| highflyers | 24.10.2014 19:21 | Abend,
Revo Uninstall habe ich erfolgreich ausgeführt.
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 24.10.2014
Suchlauf-Zeit: 19:07:43
Logdatei: maleware.txt
Administrator: Ja
Version: 2.00.3.1025
Malware Datenbank: v2014.10.24.07
Rootkit Datenbank: v2014.10.22.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Yannic
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 309877
Verstrichene Zeit: 15 Min, 15 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 25
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\13641, In Quarantäne, [2166090f7c0060d60ad5ed5e6d96ca36],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, In Quarantäne, [d5b2997f621a78be85540828fc07728e],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\13641, In Quarantäne, [c1c6cb4dc1bb0b2b756aff4c2ad94cb4],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, In Quarantäne, [cabdb95f8def51e5e9877c152adad42c],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, In Quarantäne, [3b4c1afe176550e61160c0d13fc5fd03],
PUP.Optional.RadioCanyon.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Radio Canyon, In Quarantäne, [0186a96f9ede38fe7e592c6809fb0ff1],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2271421671-2185954834-4090823298-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [dfa867b1a0dcad89bfe860222adab848],
PUP.Optional.RadioCanyon.A, HKU\S-1-5-21-2271421671-2185954834-4090823298-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Radio Canyon, In Quarantäne, [345365b3cfad26104394d1c39e66f40c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2271421671-2185954834-4090823298-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\13641, In Quarantäne, [7f08b4647efeac8a564254d0eb185da3],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.OneClickCtrl.10, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\globalUpdate.Update3WebControl.4, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
Registrierungswerte: 1
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [d5b2997f621a78be85540828fc07728e]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 21
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\defaults, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\defaults\preferences, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\userCode, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\locale, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\locale\en-US, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Download, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Install, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\Offline\{499DA868-2E6F-4AC3-9458-D7011F872575}, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.RadioCanyon.A, C:\Users\Yannic\AppData\LocalLow\Radio Canyon, In Quarantäne, [eb9c090fff7d4beb6f6b73a98380a759],
Dateien: 163
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\RHEng\5B665748B7B846948EC07F87C525C1F5\setup.exe, In Quarantäne, [7d0afa1ecfad3303833ec7046899ac54],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\8b4719f5-890f-46a9-b303-ea53638eab0b-11.exe, In Quarantäne, [bfc8140479038da92a582196778ac23e],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\8b4719f5-890f-46a9-b303-ea53638eab0b-2.exe, In Quarantäne, [0a7d40d83c4061d5087ab2050100d52b],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\8b4719f5-890f-46a9-b303-ea53638eab0b-4.exe, In Quarantäne, [5d2a9c7c403cf1458bf7694ebc4559a7],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\8b4719f5-890f-46a9-b303-ea53638eab0b-5.exe, In Quarantäne, [8bfccb4d314b79bd7b0705b2de236a96],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\Radio Canyon-bg.exe, In Quarantäne, [3750c15792eae74fc0c2cbece91801ff],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\Radio Canyon-bho.dll, In Quarantäne, [8afd5abe295374c2a3df397e9b6655ab],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\Radio Canyon-bho64.dll, In Quarantäne, [9fe8a276bfbdd561d7ab71469968cf31],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\Radio Canyon-buttonutil.exe, In Quarantäne, [70171800adcf61d58bf76f48be43956b],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\Radio Canyon-buttonutil64.exe, In Quarantäne, [cbbcbc5cd9a356e05230239404fd9d63],
PUP.Optional.RadioCanyon.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\Radio Canyon-codedownloader.exe, In Quarantäne, [61268f896517f6406919c6f16a97f010],
PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-2271421671-2185954834-4090823298-1001\$RYOZ128\utils.exe, In Quarantäne, [721550c8b3c994a259f893c14bb5758b],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Local\Temp\~nsu.tmp\Au_.exe, In Quarantäne, [5c2bff195626d561460b173d619f9e62],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-1, In Quarantäne, [dfa80f090c70db5b01d327093dc62dd3],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-11, In Quarantäne, [3651cc4c96e661d5864e46eaf50ef50b],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-2, In Quarantäne, [f3947b9d512b77bfb42028087a892fd1],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-4, In Quarantäne, [b5d2988090ec43f3775dfe321ee5f709],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-5, In Quarantäne, [5f2824f4522aa98dba1aee4222e118e8],
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-5_user, In Quarantäne, [1077c35565179a9ce3f182aec04312ee],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-1.job, In Quarantäne, [f295e4344537290dab5be1ae9b699769],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-11.job, In Quarantäne, [e7a027f1037992a444c2f29d4bb9966a],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-2.job, In Quarantäne, [3156fc1ca9d31f17b254325da55f9967],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-4.job, In Quarantäne, [a6e1d7419ce0bd79fe08325d709450b0],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-5.job, In Quarantäne, [fd8ae5336d0fff37ec1adab5ea1ada26],
PUP.Optional.CrossRider.T, C:\Windows\Tasks\8b4719f5-890f-46a9-b303-ea53638eab0b-5_user.job, In Quarantäne, [1d6a0117bebedb5bb5515d326c98e11f],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, In Quarantäne, [1077d444087445f16fad701fb2525da3],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, In Quarantäne, [93f4dc3c6814a09655c8d4bbe71d659b],
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, In Quarantäne, [f88f9385b2cabe78b46aeea1e91bff01],
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, In Quarantäne, [5b2c25f357257abc32ed69261aeae818],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome.manifest, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\install.rdf, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\3d227d28eff54ec217a6a015f5c81ef6.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\537ab9cff4e0d385ec10b650909e75a5.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\8e23d3dda6139ef87794c1f4500af804.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\b451000e362ee3e6369164a6ac986caf.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\background.html, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\browser.xul, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\c164886c11124fa7d0b52df730733701.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\dialog.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\e0d3da65bc0ecb715a51f89f71c0d833.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\ffCoreFilesIndex.txt, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\options.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\options.xul, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\search_dialog.xul, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\88c24e94cae6e777e5d2a10f04ba5dcc.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\26f1106e42a29add8b4a8976cf226714.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\29ef6b3d78a4b49ad46f1d2bae2cdc1b.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\3675067cd24ba1e1e682e9a487c57f36.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\4155f3b771a0628b79dbfa29b8e97b12.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\4b7a3759b30f0f46ed7e8e725428f78e.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\6485d83ff34436e1724b763a27f336fc.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\7371bfe0df23879fd91ec5bacbf1a978.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\78c62ae7896b34ea1e0ac6d43ced9f9c.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\8aacdb7c5a0cc678a1571dbf88e36d93.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\97476e3fdb8d89545a5e1170dd09c2d7.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\9d02bfdbc722836f11339c0a973dd559.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\a70f8f72cf455b66dab80afa0ea4cfe4.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\b417c732c1b5ca9e04e787b2dca9aef3.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\e98fb1d44d0c91bb73d515ad5d841b22.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\api\f51be12fcaa7ec70f6c87e61c930ad24.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\0972a300318e07dc5cb528aeb43e5b4f.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\1e59b18e6eb5c500f129ed50de75e78e.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\3734dc51c471fb3b06029723d4528290.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\3d2243ee70be25bc09218afc467f0fac.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\4dbf038ab5adcc9338090d8a07453cb2.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\4e59afa7344ec9e589443cf0dca29dd2.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\64d3c4bd7ca6e331f1d047cd25f7d3e6.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\68cbd97ab23a0dd00619c745821a3fed.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\781d21ad75aeeea80d0e792cd420cc00.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\c9a871b339b0e20f7e28a508e5433f64.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\ccc30a0d747e7d7b895f4be874199a86.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\cdc44fcce991caea898dc6fd497e132a.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\cfc6d6590ce90afadb0e37c4d0337490.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\d2820ccfdedccbe96af292278489a5dd.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\df2023ad9b52530a4bf8677c2710e722.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\eb1ed11a0e73f554138b4463ed64977d.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\f15e88e96392a016c57761a4baf189d0.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\f8176f052518c877ee7189bac2815dd3.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\fa6c34367769940a5038f603933d5520.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\fb2f145827182b45550ea8b10f1744a1.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\chrome\content\core\installer.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\defaults\preferences\prefs.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\manifest.xml, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins.json, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\1.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\102.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\104.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\13.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\14.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\16.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\17.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\177.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\180.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\182.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\183.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\192.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\195.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\200.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\207.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\21.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\22.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\220.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\221.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\223.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\226.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\234.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\246.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\262.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\263.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\268.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\273.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\28.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\281.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\300.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\4.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\47.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\64.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\7.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\72.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\78.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\9.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\91.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\93.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\plugins\98.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\userCode\background.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\extensionData\userCode\extension.js, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\locale\en-US\translations.dtd, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button1.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button2.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button3.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button4.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\button5.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\crossrider_statusbar.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\icon128.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\icon16.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\icon24.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\icon48.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\panelarrow-up.png, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\popup.html, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\skin.css, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\extensions\1853a82e-ce44-4a8c-a6fe-9bcf74a65575@4b6b1c16-5f0a-4ef0-866f-b063e235ef97.com\skin\update.css, In Quarantäne, [1f684fc9522ad75fc24a896e27db26da],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.T, C:\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll, In Quarantäne, [177083951b61fc3ad39c43c8768d40c0],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\GoogleCrashHandler.exe, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\GoogleUpdate.exe, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\GoogleUpdateBroker.exe, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\GoogleUpdateHelper.msi, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\GoogleUpdateOnDemand.exe, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\goopdate.dll, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\goopdateres_en.dll, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\npGoogleUpdate4.dll, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\psmachine.dll, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.GlobalUpdate.A, C:\Users\Yannic\AppData\Local\Temp\comh.159844\psuser.dll, In Quarantäne, [b2d5c652027aab8b34577f8c0ef55ba5],
PUP.Optional.CrossRider.A, C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "14903d36ca7c55e83fbcfa731cc09ed4");), Ersetzt,[c8bf22f6cdaf8aaccf169fc111f43bc5]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) AdwCleaner.txt Code:
# AdwCleaner v4.001 - Bericht erstellt am 24/10/2014 um 20:04:25
# Aktualisiert 20/10/2014 von Xplode
# Datenbank : 2014-10-23.2
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Yannic - R2D2
# Gestartet von : C:\Users\Yannic\Downloads\AdwCleaner_4.001.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Yannic\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Startfenster.lnk
Datei Gefunden : C:\Users\Yannic\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Startfenster.lnk
Datei Gefunden : C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\searchplugins\11-suche.xml
Datei Gefunden : C:\Users\Yannic\Favorites\Startfenster.lnk
Ordner Gefunden : C:\Program Files (x86)\globalUpdate
Ordner Gefunden : C:\Users\Yannic\AppData\Local\globalUpdate
Ordner Gefunden : C:\Users\Yannic\AppData\Roaming\RHEng
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\GlobalUpdate
Schlüssel Gefunden : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\GlobalUpdate
Schlüssel Gefunden : [x64] HKCU\Software\InstalledBrowserExtensions
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gefunden : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gefunden : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{06E58E5E-F8CB-4049-991E-A41C03BD419E}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{100EB1FD-D03E-47FD-81F3-EE91287F9465}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{258C9770-1713-4021-8D7E-1F184A2BD754}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{43D9E6F0-1776-4897-AE14-ECEDECBAFEC0}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{5A074B29-F830-49DE-A31B-5BB9D7F6B407}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{C451C08A-EC37-45DF-AAAD-18B51AB5E837}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{DCC70A83-E184-40A3-906B-779AF5E941C4}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{06E58E5E-F8CB-4049-991E-A41C03BD419E}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{100EB1FD-D03E-47FD-81F3-EE91287F9465}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{258C9770-1713-4021-8D7E-1F184A2BD754}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{43D9E6F0-1776-4897-AE14-ECEDECBAFEC0}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{5A074B29-F830-49DE-A31B-5BB9D7F6B407}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{855F3B16-6D32-4FE6-8A56-BBB695989046}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{BDEA95CF-F0E6-41E0-BD3D-B00F39A4E939}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{C451C08A-EC37-45DF-AAAD-18B51AB5E837}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{DCC70A83-E184-40A3-906B-779AF5E941C4}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17344
Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] - hxxp://www.startfenster.de
-\\ Mozilla Firefox v32.0.3 (x86 de)
*************************
AdwCleaner[R0].txt - [10686 octets] - [24/10/2014 20:04:25]
########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [10747 octets] ########## JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.21.2014:1)
OS: Windows 8.1 x64
Ran by Yannic on 24.10.2014 at 20:11:24,81
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\Yannic\favorites\links\startfenster.lnk"
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Yannic\AppData\Roaming\mozilla\firefox\profiles\dihxil7q.default\prefs.js
user_pref("extensions.a1853a82ece444a8ca6fe9bcf74a655754b6b1c165f0a4ef0866fb063e235ef97com60804.60804.internaldb.Resources_meta.value", "%7B%22popup.html%22%3A%7B%22id%22%3A82
user_pref("extensions.a1853a82ece444a8ca6fe9bcf74a655754b6b1c165f0a4ef0866fb063e235ef97com60804.60804.internaldb.Resources_resource_824814.value", "%22%3C%21DOCTYPE%20html%3E%
user_pref("extensions.a1853a82ece444a8ca6fe9bcf74a655754b6b1c165f0a4ef0866fb063e235ef97com60804.60804.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A
user_pref("extensions.crossrider.bic", "14903d36ca7c55e83fbcfa731cc09ed4");
Emptied folder: C:\Users\Yannic\AppData\Roaming\mozilla\firefox\profiles\dihxil7q.default\minidumps [11 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 24.10.2014 at 20:16:09,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST.txt
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-10-2014
Ran by Yannic (administrator) on R2D2 on 24-10-2014 20:17:01
Running from C:\Users\Yannic\Downloads
Loaded Profile: Yannic (Available profiles: Yannic)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
(Conexant Systems, Inc) C:\Program Files\CONEXANT\SAII\SmartAudio.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSPanel.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [911576 2013-10-30] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\Windows\system32\DptfPolicyLpmServiceHelper.exe [114048 2013-10-18] (Intel Corporation)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3216032 2013-12-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\ASUSWSLoader.exe [63296 2013-08-16] ()
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1282632 2013-07-23] (CANON INC.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Startup: C:\Users\Yannic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.0.3.226\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.0.3.226\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.0.3.226\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB
SearchScopes: HKLM - {F61CC357-9D05-4042-A131-1DECCE2EAC4E} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - {F61CC357-9D05-4042-A131-1DECCE2EAC4E} URL = hxxp://www.sm.de/?q={searchTerms}
BHO: Radio Canyon -> {11111111-1111-1111-1111-110611081104} -> C:\Program Files (x86)\Radio Canyon\Radio Canyon-bho64.dll No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default
FF SearchEngineOrder.1: SuchMaschine
FF Homepage: www.ecosia.de
FF Keyword.URL: hxxp://www.sm.de/?q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\searchplugins\search_engine.xml
FF SearchPlugin: C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Yannic\AppData\Roaming\Mozilla\Firefox\Profiles\dihxil7q.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-28]
FF Extension: UITBAutoInstaller - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\{edd7fc99-d65c-4979-85c2-ddeed30c50c7} [2014-10-11]
Chrome:
=======
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-08-29] (ASUS)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.0.3.226\AsusWSWinService.exe [71680 2013-08-16] (ASUS Cloud Corporation) [File not signed]
R2 DptfParticipantProcessorService; C:\Windows\system32\DptfParticipantProcessorService.exe [117704 2013-10-18] (Intel Corporation)
R2 DptfPolicyConfigTDPService; C:\Windows\system32\DptfPolicyConfigTDPService.exe [116680 2013-10-18] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\Windows\system32\DptfPolicyCriticalService.exe [148160 2013-10-18] (Intel Corporation)
R2 DptfPolicyLpmService; C:\Windows\system32\DptfPolicyLpmService.exe [126952 2013-10-18] (Intel Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227936 2013-11-09] (WildTangent)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [827392 2013-09-02] (Intel(R) Corporation) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-10-23] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-10-23] (Intel Corporation)
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-03-14] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-11-20] ()
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-03-06] (Microsoft Corporation)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2013-11-20] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [70928 2013-12-12] (ASUS Corporation)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113664 2013-12-16] (ASIX Electronics Corp.)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [140600 2013-07-22] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1408824 2013-10-18] (Motorola Solutions, Inc.)
R3 DptfDevDram; C:\Windows\system32\DRIVERS\DptfDevDram.sys [145640 2013-10-18] (Intel Corporation)
R3 DptfDevPch; C:\Windows\system32\DRIVERS\DptfDevPch.sys [116752 2013-10-18] (Intel Corporation)
R3 DptfDevProc; C:\Windows\system32\DRIVERS\DptfDevProc.sys [289744 2013-10-18] (Intel Corporation)
R3 DptfManager; C:\Windows\system32\DRIVERS\DptfManager.sys [494296 2013-10-18] (Intel Corporation)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [142280 2013-10-18] (Intel Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-06] ( )
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-10-23] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3609568 2013-12-25] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R2 plctrl; C:\Program Files\ASUS\P4G\plctrl.sys [14136 2013-08-29] (Windows (R) Win 7 DDK provider)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
U0 msahci; system32\drivers\msahci.sys
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-24 20:16 - 2014-10-24 20:16 - 00001565 _____ () C:\Users\Yannic\Desktop\JRT.txt
2014-10-24 20:16 - 2014-10-24 20:16 - 00000000 ____D () C:\Users\Yannic\Downloads\FRST-OlderVersion
2014-10-24 20:11 - 2014-10-24 20:11 - 00000000 ____D () C:\Windows\ERUNT
2014-10-24 20:10 - 2014-10-24 20:10 - 01706144 _____ (Thisisu) C:\Users\Yannic\Downloads\JRT(1).exe
2014-10-24 20:07 - 2014-10-24 20:07 - 00010924 _____ () C:\Users\Yannic\Desktop\AdwCleaner[R0].txt
2014-10-24 20:04 - 2014-10-24 20:07 - 00000000 ____D () C:\AdwCleaner
2014-10-24 20:03 - 2014-10-24 20:03 - 00049424 _____ () C:\Users\Yannic\Desktop\maleware.txt
2014-10-24 19:08 - 2014-10-24 19:09 - 01706144 _____ (Thisisu) C:\Users\Yannic\Downloads\JRT.exe
2014-10-24 19:08 - 2014-10-24 19:08 - 01962496 _____ () C:\Users\Yannic\Downloads\AdwCleaner_4.001.exe
2014-10-24 19:07 - 2014-10-24 20:02 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-24 19:07 - 2014-10-24 19:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-24 19:06 - 2014-10-24 19:07 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-24 19:06 - 2014-10-24 19:06 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-24 19:06 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-24 19:06 - 2014-10-01 11:11 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-24 19:06 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-24 19:05 - 2014-10-24 19:06 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\Yannic\Downloads\mbam-setup-2.0.3.1025.exe
2014-10-24 19:04 - 2014-10-24 19:04 - 00001286 _____ () C:\Users\Yannic\Desktop\Revo Uninstaller.lnk
2014-10-24 19:04 - 2014-10-24 19:04 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-10-24 19:03 - 2014-10-24 19:04 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Yannic\Downloads\revosetup95.exe
2014-10-23 12:18 - 2014-10-23 12:18 - 00541986 _____ () C:\Users\Yannic\Downloads\eduroam-w8-RAU(2).exe
2014-10-23 12:08 - 2014-10-23 12:08 - 00541986 _____ () C:\Users\Yannic\Downloads\eduroam-w8-RAU(1).exe
2014-10-23 12:07 - 2014-10-23 12:07 - 00541986 _____ () C:\Users\Yannic\Downloads\eduroam-w8-RAU.exe
2014-10-20 15:44 - 2014-10-20 15:44 - 00380416 _____ () C:\Users\Yannic\Downloads\Gmer-19357(1).exe
2014-10-20 15:35 - 2014-10-20 15:35 - 00380416 _____ () C:\Users\Yannic\Downloads\Gmer-19357.exe
2014-10-20 15:21 - 2014-10-20 15:28 - 00031894 _____ () C:\Users\Yannic\Downloads\Addition.txt
2014-10-20 15:20 - 2014-10-24 20:17 - 00014526 _____ () C:\Users\Yannic\Downloads\FRST.txt
2014-10-20 15:19 - 2014-10-24 20:17 - 00000000 ____D () C:\FRST
2014-10-20 15:18 - 2014-10-24 20:16 - 02112000 _____ (Farbar) C:\Users\Yannic\Downloads\FRST64.exe
2014-10-20 15:18 - 2014-10-20 15:18 - 00000474 _____ () C:\Users\Yannic\Downloads\defogger_disable.log
2014-10-20 15:18 - 2014-10-20 15:18 - 00000000 _____ () C:\Users\Yannic\defogger_reenable
2014-10-20 15:17 - 2014-10-20 15:17 - 00050477 _____ () C:\Users\Yannic\Downloads\Defogger.exe
2014-10-19 21:14 - 2014-10-20 15:11 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-10-19 11:09 - 2014-10-10 00:16 - 00678400 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-19 11:09 - 2014-10-09 00:09 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-19 11:09 - 2014-09-19 03:24 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-19 11:09 - 2014-09-04 02:10 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\winbici.dll
2014-10-19 11:09 - 2014-09-04 01:57 - 00921600 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-10-19 11:09 - 2014-09-04 01:49 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2014-10-19 11:07 - 2014-09-13 08:02 - 02779648 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-19 11:07 - 2014-09-13 07:30 - 03117568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-16 15:35 - 2014-09-28 00:25 - 04183040 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-16 15:35 - 2014-09-13 08:29 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-16 15:35 - 2014-09-13 07:49 - 00068608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-16 15:35 - 2014-08-29 03:58 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-10-16 15:35 - 2014-08-29 01:56 - 02646016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-10-16 15:35 - 2014-08-29 01:47 - 02321920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-10-16 15:33 - 2014-09-26 00:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-16 15:33 - 2014-09-26 00:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-16 15:33 - 2014-09-26 00:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-16 15:33 - 2014-09-26 00:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-16 15:33 - 2014-09-26 00:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-16 15:33 - 2014-09-26 00:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-16 15:33 - 2014-09-19 04:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-16 15:33 - 2014-09-19 03:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-16 15:33 - 2014-09-19 03:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-16 15:33 - 2014-09-19 03:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-16 15:33 - 2014-09-19 03:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-16 15:33 - 2014-09-19 03:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-16 15:33 - 2014-09-19 03:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-16 15:33 - 2014-09-19 03:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-16 15:33 - 2014-09-19 03:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-16 15:33 - 2014-09-19 03:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-16 15:33 - 2014-09-19 02:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-16 15:33 - 2014-09-19 02:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-16 15:33 - 2014-09-19 02:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-16 15:33 - 2014-09-19 02:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-16 15:33 - 2014-09-19 02:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-16 15:33 - 2014-09-19 02:42 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-16 15:33 - 2014-09-19 02:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-16 15:33 - 2014-09-19 02:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-16 15:33 - 2014-09-19 02:20 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-16 15:33 - 2014-09-19 02:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-16 15:33 - 2014-09-19 01:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-16 15:33 - 2014-09-19 01:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-16 15:33 - 2014-09-19 01:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-16 15:33 - 2014-09-19 01:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-16 15:32 - 2014-09-08 05:15 - 00054752 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-10-16 15:32 - 2014-09-08 03:46 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-10-16 15:32 - 2014-09-08 03:46 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-10-16 15:32 - 2014-09-08 02:08 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-10-16 15:32 - 2014-09-08 02:07 - 00137728 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-10-16 15:32 - 2014-09-08 02:05 - 03448320 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-10-16 15:32 - 2014-09-08 02:04 - 00388608 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2014-10-16 15:32 - 2014-09-08 02:04 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-10-16 15:32 - 2014-09-08 02:03 - 01702400 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-10-16 15:32 - 2014-09-08 02:03 - 00839680 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-10-16 15:32 - 2014-09-08 01:59 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-10-16 15:32 - 2014-09-08 01:59 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-10-16 15:32 - 2014-09-08 01:56 - 00672256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-10-16 15:32 - 2014-09-08 01:56 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-10-16 15:32 - 2014-09-04 02:12 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-16 15:32 - 2014-09-04 02:01 - 00514048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-16 15:31 - 2014-08-16 06:08 - 21195616 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-10-16 15:31 - 2014-08-16 06:08 - 01507648 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-10-16 15:31 - 2014-08-16 06:01 - 01710184 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-10-16 15:31 - 2014-08-16 05:58 - 01112512 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-10-16 15:31 - 2014-08-16 05:57 - 02498880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-10-16 15:31 - 2014-08-16 05:57 - 00428864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-10-16 15:31 - 2014-08-16 05:16 - 18722600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-10-16 15:31 - 2014-08-16 05:16 - 01205976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\propsys.dll
2014-10-16 15:31 - 2014-08-16 05:03 - 01467384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2014-10-16 15:31 - 2014-08-16 03:31 - 00838144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-10-16 15:31 - 2014-08-16 03:04 - 00359424 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2014-10-16 15:31 - 2014-08-16 02:58 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\SystemEventsBrokerServer.dll
2014-10-16 15:31 - 2014-08-16 02:53 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\httpprxm.dll
2014-10-16 15:31 - 2014-08-16 02:46 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\ProximityService.dll
2014-10-16 15:31 - 2014-08-16 02:45 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2014-10-16 15:31 - 2014-08-16 02:43 - 00321024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2014-10-16 15:31 - 2014-08-16 02:43 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\adhsvc.dll
2014-10-16 15:31 - 2014-08-16 02:31 - 00914432 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-10-16 15:31 - 2014-08-16 02:31 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\pcsvDevice.dll
2014-10-16 15:31 - 2014-08-16 02:29 - 00249344 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-16 15:31 - 2014-08-16 02:23 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-10-16 15:31 - 2014-08-16 02:22 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
2014-10-16 15:31 - 2014-08-16 02:22 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveShell.dll
2014-10-16 15:31 - 2014-08-16 02:19 - 00189952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-16 15:31 - 2014-08-16 02:18 - 04758528 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
2014-10-16 15:31 - 2014-08-16 02:17 - 08757760 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2014-10-16 15:31 - 2014-08-16 02:14 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SkyDriveShell.dll
2014-10-16 15:31 - 2014-08-16 02:13 - 06649344 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-16 15:31 - 2014-08-16 02:13 - 05902848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2014-10-16 15:31 - 2014-08-16 02:13 - 00840192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2014-10-16 15:31 - 2014-08-16 02:11 - 00920064 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-10-16 15:31 - 2014-08-16 02:10 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
2014-10-16 15:31 - 2014-08-16 02:08 - 05777408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-16 15:31 - 2014-08-16 02:07 - 00756224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-10-16 15:31 - 2014-08-01 01:22 - 00388729 _____ () C:\Windows\system32\ApnDatabase.xml
2014-10-11 18:28 - 2014-10-11 18:28 - 00000000 __SHD () C:\Users\Yannic\AppData\Local\EmieUserList
2014-10-11 18:28 - 2014-10-11 18:28 - 00000000 __SHD () C:\Users\Yannic\AppData\Local\EmieSiteList
2014-10-11 18:25 - 2014-10-11 18:25 - 00000000 ____D () C:\Users\Yannic\AppData\Roaming\TuneUp Software
2014-10-11 18:25 - 2014-10-11 18:25 - 00000000 ____D () C:\Users\Yannic\AppData\Local\TuneUp Software
2014-10-11 18:23 - 2014-10-11 18:26 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-10-11 18:23 - 2014-10-11 18:23 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-10-11 18:21 - 2014-10-11 18:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-10-11 18:21 - 2014-10-11 18:21 - 00000000 ____D () C:\Program Files (x86)\WEB.DE MailCheck
2014-10-11 18:21 - 2014-10-11 18:21 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-10-11 18:20 - 2014-10-11 18:21 - 00000000 ____D () C:\Users\Yannic\AppData\Roaming\DVDVideoSoft
2014-10-11 18:17 - 2014-10-11 18:20 - 31386984 _____ (DVDVideoSoft Ltd. ) C:\Users\Yannic\Downloads\FreeYouTubeToMP3Converter_3.12.46.923.exe
2014-10-06 14:30 - 2014-09-22 08:42 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-26 11:52 - 2014-09-26 11:52 - 00000000 ____D () C:\Users\Yannic\Documents\Studienstiftung
2014-09-24 23:34 - 2014-10-11 18:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-09-24 16:21 - 2014-10-06 10:50 - 00003718 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2014-09-24 16:21 - 2014-09-24 16:21 - 00003476 _____ () C:\Windows\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-24 20:18 - 2014-08-20 05:09 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2271421671-2185954834-4090823298-1001
2014-10-24 20:12 - 2014-08-19 23:39 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-24 20:11 - 2014-08-20 05:05 - 00000074 _____ () C:\Users\Yannic\AppData\Roaming\sp_data.sys
2014-10-24 20:09 - 2014-08-28 17:29 - 00000000 __RDO () C:\Users\Yannic\OneDrive
2014-10-24 20:08 - 2013-12-13 05:57 - 00050970 _____ () C:\Windows\PFRO.log
2014-10-24 20:08 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-24 20:08 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-10-24 20:07 - 2014-06-11 18:15 - 01343454 _____ () C:\Users\Public\CAFADEBUG.log
2014-10-24 20:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-10-24 19:58 - 2014-08-20 05:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-24 19:26 - 2014-06-11 18:16 - 01780928 _____ () C:\Windows\WindowsUpdate.log
2014-10-24 17:45 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-10-24 17:38 - 2014-08-20 05:43 - 00003918 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{6757FBCF-9917-461A-B7D5-44844D50589E}
2014-10-23 16:39 - 2014-08-20 05:04 - 00000000 ____D () C:\Users\Yannic
2014-10-23 12:16 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-10-20 15:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\MediaViewer
2014-10-20 15:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\FileManager
2014-10-20 15:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\Camera
2014-10-19 11:14 - 2014-08-31 19:47 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-19 11:14 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-10-18 20:03 - 2013-08-22 16:44 - 00484280 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-18 19:38 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-10-18 19:38 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\WinStore
2014-10-17 16:40 - 2014-09-11 21:37 - 00000000 ____D () C:\Users\Yannic\Documents\Studium
2014-10-11 18:10 - 2013-12-13 13:27 - 00804838 _____ () C:\Windows\system32\perfh013.dat
2014-10-11 18:10 - 2013-12-13 13:27 - 00164936 _____ () C:\Windows\system32\perfc013.dat
2014-10-11 18:10 - 2013-12-13 13:11 - 00808820 _____ () C:\Windows\system32\perfh00C.dat
2014-10-11 18:10 - 2013-12-13 13:11 - 00161790 _____ () C:\Windows\system32\perfc00C.dat
2014-10-11 18:10 - 2013-12-13 13:04 - 00773008 _____ () C:\Windows\system32\perfh007.dat
2014-10-11 18:10 - 2013-12-13 13:04 - 00162310 _____ () C:\Windows\system32\perfc007.dat
2014-10-11 18:10 - 2013-12-13 06:09 - 03696918 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-11 18:06 - 2013-08-22 16:46 - 00024687 _____ () C:\Windows\setupact.log
2014-10-10 15:25 - 2014-09-14 12:05 - 00073216 ___SH () C:\Users\Yannic\Desktop\Thumbs.db
2014-10-09 21:53 - 2014-08-20 10:36 - 00000000 ____D () C:\Users\Yannic\Scans
2014-10-06 14:31 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-10-06 13:28 - 2014-06-11 18:28 - 00000000 ____D () C:\ProgramData\McAfee
2014-10-06 13:24 - 2013-08-22 17:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-10-06 12:13 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-09-30 00:45 - 2013-08-22 17:38 - 00706016 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-09-30 00:45 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-09-28 14:47 - 2014-08-26 18:14 - 00000000 ____D () C:\Users\Yannic\Documents\Fussball
2014-09-24 16:21 - 2014-06-11 18:12 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS
Some content of TEMP:
====================
C:\Users\Yannic\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\Yannic\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Yannic\AppData\Local\Temp\PrefJsonCpp.exe
C:\Users\Yannic\AppData\Local\Temp\Quarantine.exe
C:\Users\Yannic\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Yannic\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\Yannic\AppData\Local\Temp\sqlite3.dll
C:\Users\Yannic\AppData\Local\Temp\sqlite3.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-06 11:11
==================== End Of Log ============================ --- --- ---
vielen Dank
highflyers |