05 18:40 - 2015-04-05 18:40 - 00000000 __SHD () C:\Users\Andrej\AppData\Local\EmieBrowserModeList
2015-04-05 18:40 - 2015-04-05 18:40 - 00000000 ____D () C:\Users\Andrej\AppData\Roaming\Macromedia
2015-04-05 18:35 - 2015-04-05 18:35 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2015-04-05 18:34 - 2015-04-05 21:48 - 00001009 _____ () C:\Users\Andrej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-04-05 18:34 - 2015-04-05 21:48 - 00000000 ____D () C:\Users\Andrej
2015-04-05 18:34 - 2015-04-05 18:37 - 00000000 ____D () C:\Users\Andrej\AppData\Local\Packages
2015-04-05 18:34 - 2015-04-05 18:34 - 00000020 ___SH () C:\Users\Andrej\ntuser.ini
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\Vorlagen
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\Startmenü
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\Netzwerkumgebung
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\Lokale Einstellungen
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\Eigene Dateien
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\Druckumgebung
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\Documents\Eigene Musik
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\Documents\Eigene Bilder
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\AppData\Local\Verlauf
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\AppData\Local\Anwendungsdaten
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 _SHDL () C:\Users\Andrej\Anwendungsdaten
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 ____D () C:\Users\Andrej\AppData\Roaming\Adobe
2015-04-05 18:34 - 2015-04-05 18:34 - 00000000 ____D () C:\Users\Andrej\AppData\Local\VirtualStore
2015-04-05 18:34 - 2015-02-04 12:20 - 00000000 ___RD () C:\Users\Andrej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-04-05 18:34 - 2015-02-04 12:20 - 00000000 ___RD () C:\Users\Andrej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-04-05 18:34 - 2014-03-18 12:12 - 00000369 _____ () C:\Users\Andrej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-04-05 18:34 - 2014-03-18 12:12 - 00000369 _____ () C:\Users\Andrej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-04-05 18:34 - 2014-01-12 07:50 - 00015360 _____ () C:\Windows\system32\SppExtComObjHook.dll
2015-04-05 18:34 - 2014-01-12 07:50 - 00004608 _____ () C:\Windows\system32\SppExtComObjPatcher.exe
2015-04-05 18:34 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Andrej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-04-05 18:34 - 2013-08-22 17:36 - 00000000 ____D () C:\Users\Andrej\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-04-05 18:30 - 2015-04-05 18:30 - 00000000 ____D () C:\Windows\CSC
2015-04-05 18:25 - 2015-04-05 21:57 - 00423290 _____ () C:\Windows\WindowsUpdate.log
2015-04-05 18:24 - 2015-04-05 18:24 - 00002302 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3514346005-4174202986-2708488565-500
2015-03-26 21:14 - 2015-03-26 21:14 - 00005542 _____ () C:\Users\Andrej\AppData\Roaming\CKPYXOR
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-05 22:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2015-04-05 21:42 - 2014-03-18 12:04 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-05 21:42 - 2014-03-18 11:25 - 00764340 _____ () C:\Windows\system32\perfh007.dat
2015-04-05 21:42 - 2014-03-18 11:25 - 00159160 _____ () C:\Windows\system32\perfc007.dat
2015-04-05 21:38 - 2014-03-18 03:51 - 00284480 _____ () C:\Windows\PFRO.log
2015-04-05 21:38 - 2013-08-22 16:46 - 00023927 _____ () C:\Windows\setupact.log
2015-04-05 21:38 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-05 19:58 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\restore
2015-04-05 19:51 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-04-05 19:22 - 2013-08-22 17:36 - 00262144 _____ () C:\Windows\system32\config\BCD-Template
2015-04-05 18:46 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-04-05 18:35 - 2015-02-04 11:22 - 00000000 ____D () C:\Windows\Panther
2015-04-05 18:34 - 2013-08-22 16:45 - 00000000 ____D () C:\Windows\Setup
2015-04-05 18:27 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2015-04-05 18:25 - 2015-02-04 11:24 - 00000000 __SHD () C:\Recovery
2015-04-05 18:25 - 2013-08-22 17:37 - 00003843 _____ () C:\Windows\DtcInstall.log
2015-04-05 18:25 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\Recovery
==================== Files in the root of some directories =======
2015-03-26 21:14 - 2015-03-26 21:14 - 0005542 _____ () C:\Users\Andrej\AppData\Roaming\CKPYXOR
2015-04-05 19:19 - 2015-04-05 19:15 - 0613255 _____ (CMI Limited) C:\Users\Andrej\AppData\Local\nsn3574.tmp
Some content of TEMP:
====================
C:\Users\Andrej\AppData\Local\Temp\079CD119-532D-6D75-1C2F-618037BEB765.dll
C:\Users\Andrej\AppData\Local\Temp\079CD119-532D-6D75-1C2F-618037BEB765.exe
C:\Users\Andrej\AppData\Local\Temp\avgnt.exe
C:\Users\Andrej\AppData\Local\Temp\SpOrder.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-04 11:22
==================== End Of Log ============================ --- --- ---
--- --- ---
Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-03-2015
Ran by Andrej at 2015-04-05 22:00:57
Running from C:\Users\Andrej\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avira Desktop (Disabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Disabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Avira (HKLM-x32\...\{bd538030-07d4-4999-a525-7fafa2483f56}) (Version: 1.1.30.21727 - Avira Operations & Co. KG)
Avira (x32 Version: 1.1.30.21727 - Avira Operations & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 15.0.8.656 - Avira)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.118 - Google Inc.)
Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden
Malwarebytes Anti-Malware Version 2.1.4.1018 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SpyHunter 4 (HKLM-x32\...\SpyHunter) (Version: 4.19.13.4482 - Enigma Software Group, LLC)
StartIsBack+ (HKLM-x32\...\StartIsBack) (Version: 1.7 - startisback.com)
WinRAR 5.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
==================== Restore Points =========================
05-04-2015 19:58:58 Removed Skype™ 7.3
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {123B1F1C-C733-499C-98C9-4D91A38EA1A9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-12-31] (Microsoft Corporation)
Task: {318490EE-CB23-4E0D-B229-968F6AF2271E} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcTrigger
Task: {38265361-082F-42B9-9F36-DEDAFF300947} - \Optimize Start Menu Cache Files-S-1-5-21-3514346005-4174202986-2708488565-1001 No Task File <==== ATTENTION
Task: {3A1A3F55-79A7-442D-8950-93F073AC25D2} - System32\Tasks\CKPYXOR => C:\Users\Andrej\AppData\Roaming\CKPYXOR.exe <==== ATTENTION
Task: {3FD166F2-AF13-4A5D-A455-9F151F8C33C8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {51043B06-2D44-4E2B-ABF1-36B39F07F1A2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: {54A81083-ED65-4750-9488-CBF7C762C895} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-04-05] (Enigma Software Group USA, LLC.)
Task: {BC569234-24DE-48B9-86AB-1D431153796F} - System32\Tasks\Run_Browser => C:\Users\Andrej\AppData\Local\UnicoBrowser\Application\unicobrowser.exe [2015-03-18] (The Unico Browser Authors)
Task: {DBBEE193-2B8B-4DBA-8E2E-1D24458E45AA} - System32\Tasks\VZZXGN => C:\ProgramData\4d0801eee76440b5aa8e9e9bd8f25f47\4d0801eee76440b5aa8e9e9bd8f25f47.exe [2015-04-02] ()
Task: C:\Windows\Tasks\CKPYXOR.job => C:\Users\Andrej\AppData\Roaming\CKPYXOR.exe <==== ATTENTION
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) ==============
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
AlternateDataStreams: C:\Users\Andrej\OneDrive:ms-properties
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VCL => ""="service"
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3514346005-4174202986-2708488565-1004\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-3514346005-4174202986-2708488565-500 - Administrator - Disabled)
Andrej (S-1-5-21-3514346005-4174202986-2708488565-1004 - Administrator - Enabled) => C:\Users\Andrej
Gast (S-1-5-21-3514346005-4174202986-2708488565-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3514346005-4174202986-2708488565-1003 - Limited - Enabled)
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
System errors:
=============
Error: (04/05/2015 10:00:41 PM) (Source: DCOM) (EventID: 10010) (User: ARBEITSZIMMERPC)
Description: {9AA46009-3CE0-458A-A354-715610A075E6}
Error: (04/05/2015 10:00:11 PM) (Source: DCOM) (EventID: 10010) (User: ARBEITSZIMMERPC)
Description: {9AA46009-3CE0-458A-A354-715610A075E6}
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Processor: AMD FX(tm)-4100 Quad-Core Processor
Percentage of memory in use: 19%
Total physical RAM: 6126.11 MB
Available physical RAM: 4946.03 MB
Total Pagefile: 7790.11 MB
Available Pagefile: 6407.58 MB
Total Virtual: 131072 MB
Available Virtual: 131071.83 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:98.57 GB) (Free:62.42 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: () (Fixed) (Total:367.19 GB) (Free:365.83 GB) NTFS
Drive i: (win64byDEB) (CDROM) (Total:3.83 GB) (Free:0 GB) UDF
Drive j: () (Removable) (Total:7.5 GB) (Free:7.26 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 871C871C)
Partition 1: (Active) - (Size=98.6 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=367.2 GB) - (Type=07 NTFS)
========================================================
Disk: 5 (MBR Code: Windows 7 or 8) (Size: 7.5 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
==================== End Of Log ============================ |