| Don Redhorse | 13.04.2015 21:14 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 13.04.2015
Suchlauf-Zeit: 08:38:57
Logdatei: mbam scanlog 13.04.15-09,06 vor quarantäne.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.04.13.03
Rootkit Datenbank: v2015.03.31.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Aktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Gilia
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 351389
Verstrichene Zeit: 23 Min, 17 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 2
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1416, , [a374c2aa26642511cbb66afe986819e7]
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, 1988, , [53c40c60008a55e161f142d1e91910f0]
Module: 2
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, , [d641d399c1c9a78f7df6517d976caf51],
Registrierungsschlüssel: 27
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, , [a374c2aa26642511cbb66afe986819e7],
PUP.Optional.XTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, , [53c40c60008a55e161f142d1e91910f0],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, , [b265dd8f325858dec8aab21c53b056aa],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, , [ac6b95d785057fb78cfd3ed2887c867a],
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, , [2dea5d0fd7b3a1954ecfe1f5bd460ef2],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [31e6bdafb0da9e982aa846fe8d78837d],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\WajIntEnhance, , [8c8b1d4f44466bcb36675674857ed828],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IMBoosterARP, , [f4236705aedc3df9e5987750a162738d],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IminentToolbar, , [20f703693951ad89ccb09d2a897a0bf5],
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Vosteran.com, , [968195d7ff8bda5cd8b5c21435ce1ee2],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WajIntEnhance, , [e73045278703e84eb7c38b3c58ab6b95],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, , [21f6e28a13775dd94944fde65ba87b85],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [0e099bd14b3f63d3b27140992cd7bd43],
PUP.Optional.HomeTab.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\HomeTab, , [ce49b9b3e6a4c86e70b29f56e2219967],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\SearchProtectWS, , [33e4a7c5721847ef4837b1163ac912ee],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\WajIntEnhance, , [b85fdb917b0f53e3a3fb6b5f679c7e82],
PUP.Optional.FastStart.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MOZILLA\EXTENDS, , [24f33834eaa055e16f662cb455ae06fa],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\SIMPLYTECH\HomeTabWajIEnhance, , [51c6600cf09ab38372094285c83b8d73],
Registrierungswerte: 13
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, , [76a1ec806c1e66d0613dec67f60f37c9]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, , [f522f676e1a9b680cdd199ba40c544bc]
PUP.Optional.SearchEngine.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|searchengine@gmail.com, C:\Users\Gilia\AppData\Roaming\Mozilla\Firefox\Profiles\16t7n5gl.default\extensions\searchengine@gmail.com, , [1106c3a9a0ea6dc96f9f71e0cc3936ca]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\Gilia\AppData\Roaming\Mozilla\Firefox\Profiles\16t7n5gl.default\extensions\faststartff@gmail.com, , [27f0fa72ccbef24420d6271cd530748c]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, ima, , [21f6e28a13775dd94944fde65ba87b85]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, , [d2451f4d94f65ed86d300251ba4bde22]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, , [29eee686aae0a78f930a292a28ddf20e]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|FaviconURL, hxxp://www.mystartsearch.com//favicon.ico, , [c750e884ee9c2a0c6a3378dbf0151fe1]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, , [3ed96606e4a62610702d58fb858039c7]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|TopResultURL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, , [45d25e0ebecc6dc956474a09c144d42c]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CEB877DF-3828-48BB-B3E4-6D86F6F39AD5}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, , [789f1458cfbb82b4415c252ef015b14f]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, , [33e446267c0eae88e7b6381b07fec33d]
PUP.Optional.FastStart.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, , [24f33834eaa055e16f662cb455ae06fa]
Registrierungsdaten: 14
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),,[3addcf9d1f6ba88e5bd79f577b8ac53b]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}),,[7d9ae389f59554e2dfcd0beae71e9f61]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),,[10078ddf23672016793337be8283ab55]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),,[5eb955170a805cdac8e47b7a788d9d63]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}),,[0a0da7c5bbcf77bf37757283dd284eb2]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[43d4f9730a80072f7232679a12f47a86]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),,[46d124486624e84ebd75c1353cc96e92]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}),,[6ea94a22b1d91521f8b4a550d3326b95]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),,[6fa8fa720e7cf83ee2ca0ee7986df808]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),,[64b3511b226846f0406c62931bea758b]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}),,[35e22d3f7f0b47ef5f4df302fb0a7b85]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[a3746a020b7f2c0a53517a87e323ea16]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),,[bc5bbeae5d2db68046673cb951b4639d]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),,[fc1bf7750288bd794b62827349bc7090]
Ordner: 31
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\image, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [ec2b23495b2f3ef8fa69d3ca5fa4a15f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, , [ec2b23495b2f3ef8fa69d3ca5fa4a15f],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, , [e0374f1d84068caaa6543f7412f1738d],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, , [e0374f1d84068caaa6543f7412f1738d],
Dateien: 80
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, , [a374c2aa26642511cbb66afe986819e7],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, , [53c40c60008a55e161f142d1e91910f0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\XTab\SupTab.dll, , [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchCH.dll, , [978090dc3357c076a8015e11dd2318e8],
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchFF.dll, , [49ce105ca0ea8da94366333c8080cd33],
PUP.Optional.SearchProtect, C:\Program Files (x86)\XTab\BrowserAction.dll, , [3add89e35832a78f37a79ca7f80a619f],
PUP.Optional.ELEX, C:\Program Files (x86)\XTab\HPNotify.exe, , [85922d3f9cee59dd81c8e54f5ea4f010],
PUP.Optional.OpenCandy, C:\Users\Gilia\Downloads\MediaInfo_GUI_0.7.72_Windows.exe, , [c5529ad2dfab46f0e24784a448bee21e],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\uninstall.exe, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\conf, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ffsearch_toolbar!1.0.0.1025.xpi, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\IeWatchDog.dll, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\install.data, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\searchProvider.xml, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about_bk.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn_apply.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\close.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf.xml, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf_back.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\input_bk.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\logo.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\main.xml, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_1.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_2.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\rigth_arrow.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\settings.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\data.html, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE.html, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE8.html, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\main.css, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\ver.txt, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\arrow.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo_hover.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_logo.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo2.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\google_trends.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon128.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon16.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon48.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\loading.gif, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\logo32.ico, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather\0.png, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\common.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ga.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ie8.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery-1.11.0.min.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery.autocomplete.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\js.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\library.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit-ie8.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit2.0.js, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW\messages.json, , [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, , [ec2b23495b2f3ef8fa69d3ca5fa4a15f],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update\conf, , [e0374f1d84068caaa6543f7412f1738d],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 13.04.2015
Suchlauf-Zeit: 08:38:57
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.04.13.03
Rootkit Datenbank: v2015.03.31.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Aktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Gilia
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 351389
Verstrichene Zeit: 23 Min, 17 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 2
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1416, Löschen bei Neustart, [a374c2aa26642511cbb66afe986819e7]
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, 1988, Löschen bei Neustart, [53c40c60008a55e161f142d1e91910f0]
Module: 2
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [d641d399c1c9a78f7df6517d976caf51],
Registrierungsschlüssel: 27
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [a374c2aa26642511cbb66afe986819e7],
PUP.Optional.XTab.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IHProtect Service, In Quarantäne, [53c40c60008a55e161f142d1e91910f0],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, In Quarantäne, [b265dd8f325858dec8aab21c53b056aa],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [ac6b95d785057fb78cfd3ed2887c867a],
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, In Quarantäne, [2dea5d0fd7b3a1954ecfe1f5bd460ef2],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [31e6bdafb0da9e982aa846fe8d78837d],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\WajIntEnhance, In Quarantäne, [8c8b1d4f44466bcb36675674857ed828],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IMBoosterARP, In Quarantäne, [f4236705aedc3df9e5987750a162738d],
PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\IminentToolbar, In Quarantäne, [20f703693951ad89ccb09d2a897a0bf5],
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Vosteran.com, In Quarantäne, [968195d7ff8bda5cd8b5c21435ce1ee2],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WajIntEnhance, In Quarantäne, [e73045278703e84eb7c38b3c58ab6b95],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [21f6e28a13775dd94944fde65ba87b85],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [0e099bd14b3f63d3b27140992cd7bd43],
PUP.Optional.HomeTab.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\HomeTab, In Quarantäne, [ce49b9b3e6a4c86e70b29f56e2219967],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\SearchProtectWS, In Quarantäne, [33e4a7c5721847ef4837b1163ac912ee],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\WajIntEnhance, In Quarantäne, [b85fdb917b0f53e3a3fb6b5f679c7e82],
PUP.Optional.FastStart.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [24f33834eaa055e16f662cb455ae06fa],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\SIMPLYTECH\HomeTabWajIEnhance, In Quarantäne, [51c6600cf09ab38372094285c83b8d73],
Registrierungswerte: 13
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, In Quarantäne, [76a1ec806c1e66d0613dec67f60f37c9]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, In Quarantäne, [f522f676e1a9b680cdd199ba40c544bc]
PUP.Optional.SearchEngine.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|searchengine@gmail.com, C:\Users\Gilia\AppData\Roaming\Mozilla\Firefox\Profiles\16t7n5gl.default\extensions\searchengine@gmail.com, In Quarantäne, [1106c3a9a0ea6dc96f9f71e0cc3936ca]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\Gilia\AppData\Roaming\Mozilla\Firefox\Profiles\16t7n5gl.default\extensions\faststartff@gmail.com, In Quarantäne, [27f0fa72ccbef24420d6271cd530748c]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, ima, In Quarantäne, [21f6e28a13775dd94944fde65ba87b85]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, In Quarantäne, [d2451f4d94f65ed86d300251ba4bde22]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, In Quarantäne, [29eee686aae0a78f930a292a28ddf20e]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|FaviconURL, hxxp://www.mystartsearch.com//favicon.ico, In Quarantäne, [c750e884ee9c2a0c6a3378dbf0151fe1]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, In Quarantäne, [3ed96606e4a62610702d58fb858039c7]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|TopResultURL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, In Quarantäne, [45d25e0ebecc6dc956474a09c144d42c]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{CEB877DF-3828-48BB-B3E4-6D86F6F39AD5}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, In Quarantäne, [789f1458cfbb82b4415c252ef015b14f]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=ima&utm_campaign=install_ie&utm_content=ds&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&ts=1424601161&type=default&q={searchTerms}, In Quarantäne, [33e446267c0eae88e7b6381b07fec33d]
PUP.Optional.FastStart.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [24f33834eaa055e16f662cb455ae06fa]
Registrierungsdaten: 14
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),Ersetzt,[3addcf9d1f6ba88e5bd79f577b8ac53b]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}),Ersetzt,[7d9ae389f59554e2dfcd0beae71e9f61]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),Ersetzt,[10078ddf23672016793337be8283ab55]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),Ersetzt,[5eb955170a805cdac8e47b7a788d9d63]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}),Ersetzt,[0a0da7c5bbcf77bf37757283dd284eb2]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[43d4f9730a80072f7232679a12f47a86]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),Ersetzt,[46d124486624e84ebd75c1353cc96e92]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}),Ersetzt,[6ea94a22b1d91521f8b4a550d3326b95]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),Ersetzt,[6fa8fa720e7cf83ee2ca0ee7986df808]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),Ersetzt,[64b3511b226846f0406c62931bea758b]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW&q={searchTerms}),Ersetzt,[35e22d3f7f0b47ef5f4df302fb0a7b85]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[a3746a020b7f2c0a53517a87e323ea16]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),Ersetzt,[bc5bbeae5d2db68046673cb951b4639d]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-1773740722-1353712620-2879442739-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1424601085&from=ima&uid=ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW),Ersetzt,[fc1bf7750288bd794b62827349bc7090]
Ordner: 31
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab, Löschen bei Neustart, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\image, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [ec2b23495b2f3ef8fa69d3ca5fa4a15f],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [ec2b23495b2f3ef8fa69d3ca5fa4a15f],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, In Quarantäne, [e0374f1d84068caaa6543f7412f1738d],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, In Quarantäne, [e0374f1d84068caaa6543f7412f1738d],
Dateien: 80
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [a374c2aa26642511cbb66afe986819e7],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ProtectService.exe, Löschen bei Neustart, [53c40c60008a55e161f142d1e91910f0],
PUP.Optional.SupTab.A, C:\Program Files (x86)\XTab\SupTab.dll, In Quarantäne, [29eeee7eb9d156e0247ebc8323e0659b],
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchCH.dll, In Quarantäne, [978090dc3357c076a8015e11dd2318e8],
PUP.Optional.BrowserWatch, C:\Program Files (x86)\XTab\BrowerWatchFF.dll, In Quarantäne, [49ce105ca0ea8da94366333c8080cd33],
PUP.Optional.SearchProtect, C:\Program Files (x86)\XTab\BrowserAction.dll, In Quarantäne, [3add89e35832a78f37a79ca7f80a619f],
PUP.Optional.ELEX, C:\Program Files (x86)\XTab\HPNotify.exe, In Quarantäne, [85922d3f9cee59dd81c8e54f5ea4f010],
PUP.Optional.OpenCandy, C:\Users\Gilia\Downloads\MediaInfo_GUI_0.7.72_Windows.exe, In Quarantäne, [c5529ad2dfab46f0e24784a448bee21e],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\uninstall.exe, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\CmdShell.exe, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\conf, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\ffsearch_toolbar!1.0.0.1025.xpi, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\IeWatchDog.dll, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\install.data, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcp110.dll, Löschen bei Neustart, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\msvcr110.dll, Löschen bei Neustart, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\searchProvider.xml, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\about_bk.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\btn_apply.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\close.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf.xml, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\conf_back.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\input_bk.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\logo.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\main.xml, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_1.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\radio_2.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\rigth_arrow.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\skin\settings.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\data.html, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE.html, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\indexIE8.html, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\main.css, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\ver.txt, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\arrow.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_add_logo_hover.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\default_logo.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\googlelogo2.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\google_trends.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon128.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon16.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\icon48.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\loading.gif, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\logo32.ico, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\img\weather\0.png, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\common.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ga.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\ie8.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\jquery.autocomplete.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\js.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\library.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit-ie8.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\js\xagainit2.0.js, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\en-US\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-419\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\es-ES\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-BE\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CA\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-CH\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-FR\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\fr-LU\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-CH\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\it-IT\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pl\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\pt-BR\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\ru-MO\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\tr-TR\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\vi-VI\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-CN\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.XTab.A, C:\Program Files (x86)\XTab\web\_locales\zh-TW\messages.json, In Quarantäne, [d641d399c1c9a78f7df6517d976caf51],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [ec2b23495b2f3ef8fa69d3ca5fa4a15f],
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update\conf, In Quarantäne, [e0374f1d84068caaa6543f7412f1738d],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
# AdwCleaner v4.201 - Bericht erstellt 13/04/2015 um 09:17:45
# Aktualisiert 08/04/2015 von Xplode
# Datenbank : 2015-04-08.1 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : Gilia - IDEAPAD
# Gestarted von : C:\Users\Gilia\Desktop\AdwCleaner_4.201.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : 0200621426811956mcinstcleanup
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\baidu
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniLyrics
Ordner Gelöscht : C:\Program Files (x86)\MiniLyrics
Ordner Gelöscht : C:\Users\Gilia\AppData\Local\pokki
Ordner Gelöscht : C:\Users\Gilia\AppData\Roaming\MiniLyrics
Datei Gelöscht : C:\Users\Gilia\AppData\Roaming\Mozilla\Firefox\Profiles\16t7n5gl.default\user.js
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4580AB54-3C2F-4970-9A77-8628FA182F03}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{46B5EE7F-3B6B-4079-A756-5EFC10B1F50B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{4580AB54-3C2F-4970-9A77-8628FA182F03}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{46B5EE7F-3B6B-4079-A756-5EFC10B1F50B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\simplytech
Schlüssel Gelöscht : HKCU\Software\MiniLyrics
Schlüssel Gelöscht : HKLM\SOFTWARE\AskPartnerNetwork
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Myfree Codec
Schlüssel Gelöscht : HKLM\SOFTWARE\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\SupDp
Schlüssel Gelöscht : HKLM\SOFTWARE\SpeedBit
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MiniLyrics
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v37.0.1 (x86 de)
[16t7n5gl.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.alias", "mystartsearch");
[16t7n5gl.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.searchengine.name", "mystartsearch");
[16t7n5gl.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "mystartsearch");
[16t7n5gl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.nosquint.sites", "sparkasse-fuerth.de=0,1428724977858,27,140,0,0,false,0,0,false primeshare.tv=0,1428259780654,29,90,0,0,false,0,0,false blog.de=0,1422758869741,1,160,0,0,false,0[...]
[16t7n5gl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.enable_search1", false);
[16t7n5gl.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.quick_start.sd.closeWindowWithLastTab_prev_state", false);
*************************
AdwCleaner[R0].txt - [10376 Bytes] - [13/04/2015 07:14:44]
AdwCleaner[R1].txt - [4270 Bytes] - [13/04/2015 09:15:23]
AdwCleaner[S0].txt - [3971 Bytes] - [13/04/2015 09:17:45]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4030 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.3 (04.07.2015:1)
OS: Windows 8.1 x64
Ran by Gilia on 13.04.2015 at 9:32:00,68
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
~~~ Files
Successfully deleted: [File] C:\WINDOWS\prefetch\MINILYRICS.EXE-AACDB03E.pf
Successfully deleted: [File] C:\WINDOWS\prefetch\ASKPIP_FF_.EXE-663D9C10.pf
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"
~~~ FireFox
Successfully deleted the following from C:\Users\Gilia\AppData\Roaming\mozilla\firefox\profiles\16t7n5gl.default\prefs.js
user_pref("browser.search.searchengine.desc", "this is my first firefox searchEngine");
user_pref("browser.search.searchengine.ptid", "ima");
user_pref("browser.search.searchengine.uid", "ST1000LM014-SSHD-8GB_W382D5WWXXXXW382D5WW");
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.04.2015 at 9:34:19,96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Shortcut Cleaner 1.3.5 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/
Windows Version: Windows 8.1
Program started at: 04/13/2015 09:36:17 AM.
Scanning for registry hijacks:
* No issues found in the Registry.
Searching for Hijacked Shortcuts:
Searching C:\Users\Gilia\AppData\Roaming\Microsoft\Windows\Start Menu\
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
Searching C:\Users\Gilia\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
Searching C:\Users\Public\Desktop\
Searching C:\Users\Gilia\Desktop
0 bad shortcuts found.
Program finished at: 04/13/2015 09:36:17 AM
Execution time: 0 hours(s), 0 minute(s), and 0 seconds(s) Code:
ESETSmartInstaller@High as downloader log:
all ok
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=a2cdcb5bb6c17f4ea2bd9b5c4728364f
# engine=23349
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-04-13 10:30:59
# local_time=2015-04-13 12:30:59 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='McAfee Anti-Virus * Anti-Spyware'
# compatibility_mode=5130 16777214 100 94 2893107 28986645 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 2776224 10311447 0 0
# scanned=442517
# found=0
# cleaned=0
# scan_time=7598 Da ich nicht sicher war ob ich das mit OTH beim ersten Mal richtig gemacht habe hier noch einmal ein mbam.txt-logfile.Erzeugt nach der Anleitung "MyStartSearch.com Virus entfernen" in Verbindung mit "OTH - OTHelper - Kill All Processes"
Danke! Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 13.04.2015
Suchlauf-Zeit: 21:18:56
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.04.13.07
Rootkit Datenbank: v2015.03.31.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Aktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Gilia
Suchlauf-Art: Hyper-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 285083
Verstrichene Zeit: 1 Min, 55 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Deaktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Warnen
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 0
(Keine schädliche Elemente gefunden)
Dateien: 0
(Keine schädliche Elemente gefunden)
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) So endlich geschafft, puuh! Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 13.04.2015
Suchlauf-Zeit: 21:18:56
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.04.13.07
Rootkit Datenbank: v2015.03.31.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Aktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Gilia
Suchlauf-Art: Hyper-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 285083
Verstrichene Zeit: 1 Min, 55 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Deaktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Warnen
PUM: Warnen
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 0
(Keine schädliche Elemente gefunden)
Dateien: 0
(Keine schädliche Elemente gefunden)
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) |