Danke für deine schnelle Hilfe.
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.06.2014
Suchlauf-Zeit: 18:39:05
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.03.05
Rootkit Datenbank: v2014.06.02.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: kebin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 309763
Verstrichene Zeit: 2 Std, 44 Min, 49 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 6
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarantäne, [3dd4a7cd6714ed49d6149f9950b2d32d],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [3dd4a7cd6714ed49d6149f9950b2d32d],
PUP.Optional.Zwangi, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{47AE1BA9-0BD1-44F4-88AE-45F8F7B605EF}, Löschen bei Neustart, [020f21531e5d4fe7e540b588758d06fa],
PUP.Optional.PlusHD.A, HKLM\SOFTWARE\Plus-HD-4.5, In Quarantäne, [37da7df7d7a47cba4a65b204bd454ab6],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Löschen bei Neustart, [eb26b5bf3d3e71c53934d509ed1648b8],
PUP.Optional.FilesFrog.A, HKU\S-1-5-21-3919152501-1714073753-3578707811-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BI, Löschen bei Neustart, [7c95571ddc9f0d292058953a000321df],
Registrierungswerte: 8
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [db3680f4bbc09f97e90fb88131d1e818],
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, C:\Program Files\V-bates\Firefox, In Quarantäne, [db3680f4bbc09f97e90fb88131d1e818]
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, C:\Program Files\V-bates\Firefox, In Quarantäne, [db3680f4bbc09f97e90fb88131d1e818]
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [e42d373d304bde581edac6736c969a66],
PUP.BProtector, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, hxxp://www1.delta-search.com/?babsrc=HP_ss&mntrId=D2636C626D8AF7C3&affID=120517&tt=160713_9127&tsp=4945, Löschen bei Neustart, [0b06c6ae9fdc181ea82818b1986be917]
PUP.BProtector, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Löschen bei Neustart, [ef226c08b8c3092defe29039838043bd]
PUP.Optional.Wajam.A, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}, C:\Program Files\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi, Löschen bei Neustart, [a869d59fc4b7e452372e4851dd258f71]
PUP.Optional.FilesFrog.A, HKU\S-1-5-21-3919152501-1714073753-3578707811-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BI|ui_path_filesfrog, HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker, Löschen bei Neustart, [7c95571ddc9f0d292058953a000321df]
Registrierungsdaten: 10
PUP.Optional.Qvo6.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=WDCXWD15EARS-00MVWB0_WD-WMAZA083549035490&ts=1373373982, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=WDCXWD15EARS-00MVWB0_WD-WMAZA083549035490&ts=1373373982),Ersetzt,[49c8b0c4cab154e28685bfa96d97926e]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=WDCXWD15EARS-00MVWB0_WD-WMAZA083549035490&ts=1373376527, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=WDCXWD15EARS-00MVWB0_WD-WMAZA083549035490&ts=1373376527),Ersetzt,[f0219fd5f3889c9a24ee6502ab5948b8]
Hijack.StartPage, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=WDCXWD15EARS-00MVWB0_WD-WMAZA083549035490&ts=1373376527, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=WDCXWD15EARS-00MVWB0_WD-WMAZA083549035490&ts=1373376527),Ersetzt,[52bfd4a05c1fad89e729481f887c7987]
PUP.Optional.SnapDo.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970),Ersetzt,[18f921537803072ff881fe5faf5519e7]
PUP.Optional.Snapdo, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970),Löschen bei Neustart,[6da41a5a1f5cc3733ea1442234d053ad]
PUP.Optional.Snapdo, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970),Löschen bei Neustart,[5eb3f381f08b989e9d411b4b30d443bd]
Hijack.StartPage, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=WDCXWD15EARS-00MVWB0_WD-WMAZA083549035490&ts=1373376527, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.qvo6.com/?utm_source=b&utm_medium=vtt&from=vtt&uid=WDCXWD15EARS-00MVWB0_WD-WMAZA083549035490&ts=1373376527),Löschen bei Neustart,[e22f353f245765d1e52c3235fe062dd3]
PUP.Optional.Snapdo, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970),Löschen bei Neustart,[ad64db99a9d287af04dd85e107fd3bc5]
PUP.Optional.Snapdo, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970),Löschen bei Neustart,[947d056f017a3bfb6b772d39cb3926da]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-3919152501-1714073753-3578707811-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970),Löschen bei Neustart,[7998571dbfbc092d3b3f8ecfa36126da]
Ordner: 18
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Temp\ct3288691, In Quarantäne, [2be6f57fd3a8c27400e4522e7b87b54b],
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Temp\ct3297265, In Quarantäne, [5eb33341631845f140a4433d966c38c8],
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Temp\ct3297861, In Quarantäne, [f1206b094c2fb581ba2a651bc83a55ab],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Local\Updater21058, In Quarantäne, [4dc45f15ec8f9e98ee6e7310ba48837d],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\defaults, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\defaults\preferences, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\userCode, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\locale, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\locale\en-US, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-4.5, In Quarantäne, [35dccba94a31dc5ae96807804eb4bb45],
Dateien: 139
PUP.Optional.E7, C:\Users\kebin\AppData\Roaming\eIntaller\24A49A9502EA478b890445B08B958055\Desk365.exe, In Quarantäne, [cb4681f38eed8aac3669db430cf455ab],
PUP.Optional.E7, C:\Users\kebin\AppData\Roaming\eIntaller\A27FA4BE44DE4315AC0ECEF4B05FF221\Desk365.exe, In Quarantäne, [b25fb9bbe59694a29c03ce50837d4cb4],
PUP.Optional.SearchProtect.A, C:\Users\kebin\AppData\Local\Temp\nsk196A.exe, In Quarantäne, [20f1d0a493e8f44243b09d8dc0410af6],
PUP.Optional.SearchProtect.A, C:\Users\kebin\AppData\Local\Temp\nsk1F36.exe, In Quarantäne, [dd34096b17643204ad465bcf58a9a65a],
PUP.Optional.SearchProtect.A, C:\Users\kebin\AppData\Local\Temp\nskE4B0.exe, In Quarantäne, [37dafa7a16659c9a53a045e5669b26da],
PUP.Optional.SearchProtect.A, C:\Users\kebin\AppData\Local\Temp\nspE210.exe, In Quarantäne, [3bd60b697803ce685e95e644e918946c],
PUP.Optional.SearchProtect.A, C:\Users\kebin\AppData\Local\Temp\nstBEE7.exe, In Quarantäne, [a8693f357ffc62d4589b7ab00cf59b65],
PUP.Optional.SearchProtect.A, C:\Users\kebin\AppData\Local\Temp\nsu1C67.exe, In Quarantäne, [809173013a419d99ca298aa0c33e9868],
PUP.Optional.SearchProtect.A, C:\Users\kebin\AppData\Local\Temp\nszDF41.exe, In Quarantäne, [9e73e490cab1979f1fd48d9dd52c30d0],
PUP.Optional.VBates.A, C:\Users\kebin\AppData\Local\Temp\v-bates.exe, In Quarantäne, [b65b096b780362d47a109aabef11ed13],
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Temp\nszAA3C\SpSetup.exe, In Quarantäne, [7c955420b1cae45207dc53cc14ed25db],
PUP.Optional.Superfish.A, C:\Users\kebin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, In Quarantäne, [fd14e68ee398fd3936d3cecd1ee4a957],
PUP.Optional.Superfish.A, C:\Users\kebin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [6da48ee63942e0562ddc4b50c0421ce4],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot.exe, In Quarantäne, [cb46571de7940f27de0ef8d2729118e8],
PUP.Optional.BProtector.A, C:\Users\kebin\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences, In Quarantäne, [937e6113b6c551e537f24e7fe71cbd43],
PUP.Optional.PricePeep.A, C:\Users\kebin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_licjnkifamhpbaefhdpacpmihicfbomb_0.localstorage, In Quarantäne, [61b0cca8d0abcd698bb8d0182fd45ea2],
PUP.Optional.PricePeep.A, C:\Users\kebin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_licjnkifamhpbaefhdpacpmihicfbomb_0.localstorage-journal, In Quarantäne, [957c581c5625ed49a0a32abefb08956b],
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Temp\ct3288691\chromeid.txt, In Quarantäne, [2be6f57fd3a8c27400e4522e7b87b54b],
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Temp\ct3288691\setup.ini.txt, In Quarantäne, [2be6f57fd3a8c27400e4522e7b87b54b],
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Temp\ct3297265\ism.exe, In Quarantäne, [5eb33341631845f140a4433d966c38c8],
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Temp\ct3297861\chromeid.txt, In Quarantäne, [f1206b094c2fb581ba2a651bc83a55ab],
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Temp\ct3297861\setup.ini.txt, In Quarantäne, [f1206b094c2fb581ba2a651bc83a55ab],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome.manifest, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\install.rdf, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\background.html, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\baseObject.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\browser.xul, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\dialog.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\ffCoreFilesIndex.txt, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\main.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\options.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\options.xul, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\platformVersion.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\search_dialog.xul, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\asyncDB.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\background.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\browserAction.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\contextMenu.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\dbManager.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\dom_bg.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\fileManager.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\firefox.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\firefoxNotifications.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\firefoxOmnibox.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\message.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\pageAction.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\request.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\tabs.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\webRequest.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\api\windowsMessagingHandler.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\addressBarChangeObserver.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\console.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\consts.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\delegate.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\extensionDataStore.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\folderIOWrapper.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\httpObserver.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\IDBWrapper.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\installer.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\logFile.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\prefs.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\progressListenerObserver.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\registry.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\reloadObserver.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\reports.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\requestObject.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\searchSettings.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\uninstallObserver.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\updateManager.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\utils.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\chrome\content\core\xhr.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\defaults\preferences\prefs.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\manifest.xml, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins.json, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\207.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\1.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\102.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\103.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\104.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\119.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\123.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\13.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\14.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\158.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\16.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\17.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\177.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\178.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\179.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\180.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\182.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\183.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\184.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\190.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\195.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\21.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\217.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\22.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\220.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\221.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\223.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\226.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\242.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\246.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\28.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\4.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\47.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\64.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\7.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\72.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\78.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\9.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\91.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\93.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\plugins\98.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\userCode\background.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\extensionData\userCode\extension.js, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\locale\en-US\translations.dtd, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\button1.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\button2.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\button3.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\button4.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\button5.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\crossrider_statusbar.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\icon128.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\icon16.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\icon24.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\icon48.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\panelarrow-up.png, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\popup.html, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\skin.css, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\extensions\a892fa08-2d07-49e8-adce-f650222629ca@82592752-c212-4885-b999-cb2a1d2f9d09.com\skin\update.css, In Quarantäne, [45cce09493e8e84ee71e572f48ba0af6],
PUP.Optional.PlusHD.A, C:\Program Files\Plus-HD-4.5\39678.xpi, In Quarantäne, [35dccba94a31dc5ae96807804eb4bb45],
PUP.Optional.Snapdo.A, C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: (,"homepage": "hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=hp&installDate=01/01/1970","homepage_is_newtabpage": false), Ersetzt,[41d0551fbac10234c35e7c1806fe6c94]
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://search.conduit.com/?ctid=CT3311268&SearchSource=48&CUI=UN29504919652995354&UM=2&UP=SP227CA280-2830-4C9A-BC80-F19CEDB88F74&SSPV=",), Ersetzt,[de33d79d6e0d74c230de1b7af90b55ab]
PUP.Optional.CrossRider.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "1418316622e2637b4c9a4508775cbe3c");), Ersetzt,[7c9583f1611a4aec601ceea6ab5905fb]
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3311268&SearchSource=2&CUI=UN38072101937782320&UM=2&q=");), Ersetzt,[98793b39d7a40f27a23a148063a1a55b]
PUP.Optional.Conduit.A, C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3311268&CUI=UN38072101937782320&UM=2&SearchSource=3&q={searchTerms}");), Ersetzt,[bc5502726219d165549d256f40c443bd]
Physische Sektoren: 0
(No malicious items detected)
(end) ---------------------
AdwCleaner.txt Code:
# AdwCleaner v3.211 - Bericht erstellt am 03/06/2014 um 21:37:04
# Aktualisiert 26/05/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : kebin - KEBIN-PC
# Gestartet von : C:\Users\kebin\Desktop\adwcleaner_3.211.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Tarma Installer
Ordner Gelöscht : C:\Program Files\Omiga Plus
Ordner Gelöscht : C:\Program Files\Uninstaller
Ordner Gelöscht : C:\Program Files\V-bates
Ordner Gelöscht : C:\Program Files\WinZipper
Ordner Gelöscht : C:\Users\kebin\AppData\Local\PutLockerDownloader
Ordner Gelöscht : C:\Users\kebin\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\kebin\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\kebin\AppData\LocalLow\Delta
Ordner Gelöscht : C:\Users\kebin\AppData\Roaming\337
Ordner Gelöscht : C:\Users\kebin\AppData\Roaming\eIntaller
Ordner Gelöscht : C:\Users\kebin\AppData\Roaming\ExpressFiles
Ordner Gelöscht : C:\Users\kebin\AppData\Roaming\Omiga Plus
Ordner Gelöscht : C:\Users\kebin\AppData\Roaming\WinZipper
Ordner Gelöscht : C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\CT3311268
Ordner Gelöscht : C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\Extensions\{da7f5ae1-3be3-43c0-8098-c1d183616e97}
Ordner Gelöscht : C:\Users\Gast.kebin-PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljmibnagodajacnnbifpamhggcohblip
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
Datei Gelöscht : C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\user.js
Datei Gelöscht : C:\Windows\Tasks\Dealply.job
Datei Gelöscht : C:\Windows\System32\Tasks\Dealply
Datei Gelöscht : C:\Windows\System32\Tasks\Desk 365 RunAsStdUser
Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
Verknüpfung Desinfiziert : C:\Users\kebin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11428800-BABD-4EC0-8DF7-F9B0014941F9}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11428800-BABD-4EC0-8DF7-F9B0014941F9}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D06FACCC-0160-487B-B897-151B08EF4CEC}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D06FACCC-0160-487B-B897-151B08EF4CEC}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{82AEEE4E-A795-4597-BD04-EABC0A8FF318}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{82AEEE4E-A795-4597-BD04-EABC0A8FF318}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ACDACEA7-2EE0-4613-8F30-114192EB9520}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ACDACEA7-2EE0-4613-8F30-114192EB9520}
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WMHelper.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dealplylive.exe
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\DeskSvc
Schlüssel Gelöscht : HKCU\Software\f4d8dae73fb946
Schlüssel Gelöscht : HKLM\SOFTWARE\f4d8dae73fb946
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3311268
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{A7DDCBDE-5C86-415C-8A37-763AE183E7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\ExpressFiles
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\powerpack
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software
Schlüssel Gelöscht : HKLM\Software\Desksvc
Schlüssel Gelöscht : HKLM\Software\ExpressFiles
Schlüssel Gelöscht : HKLM\Software\hdcode
Schlüssel Gelöscht : HKLM\Software\Software
Schlüssel Gelöscht : HKLM\Software\Tarma Installer
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ]
[ Datei : C:\Users\kebin\AppData\Roaming\Mozilla\Firefox\Profiles\olbrdq18.default\prefs.js ]
Zeile gelöscht : user_pref("CT3311268.FF19Solved", "true");
Zeile gelöscht : user_pref("CT3311268.UserID", "UN38072101937782320");
Zeile gelöscht : user_pref("CT3311268.browser.search.defaultthis.engineName", "true");
Zeile gelöscht : user_pref("CT3311268.fullUserID", "UN38072101937782320.IN.20130927212443");
Zeile gelöscht : user_pref("CT3311268.installDate", "27/09/2013 21:24:50");
Zeile gelöscht : user_pref("CT3311268.installSessionId", "{191DD0B7-8CC8-486F-92AF-07A25DA7B4F0}");
Zeile gelöscht : user_pref("CT3311268.installSp", "false");
Zeile gelöscht : user_pref("CT3311268.installerVersion", "1.7.1.4");
Zeile gelöscht : user_pref("CT3311268.keyword", "true");
Zeile gelöscht : user_pref("CT3311268.originalHomepage", "about:home");
Zeile gelöscht : user_pref("CT3311268.originalSearchAddressUrl", "");
Zeile gelöscht : user_pref("CT3311268.originalSearchEngine", "");
Zeile gelöscht : user_pref("CT3311268.originalSearchEngineName", "");
Zeile gelöscht : user_pref("CT3311268.searchRevert", "true");
Zeile gelöscht : user_pref("CT3311268.searchUserMode", "2");
Zeile gelöscht : user_pref("CT3311268.smartbar.homepage", "true");
Zeile gelöscht : user_pref("CT3311268.versionFromInstaller", "10.20.1.8");
Zeile gelöscht : user_pref("CT3311268.xpeMode", "0");
Zeile gelöscht : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "");
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Conduit Search");
Zeile gelöscht : user_pref("browser.search.defaultthis.engineName", "WhiteSmoke New V6 Customized Web Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Conduit Search");
Zeile gelöscht : user_pref("extensions.aa892fa082d0749e8adcef650222629ca82592752c2124885b999cb2a1d2f9d09com39678.39678.internaldb.cache/3518e1eac042730aa1274618984462b3_DE.value", "%22var%20cat_3518e1eac042730aa127461[...]
Zeile gelöscht : user_pref("extensions.aa892fa082d0749e8adcef650222629ca82592752c2124885b999cb2a1d2f9d09com39678.39678.internaldb.cache/5cdf8a7ef2ec84abac286c67587b78d9.value", "%22function%20tcmMarkWindow%28a%29%7Bva[...]
Zeile gelöscht : user_pref("extensions.aa892fa082d0749e8adcef650222629ca82592752c2124885b999cb2a1d2f9d09com39678.39678.internaldb.cache/d5baae4ef839769f8eb7e9f9d82d8a40_DE.value", "%22var%20cat_d5baae4ef839769f8eb7e9f[...]
Zeile gelöscht : user_pref("smartbar.addressBarOwnerCTID", "CT3311268");
Zeile gelöscht : user_pref("smartbar.conduitHomepageList", "hxxp://search.conduit.com/?ctid=CT3311268&CUI=UN38072101937782320&UM=2&SearchSource=13");
Zeile gelöscht : user_pref("smartbar.conduitSearchAddressUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3311268&SearchSource=2&CUI=UN38072101937782320&UM=2&q=");
Zeile gelöscht : user_pref("smartbar.defaultSearchOwnerCTID", "CT3311268");
Zeile gelöscht : user_pref("smartbar.homePageOwnerCTID", "CT3311268");
Zeile gelöscht : user_pref("smartbar.machineId", "KBVU9/UPX+4MGX6MKJ+YUECUQP866N/S2DSUQA019M5UH9ACGQBMQZUDEGDTRO+QCVKJ/RW+LOD3FX+CWTLVNA");
-\\ Google Chrome v35.0.1916.114
[ Datei : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://feed.snapdo.com/?publisher=VertiTechnologyYB&dpid=VertiTechnologyYB&co=DE&userid=67df9fbc-4fcc-49d5-9d21-2130fbe62346&searchtype=ds&q={searchTerms}&installDate=01/01/1970
Gelöscht [Extension] : dhdepfaagokllfmhfbcfmocaeigmoebo
Gelöscht [Extension] : hphibigbodkkohoglgfkddblldpfohjl
Gelöscht [Extension] : kdcnnmifdmlmjffdgeieikcokcogpbej
Gelöscht [Extension] : kincjchfokkeneeofpeefomkikfkiedl
Gelöscht [Extension] : kkkeikdkpjenmoiicggnnodbkebafgpc
Gelöscht [Extension] : pgmfkblbflahhponhjmkcnpjinenhlnc
[ Datei : C:\Users\Gast.kebin-PC\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Extension] : ljmibnagodajacnnbifpamhggcohblip
[ Datei : C:\Users\kebin\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Homepage] : hxxp://search.conduit.com/?ctid=CT3311268&SearchSource=48&CUI=UN29504919652995354&UM=2&UP=SP227CA280-2830-4C9A-BC80-F19CEDB88F74&SSPV=
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : eooncjejnppfjjklapaamhcdmjbilmde
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gelöscht [Extension] : jpmbfleldcgkldadpdinhjjopdfpjfjp
*************************
AdwCleaner[R0].txt - [11644 octets] - [03/06/2014 21:34:27]
AdwCleaner[S0].txt - [10953 octets] - [03/06/2014 21:37:04]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11014 octets] ########## --------------
JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x86
Ran by kebin on 03.06.2014 at 21:46:11,22
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3919152501-1714073753-3578707811-1000\Software\Microsoft\Internet Explorer\Main\\Start Page
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3919152501-1714073753-3578707811-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211101158}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211101158}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6EE4760F-2013-4BA5-BC1C-AC5D33C65EFA}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"
~~~ FireFox
Successfully deleted the following from C:\Users\kebin\AppData\Roaming\mozilla\firefox\profiles\olbrdq18.default\prefs.js
user_pref("browser.startup.homepage", "hxxp://www.golsearch.com/?babsrc=HP_ss_Btisdt6&mntrId=D2636C626D8AF7C3&affID=121564&tt=160713_9127&tsp=4946");
user_pref("extensions.aa892fa082d0749e8adcef650222629ca82592752c2124885b999cb2a1d2f9d09com39678.39678.cookie.previous_page.value", "%22hxxp%3A//www.golsearch.com/%3Fbabsrc%3DH
user_pref("extensions.aa892fa082d0749e8adcef650222629ca82592752c2124885b999cb2a1d2f9d09com39678.39678.internaldb.cache/530e52021dc20843b1aa62957edeb9f8.value", "%22var%20adsDe
user_pref("extensions.aa892fa082d0749e8adcef650222629ca82592752c2124885b999cb2a1d2f9d09com39678.39678.internaldb.cache/833447eaff04548ccb80787286a7cad9_DE.value", "%22var%20ca
Emptied folder: C:\Users\kebin\AppData\Roaming\mozilla\firefox\profiles\olbrdq18.default\minidumps [23 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.06.2014 at 21:52:29,96
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |