Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.10.2014
Suchlauf-Zeit: 20:29:35
Logdatei: Malesuchvrl.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.10.03.05
Rootkit Datenbank: v2014.09.19.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Asus
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 318768
Verstrichene Zeit: 21 Min, 31 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 13
PUP.Optional.Spigot.A, HKLM\SOFTWARE\CLASSES\CLSID\{B9C767DD-F66A-40B4-8F12-4199A9A4393C}, In Quarantäne, [90c1d23e97e53df91e64c4d18b77cb35],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Löschen bei Neustart, [b79a4dc35428c670401bd5fcc240fb05],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [b79a4dc35428c670401bd5fcc240fb05],
PUP.Optional.WindowsProtectManger.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsProtectManger, In Quarantäne, [7fd2090793e979bd3a39d846da29ab55],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [5ff2030d9ddf00360291e489798b53ad],
PUP.Optional.Spigot.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\hbcennhacfaagdopikcegfcobcadeocj, In Quarantäne, [a0b146cad4a8171f88b3df4d8f74f907],
PUP.Optional.Spigot.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\mhkaekfpcppmmioggniknbnbdbcigpkk, In Quarantäne, [c48dd13ff4884bebce6ffd2fa36040c0],
PUP.Optional.Spigot.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pfndaklgolladniicklehhancnlgocpp, In Quarantäne, [d37e6ea2710b270f6ad405279c676a96],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, In Quarantäne, [361bc749720a42f43e94ce44c3406898],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [db767b95e29afd3930d536dde02347b9],
PUP.Optional.Spigot.A, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Search Settings, Löschen bei Neustart, [232ebf519fdd6ec8c15d1960798b20e0],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [a4adbb55fa82191d407b4ff3d82b847c],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [d180838d0478ae8846d1a4b51ee6ee12],
Registrierungswerte: 6
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [0a47729e92ea6acc297d9b76649fe719]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [f0617a963547d5618026c74ac04343bd]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, In Quarantäne, [361bc749720a42f43e94ce44c3406898]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, cor, In Quarantäne, [db767b95e29afd3930d536dde02347b9]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, Löschen bei Neustart, [d180838d0478ae8846d1a4b51ee6ee12]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, Löschen bei Neustart, [252c52be98e462d41e3f3be0ff04ff01]
Registrierungsdaten: 7
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1402861432&from=cor&uid=ST9320325AS_6VD7427QXXXX6VD7427Q&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1402861432&from=cor&uid=ST9320325AS_6VD7427QXXXX6VD7427Q&q={searchTerms}),Ersetzt,[d18032de8cf0b482eada14fedc297f81]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1402861432&from=cor&uid=ST9320325AS_6VD7427QXXXX6VD7427Q&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1402861432&from=cor&uid=ST9320325AS_6VD7427QXXXX6VD7427Q&q={searchTerms}),Ersetzt,[133e0010611b15210b9d64a38d78c23e]
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mjo1Ue97g2mD_AT1mrYV-lAq7AH0Wtr6DkOV7x-IkzNe_arMt5JmXME4I64tB6L9ePlz6UIJT_T2Y0FVXl0_OEPhd8-6g1HQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mjo1Ue97g2mD_AT1mrYV-lAq7AH0Wtr6DkOV7x-IkzNe_arMt5JmXME4I64tB6L9ePlz6UIJT_T2Y0FVXl0_OEPhd8-6g1HQ,,&q={searchTerms}),Ersetzt,[d77a58b84b31d75feb95739529dc649c]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mvlUsu_OOBolmtWKJekyVj1Ji3ft-QzZly_pJDWIpnkpxFkBxK7g4u41zy3YtriWRHSA7EMx8yht3uLUHdBDmzLmBlGPfxXA,,, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mvlUsu_OOBolmtWKJekyVj1Ji3ft-QzZly_pJDWIpnkpxFkBxK7g4u41zy3YtriWRHSA7EMx8yht3uLUHdBDmzLmBlGPfxXA,,),Löschen bei Neustart,[ff5211ff0b713ff7681c1eea669f659b]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mjo1Ue97g2mD_AT1mrYV-lAq7AH0Wtr6DkOV7x-IkzNe_arMt5JmXME4I64tB6L9ePlz6UIJT_T2Y0EkjkSLxZVT1vSTcNsQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mjo1Ue97g2mD_AT1mrYV-lAq7AH0Wtr6DkOV7x-IkzNe_arMt5JmXME4I64tB6L9ePlz6UIJT_T2Y0EkjkSLxZVT1vSTcNsQ,,&q={searchTerms}),Löschen bei Neustart,[76db937daece1026e69fed1b0302f10f]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mjo1Ue97g2mD_AT1mrYV-lAq7AH0Wtr6DkOV7x-IkzNe_arMt5JmXME4I64tB6L9ePlz6UIJT_T2Y0EkjkSLxZVT1vSTcNsQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mjo1Ue97g2mD_AT1mrYV-lAq7AH0Wtr6DkOV7x-IkzNe_arMt5JmXME4I64tB6L9ePlz6UIJT_T2Y0EkjkSLxZVT1vSTcNsQ,,&q={searchTerms}),Löschen bei Neustart,[59f8838d1864c373691dff09fa0bb44c]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1786342322-1499335809-2846592369-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mjo1Ue97g2mD_AT1mrYV-lAq7AH0Wtr6DkOV7x-IkzNe_arMt5JmXME4I64tB6L9ePlz6UIJT_T2Y0EkjkSLxZVT1vSTcNsQ,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mjo1Ue97g2mD_AT1mrYV-lAq7AH0Wtr6DkOV7x-IkzNe_arMt5JmXME4I64tB6L9ePlz6UIJT_T2Y0EkjkSLxZVT1vSTcNsQ,,&q={searchTerms}),Löschen bei Neustart,[c38ec34d55270c2ad4ad19ef54b146ba]
Ordner: 32
PUP.Optional.OpenCandy, C:\Users\Asus\AppData\Roaming\OpenCandy, In Quarantäne, [89c8ce427b01dd59322110d1cb374cb4],
PUP.Optional.OpenCandy, C:\Users\Asus\AppData\Roaming\OpenCandy\2FE4866EEE1C4558BF02E145A76D7C2E, In Quarantäne, [89c8ce427b01dd59322110d1cb374cb4],
PUP.Optional.OpenCandy, C:\Users\Asus\AppData\Roaming\OpenCandy\686615BB7D7E435B8F40982BFA016783, In Quarantäne, [89c8ce427b01dd59322110d1cb374cb4],
PUP.Optional.OpenCandy, C:\Users\Asus\AppData\Roaming\OpenCandy\86C9C52A3A444248AE025F2AF7BAFC62, In Quarantäne, [89c8ce427b01dd59322110d1cb374cb4],
PUP.Optional.OpenCandy, C:\Users\Asus\AppData\Roaming\OpenCandy\BFC16944F10A4F5F988233B03583C03D, In Quarantäne, [89c8ce427b01dd59322110d1cb374cb4],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\chrome, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\chrome\content, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj, In Quarantäne, [7fd2f41c5725092db3830ee15da5bd43],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_0, In Quarantäne, [7fd2f41c5725092db3830ee15da5bd43],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\_metadata, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\css, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\Img, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\_metadata, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cikkkfooompgefbcjlgdjejfdknkheaj, In Quarantäne, [57fabd533745d066800312e20002c040],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gpiifgmgnfdiblgpaepbmfdkcheicgof, In Quarantäne, [7dd47799a6d66bcb7f059b598c768977],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj, In Quarantäne, [1d3460b004780135f68fc52f6b9735cb],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [b39e9080b2ca05312dcf45b19072ed13],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [b39e9080b2ca05312dcf45b19072ed13],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger, In Quarantäne, [4c05d23eaad21323f9a6af48748e47b9],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log, In Quarantäne, [4c05d23eaad21323f9a6af48748e47b9],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update, In Quarantäne, [4c05d23eaad21323f9a6af48748e47b9],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot, In Quarantäne, [fc551ef24d2f75c1f674fc0b649f867a],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC, In Quarantäne, [fc551ef24d2f75c1f674fc0b649f867a],
Dateien: 101
PUP.Optional.Conduit.A, C:\Users\Asus\AppData\Roaming\OpenCandy\686615BB7D7E435B8F40982BFA016783\sp-downloader.exe, In Quarantäne, [52ffba56adcf8ea8ad670926b24f0bf5],
PUP.Optional.OpenCandy.A, C:\Users\Asus\AppData\Roaming\OpenCandy\BFC16944F10A4F5F988233B03583C03D\dlm.exe, In Quarantäne, [3c1512fe413b092d33a341f0e120ce32],
PUP.Optional.SmartBar.A, C:\Users\Asus\AppData\Roaming\OpenCandy\BFC16944F10A4F5F988233B03583C03D\LinkuryYAHOO_RBCB_p4v7.exe, In Quarantäne, [b89929e7b5c742f4b49387ffbc45867a],
PUP.Optional.SmartBar.A, C:\Users\Asus\AppData\Roaming\OpenCandy\BFC16944F10A4F5F988233B03583C03D\Packer.exe, In Quarantäne, [4d0412fe94e867cf2621e3a358a99c64],
PUP.Optional.Conduit.A, C:\Program Files (x86)\WhiteSmoke_New_V6\WhiteSmoke_New_V6ToolbarHelper.exe, In Quarantäne, [bf92d33d1c604ee84c1c58c6738db749],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI1BE9.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [4a07a36d0478132349089a945aa607f9],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIC961.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [6ae72ee2bdbfab8bb99863cbf907f907],
PUP.Optional.SmartBar, C:\Windows\Installer\MSI5C36.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [a4ad2ee21d5fa690f55cc06eec14ce32],
PUP.Optional.WebSearch.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\searchplugins\Web Search.xml, In Quarantäne, [91c09d73fa8294a20aead167e41f6a96],
PUP.Optional.OpenCandy, C:\Users\Asus\AppData\Roaming\OpenCandy\2FE4866EEE1C4558BF02E145A76D7C2E\WS_p4v1_2CB.exe, In Quarantäne, [89c8ce427b01dd59322110d1cb374cb4],
PUP.Optional.OpenCandy, C:\Users\Asus\AppData\Roaming\OpenCandy\BFC16944F10A4F5F988233B03583C03D\4649.ico, In Quarantäne, [89c8ce427b01dd59322110d1cb374cb4],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\GottenAppsContextMenu.xml, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\hk64tbWhit.dll, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\hktbWhit.dll, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\ldrtbWhit.dll, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\OtherAppsContextMenu.xml, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\prxtbWhit.dll, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\SharedAppsContextMenu.xml, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\tbWhit.dll, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\toolbar.cfg, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.WhiteSmoke.A, C:\Program Files (x86)\WhiteSmoke_New_V6\ToolbarContextMenu.xml, In Quarantäne, [e17014fcf28a2a0c601bb929936f2ed2],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\chrome.manifest, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\icon.png, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\install.rdf, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\chrome\content\config.json, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\chrome\content\main.js, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\chrome\content\savingsslider.js, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\chrome\content\savingsslider.xul, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.SavingsSlider.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com\chrome\content\spigot.js, In Quarantäne, [87cae42cea920d29f715a047af53ec14],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome.manifest, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\icon.png, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\install.rdf, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\config.json, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\main.js, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\main.xul, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\newtab.xul, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\prefs.txt, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\redirects.js, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\spigot.js, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\startpage.js, In Quarantäne, [450c3ed2df9d2313ac422ebd2bd7d32d],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_0\background.js, In Quarantäne, [7fd2f41c5725092db3830ee15da5bd43],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_0\ebay-128.png, In Quarantäne, [7fd2f41c5725092db3830ee15da5bd43],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_0\ebay-19.png, In Quarantäne, [7fd2f41c5725092db3830ee15da5bd43],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_0\ebay-48.png, In Quarantäne, [7fd2f41c5725092db3830ee15da5bd43],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbcennhacfaagdopikcegfcobcadeocj\1.1_0\manifest.json, In Quarantäne, [7fd2f41c5725092db3830ee15da5bd43],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\background.html, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\background.js, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\config.json, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\deh-128.png, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\deh-19.png, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\deh-48.png, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\manifest.json, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\util.js, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj\1.1_1\_metadata\verified_contents.json, In Quarantäne, [f65b51bf23598aacee93b440e61c3ec2],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\background.html, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\background.js, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\config.json, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\empty-favicon.ico, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\jquery.js, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\manifest.json, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\newtab.html, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\newtab.js, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\nta-128.png, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\nta-48.png, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\redirect.html, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\redirect.js, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\util.js, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\css\newtab.css, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\Img\no_thumb.png, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\Img\search-icon.png, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof\1.1_0\_metadata\verified_contents.json, In Quarantäne, [08495ab6fb81ed49532fa54f0ff36799],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cikkkfooompgefbcjlgdjejfdknkheaj\000005.ldb, In Quarantäne, [57fabd533745d066800312e20002c040],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cikkkfooompgefbcjlgdjejfdknkheaj\000078.log, In Quarantäne, [57fabd533745d066800312e20002c040],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cikkkfooompgefbcjlgdjejfdknkheaj\CURRENT, In Quarantäne, [57fabd533745d066800312e20002c040],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cikkkfooompgefbcjlgdjejfdknkheaj\LOCK, In Quarantäne, [57fabd533745d066800312e20002c040],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cikkkfooompgefbcjlgdjejfdknkheaj\LOG, In Quarantäne, [57fabd533745d066800312e20002c040],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cikkkfooompgefbcjlgdjejfdknkheaj\LOG.old, In Quarantäne, [57fabd533745d066800312e20002c040],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cikkkfooompgefbcjlgdjejfdknkheaj\MANIFEST-000077, In Quarantäne, [57fabd533745d066800312e20002c040],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gpiifgmgnfdiblgpaepbmfdkcheicgof\000005.ldb, In Quarantäne, [7dd47799a6d66bcb7f059b598c768977],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gpiifgmgnfdiblgpaepbmfdkcheicgof\000032.ldb, In Quarantäne, [7dd47799a6d66bcb7f059b598c768977],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gpiifgmgnfdiblgpaepbmfdkcheicgof\000079.log, In Quarantäne, [7dd47799a6d66bcb7f059b598c768977],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gpiifgmgnfdiblgpaepbmfdkcheicgof\CURRENT, In Quarantäne, [7dd47799a6d66bcb7f059b598c768977],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gpiifgmgnfdiblgpaepbmfdkcheicgof\LOCK, In Quarantäne, [7dd47799a6d66bcb7f059b598c768977],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gpiifgmgnfdiblgpaepbmfdkcheicgof\LOG, In Quarantäne, [7dd47799a6d66bcb7f059b598c768977],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gpiifgmgnfdiblgpaepbmfdkcheicgof\LOG.old, In Quarantäne, [7dd47799a6d66bcb7f059b598c768977],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gpiifgmgnfdiblgpaepbmfdkcheicgof\MANIFEST-000078, In Quarantäne, [7dd47799a6d66bcb7f059b598c768977],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj\000005.ldb, In Quarantäne, [1d3460b004780135f68fc52f6b9735cb],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj\000076.log, In Quarantäne, [1d3460b004780135f68fc52f6b9735cb],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj\CURRENT, In Quarantäne, [1d3460b004780135f68fc52f6b9735cb],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj\LOCK, In Quarantäne, [1d3460b004780135f68fc52f6b9735cb],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj\LOG, In Quarantäne, [1d3460b004780135f68fc52f6b9735cb],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj\LOG.old, In Quarantäne, [1d3460b004780135f68fc52f6b9735cb],
PUP.Optional.Spigot.A, C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hbcennhacfaagdopikcegfcobcadeocj\MANIFEST-000075, In Quarantäne, [1d3460b004780135f68fc52f6b9735cb],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [b39e9080b2ca05312dcf45b19072ed13],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log\wprotectmanager_2014-06-15[21-46-36-543].log, In Quarantäne, [4c05d23eaad21323f9a6af48748e47b9],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update\conf, In Quarantäne, [4c05d23eaad21323f9a6af48748e47b9],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC\DomainErrorHelper_1.0_0.crx, In Quarantäne, [fc551ef24d2f75c1f674fc0b649f867a],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC\nta_1.0_0.crx, In Quarantäne, [fc551ef24d2f75c1f674fc0b649f867a],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC\saamazon_1.0.crx, In Quarantäne, [fc551ef24d2f75c1f674fc0b649f867a],
PUP.Optional.Spigot.A, C:\Program Files (x86)\Common Files\Spigot\GC\saebay_1.1.crx, In Quarantäne, [fc551ef24d2f75c1f674fc0b649f867a],
PUP.Optional.HelperBar.A, C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\prefs.js, Gut: (), Schlecht: (user_pref("keyword.URL", "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mjo1Ue97g2mD_AT1mrYV-lAq7AH0Wtr6DkOV7x-IkzNe_arMt5JmXME4I64tB6L9ePlz6UIJT_T2Y0EkjkSLxZVT1vSTcNsQ,,&q=");), Ersetzt,[1839b060562622148a611431768f5ca4]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.311 - Bericht erstellt am 03/10/2014 um 21:08:32
# Aktualisiert 30/09/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Asus - ASUS-PC
# Gestartet von : C:\Users\Asus\Desktop\AdwCleaner_3.311.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\Users\Asus\AppData\Local\Slick Savings
Ordner Gelöscht : C:\Users\Asus\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Asus\Documents\Updater
Ordner Gelöscht : C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\Extensions\ffxtlbr@zonealarm.com
Datei Gelöscht : C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\Extensions\staged\{58d2a791-6199-482f-a9aa-9b725ec61362}.xpi
Datei Gelöscht : C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\Extensions\staged\savingsslider@mybrowserbar.com.xpi
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2A841F7A-A014-4DA5-B6D9-8B913DFB7A8C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{987D9269-F8A1-408F-BF62-4397D2F5363E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0722BEB-FDA1-4AA1-A2A8-15A74A5B3F70}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F1963E76-845B-474C-8C7F-D69A96D8AA34}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{06DEB529-DE09-43EC-B6E2-451AAB0FF000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E00DE9B9-B128-4C39-B732-B5D85013FA48}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{DA7F5AE1-3BE3-43C0-8098-C1D183616E97}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{DA7F5AE1-3BE3-43C0-8098-C1D183616E97}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{744E0E81-BC79-4719-A58B-C98F7E78EE5D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\WhiteSmoke_New_V6
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\WhiteSmoke_New_V6
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17280
-\\ Mozilla Firefox v19.0.2 (de)
[ Datei : C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\prefs.js ]
Zeile gelöscht : user_pref("CT3311268.UserID", "UN13201835012082410");
Zeile gelöscht : user_pref("CT3311268.fullUserID", "UN13201835012082410.IN.20131003214110");
Zeile gelöscht : user_pref("CT3311268.installerVersion", "1.7.1.7");
Zeile gelöscht : user_pref("CT3311268.versionFromInstaller", "10.20.1.8");
Zeile gelöscht : user_pref("CT3311268.xpeMode", "0");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Web Search");
Zeile gelöscht : user_pref("extensions.zonealarm.lastB", "hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAatONRMkeCp_jlwhXYG10AyROJ5UKUtNhArueKg-qR3_E53mA-8-AWgDCS9dJDmS1mvlUsu_O[...]
Zeile gelöscht : user_pref("smartbar.machineId", "LFRYGOLQCS+4MY7GMVT6RPHFWK+UCEPIRW1TJ1RPO7YYYFEFEZDUHALVJ9FVKJPRRNFH48DF8OUNZB8Z3MTJHW");
Zeile gelöscht : user_pref("startpage.ntsearch_url", "hxxp://search.yahoo.com/search?ei=utf-8&fr=spigot-nt-ff&type=0&ilc=12&p={searchTerms}");
-\\ Google Chrome v37.0.2062.124
[ Datei : C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [7724 octets] - [03/10/2014 21:06:11]
AdwCleaner[S0].txt - [7388 octets] - [03/10/2014 21:08:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7448 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.2.7 (10.03.2014:1)
OS: Windows 7 Home Premium x64
Ran by Asus on 03.10.2014 at 21:17:21,09
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho76F9.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8B03.tmp
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\uiyfkznn.default\extensions\staged
Emptied folder: C:\Users\Asus\AppData\Roaming\mozilla\firefox\profiles\uiyfkznn.default\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.10.2014 at 21:22:42,19
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2014
Ran by Asus (administrator) on ASUS-PC on 03-10-2014 21:26:04
Running from C:\Users\Asus\Desktop
Loaded Profile: Asus (Available profiles: Asus)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ATK) C:\Program Files\P4G\BatteryLife.exe
(ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Check Point Software Technologies, Ltd.) C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
(Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
(ASUS) C:\Windows\AsScrPro.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM-x32\...\Run: [RemoteControl9] => C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe [87336 2009-07-06] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2010-06-25] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [Boingo Wi-Fi] => C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk [2429 2010-10-29] ()
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-08-12] ()
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-11-02] (CyberLink)
HKLM-x32\...\Run: [ASUS Screen Saver Protector] => C:\Windows\AsScrPro.exe [3054136 2010-10-29] (ASUS)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-15] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ZoneAlarm] => C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe [137352 2014-05-30] (Check Point Software Technologies Ltd.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1786342322-1499335809-2846592369-1000\...\Run: [Akamai NetSession Interface] => "C:\Users\Asus\AppData\Local\Akamai\netsession_win.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk
ShortcutTarget: CodecPackUpdateChecker.lnk -> C:\Windows\SysWOW64\C2MP\UpdateChecker.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk
ShortcutTarget: SRS Premium Sound.lnk -> C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe (No File)
Startup: C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
BHO: Windows Live Family Safety Browser Helper Class -> {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} -> C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Google Toolbar Notifier BHO -> {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -> C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Google Dictionary Compression sdch -> {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -> C:\Program Files (x86)\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\amd64\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {eec0f710-38b5-4aba-99bf-ec87564a4e13} - C:\Program Files (x86)\Microsoft\BingBar\7.3.132.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{49C99D73-AFB2-4217-AC49-FB24651C37D2}: [NameServer] 0.0.0.0
FireFox:
========
FF ProfilePath: C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1212152.dll (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8051.1204 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Avira Browser Safety - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\Extensions\abs@avira.com [2014-09-30]
FF Extension: Amazon-Icon - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\Extensions\amazon-icon@giga.de [2014-03-11]
FF Extension: No Name - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362} [Not Found]
FF Extension: No Name - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\savingsslider@mybrowserbar.com [Not Found]
FF Extension: No Name - C:\Users\Asus\AppData\Roaming\Mozilla\Firefox\Profiles\uiyfkznn.default\extensions\ffxtlbr@zonealarm.com [Not Found]
Chrome:
=======
CHR DefaultSuggestURL: Default ->
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\37.0.2062.124\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Profile: C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-03-24]
CHR Extension: (Google Drive) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-03-24]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-06]
CHR Extension: (YouTube) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-03-24]
CHR Extension: (Last updated at $time$ on $date$) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-05]
CHR Extension: (Google Search) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-03-24]
CHR Extension: (Yulia Brodskaya) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlgdloilieclkegafohackmhffbmdpko [2014-08-31]
CHR Extension: (ZoneAlarm Chrome Toolbar) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgdcapepedmpopjkmdbjnmmmfgllnfek [2014-09-30]
CHR Extension: (Google Wallet) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-06]
CHR Extension: (Gmail) - C:\Users\Asus\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-03-24]
CHR HKCU\...\Chrome\Extension: [kgdcapepedmpopjkmdbjnmmmfgllnfek] - C:\Users\Asus\AppData\Roaming\Check Point Software Technologies LTD\zonealarm\1.8.29.17\zonealarm.crx [2014-02-12]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2013-06-01] (Adobe Systems) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-15] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
R2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-10-01] (Intel Corporation) [File not signed]
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273136 2013-02-08] ()
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5284208 2013-10-30] (INCA Internet Co., Ltd.)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () [File not signed]
R2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-10-01] (Intel Corporation) [File not signed]
S2 vsmon; C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe [3592120 2014-05-30] (Check Point Software Technologies Ltd.)
R2 ZAPrivacyService; C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [90936 2014-05-29] (Check Point Software Technologies, Ltd.)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3386608 2013-02-08] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-08-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-08-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-08-15] (Avira Operations GmbH & Co. KG)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2014-04-30] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [92768 2014-04-30] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [490592 2014-04-30] (Kaspersky Lab ZAO)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
S3 Netaapl; C:\Windows\System32\DRIVERS\netaapl64.sys [23040 2013-08-06] (Apple Inc.) [File not signed]
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2013-03-18] (Apple, Inc.) [File not signed]
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [450968 2014-05-30] (Check Point Software Technologies Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
U3 tmlwf; No ImagePath
U3 tmwfp; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-03 21:26 - 2014-10-03 21:27 - 00021675 _____ () C:\Users\Asus\Desktop\FRST.txt
2014-10-03 21:25 - 2014-10-03 21:25 - 00000000 ____D () C:\Users\Asus\Desktop\FRST-OlderVersion
2014-10-03 21:22 - 2014-10-03 21:22 - 00001002 _____ () C:\Users\Asus\Desktop\JRT.txt
2014-10-03 21:16 - 2014-10-03 21:16 - 00000000 ____D () C:\Windows\ERUNT
2014-10-03 21:15 - 2014-10-03 21:15 - 01702068 _____ (Thisisu) C:\Users\Asus\Desktop\JRT.exe
2014-10-03 21:06 - 2014-10-03 21:08 - 00000000 ____D () C:\AdwCleaner
2014-10-03 21:05 - 2014-10-03 21:05 - 01375089 _____ () C:\Users\Asus\Desktop\AdwCleaner_3.311.exe
2014-10-03 21:03 - 2014-10-03 21:03 - 00033941 _____ () C:\Users\Asus\Desktop\mbam.txt
2014-10-03 20:52 - 2014-10-03 20:52 - 00001167 _____ () C:\Users\Asus\Desktop\MalewareTEXST.txt
2014-10-03 20:28 - 2014-10-03 21:03 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-03 20:28 - 2014-10-03 20:28 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-03 20:28 - 2014-10-03 20:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-03 20:28 - 2014-10-03 20:28 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-03 20:28 - 2014-10-03 20:28 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-03 20:28 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-03 20:28 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-03 20:28 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-02 21:07 - 2014-10-02 22:02 - 00000000 ____D () C:\ComboFix
2014-10-02 21:07 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-02 21:07 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-02 21:07 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-02 21:07 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-02 21:07 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-02 21:07 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-02 21:07 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-02 21:07 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-02 20:58 - 2014-10-02 21:07 - 00000000 ____D () C:\Qoobox
2014-10-02 20:56 - 2014-10-02 20:56 - 00000000 ____D () C:\Windows\erdnt
2014-10-02 20:52 - 2014-10-02 20:55 - 05582981 ____R (Swearware) C:\Users\Asus\Desktop\ComboFix.exe
2014-10-01 20:40 - 2014-10-03 21:26 - 00000000 ____D () C:\FRST
2014-10-01 20:19 - 2014-10-01 20:19 - 00262144 _____ () C:\Windows\system32\config\elam
2014-10-01 20:14 - 2014-10-03 21:25 - 02109440 _____ (Farbar) C:\Users\Asus\Desktop\FRST64.exe
2014-10-01 16:45 - 2014-10-03 21:10 - 00184784 _____ () C:\Windows\PFRO.log
2014-09-30 22:13 - 2014-09-30 22:14 - 00431135 _____ () C:\Windows\system32\Drivers\vsconfig.xml
2014-09-30 22:13 - 2014-04-30 11:01 - 00490592 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-09-30 22:13 - 2014-04-30 11:01 - 00092768 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-09-30 22:13 - 2014-04-30 11:00 - 07717984 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2014-09-30 22:12 - 2014-09-30 22:12 - 00000762 _____ () C:\Users\Public\Desktop\ZoneAlarm Security.lnk
2014-09-30 22:12 - 2014-09-30 22:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
2014-09-30 21:59 - 2014-09-30 22:12 - 00000000 ____D () C:\Program Files (x86)\CheckPoint
2014-09-30 21:59 - 2014-09-30 21:59 - 00000000 ____D () C:\Users\Asus\AppData\Roaming\Check Point Software Technologies LTD
2014-09-30 21:59 - 2014-09-30 21:59 - 00000000 ____D () C:\Program Files (x86)\Check Point Software Technologies LTD
2014-09-30 21:57 - 2014-09-30 21:57 - 00000000 ____D () C:\Users\Asus\AppData\Roaming\Avira
2014-09-30 21:56 - 2014-09-30 21:54 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-09-30 21:51 - 2014-08-15 10:30 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-09-30 21:51 - 2014-08-15 10:30 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-09-30 21:51 - 2014-08-15 10:30 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-09-30 21:48 - 2014-09-30 21:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-09-30 21:48 - 2014-09-30 21:51 - 00000000 ____D () C:\ProgramData\Avira
2014-09-30 21:48 - 2014-09-30 21:51 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-30 21:48 - 2014-09-30 21:48 - 00001139 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-09-30 19:32 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-09-30 19:32 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-27 22:17 - 2014-09-29 23:02 - 01624173 _____ () C:\Users\Asus\Desktop\banger.flp
2014-09-23 19:21 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-23 19:21 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-23 19:06 - 2014-10-03 21:10 - 00001232 _____ () C:\Windows\setupact.log
2014-09-23 19:06 - 2014-09-23 19:06 - 00000000 _____ () C:\Windows\setuperr.log
2014-09-22 19:02 - 2014-09-22 19:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
2014-09-22 19:01 - 2014-09-22 19:57 - 00000000 ____D () C:\Users\Asus\AppData\Roaming\Winamp
2014-09-22 19:01 - 2014-09-22 19:02 - 00000000 ____D () C:\Program Files (x86)\Winamp
2014-09-20 23:43 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-20 23:43 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-20 23:43 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-20 23:43 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-20 23:42 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-20 23:42 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-20 23:42 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-20 23:42 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-20 23:42 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-20 23:42 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-20 23:42 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-20 23:42 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-20 23:42 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-20 23:42 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-20 23:42 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-20 23:42 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-20 23:42 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-20 23:42 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-20 23:42 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-20 23:42 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-20 23:42 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-20 23:42 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-20 23:42 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-20 23:42 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-20 23:42 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-20 23:42 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-20 23:42 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-20 23:42 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-20 23:42 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-20 23:42 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-20 23:42 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-20 23:42 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-20 23:42 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-20 23:42 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-20 23:42 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-20 23:42 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-20 23:42 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-20 23:42 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-20 23:42 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-20 23:42 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-20 23:42 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-20 23:42 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-20 23:42 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-20 23:42 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-20 23:42 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-20 23:42 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-20 23:42 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-20 23:42 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-20 23:42 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-20 23:42 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-20 23:42 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-20 23:42 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-20 23:42 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-20 23:42 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-20 23:42 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-20 23:42 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-16 17:15 - 2014-10-02 20:30 - 00000098 _____ () C:\Users\Asus\Desktop\Blacklist.txt
2014-09-11 18:21 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-11 18:21 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-11 18:21 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-11 18:21 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-11 18:21 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-09-11 18:06 - 2014-08-01 13:53 - 01031168 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-09-11 18:06 - 2014-08-01 13:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2014-09-11 17:52 - 2014-06-24 05:29 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-09-11 17:52 - 2014-06-24 04:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-09-11 17:34 - 2014-06-27 04:08 - 02777088 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-09-11 17:34 - 2014-06-27 03:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2014-09-05 22:13 - 2014-09-05 22:14 - 00000000 ____D () C:\Users\Asus\Desktop\AWO
2014-09-05 20:08 - 2014-09-14 20:05 - 01683754 _____ () C:\Users\Asus\Desktop\ff2.flp
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-03 21:19 - 2009-07-14 06:45 - 00010016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-03 21:19 - 2009-07-14 06:45 - 00010016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-03 21:18 - 2010-10-29 01:31 - 01254203 _____ () C:\Windows\WindowsUpdate.log
2014-10-03 21:12 - 2014-08-31 17:12 - 00001360 _____ () C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-10-03 21:10 - 2013-03-24 22:26 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-03 21:10 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-03 21:04 - 2013-03-24 22:26 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-03 20:55 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas
2014-10-03 20:33 - 2009-02-26 13:06 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-02 21:29 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-02 21:21 - 2010-10-29 01:54 - 00000000 ____D () C:\Program Files (x86)\Adobe
2014-10-02 21:05 - 2009-02-26 12:37 - 00002198 _____ () C:\Windows\epplauncher.mif
2014-10-02 21:02 - 2009-02-26 12:25 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-10-02 20:49 - 2009-08-04 11:51 - 00700110 _____ () C:\Windows\system32\perfh007.dat
2014-10-02 20:49 - 2009-08-04 11:51 - 00149960 _____ () C:\Windows\system32\perfc007.dat
2014-10-02 20:49 - 2009-07-14 07:13 - 01622124 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-02 20:16 - 2014-08-22 13:53 - 00000000 ____D () C:\Users\Asus\AppData\Roaming\MAGIX
2014-10-01 17:02 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-09-30 21:48 - 2013-03-29 01:51 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-29 20:48 - 2009-02-26 12:19 - 00000000 ____D () C:\Users\Asus\AppData\Roaming\vlc
2014-09-29 19:09 - 2013-11-30 23:30 - 00000000 ____D () C:\Users\Asus\Desktop\Programme
2014-09-27 13:33 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-09-25 17:33 - 2009-02-26 13:06 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-25 17:33 - 2009-02-26 13:06 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-25 17:33 - 2009-02-26 13:06 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-09-25 17:07 - 2013-03-24 22:27 - 00002177 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-22 20:43 - 2009-02-26 13:21 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-22 08:42 - 2013-02-26 17:20 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-21 12:43 - 2014-08-25 12:34 - 00000000 ____D () C:\Users\Asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2014-09-20 23:42 - 2013-09-19 22:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-09-11 20:39 - 2009-02-26 09:58 - 01596404 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-11 20:37 - 2013-08-14 20:10 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-11 20:37 - 2009-02-26 12:25 - 00002119 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-09-11 20:37 - 2009-02-26 12:25 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-09-11 20:24 - 2013-02-26 14:50 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-05 23:58 - 2009-02-26 09:59 - 00000000 ____D () C:\Users\Asus\AppData\Roaming\SoftGrid Client
2014-09-05 23:26 - 2014-08-25 12:34 - 00000000 ____D () C:\Users\Asus\AppData\Roaming\FlowStone
2014-09-05 22:23 - 2014-03-08 00:18 - 00000000 ____D () C:\Users\Asus\AppData\Roaming\Skype
2014-09-04 21:25 - 2013-11-30 23:30 - 00000000 ____D () C:\Users\Asus\Desktop\Daten Janine u Michael
Some content of TEMP:
====================
C:\Users\Asus\AppData\Local\Temp\avgnt.exe
C:\Users\Asus\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-27 13:25
==================== End Of Log ============================ --- --- ---
--- --- --- |