Zitronentee | 02.11.2014 21:35 | Hallo schrauber,
vielen Dank für die Antwort! Wir haben alles nach Anweisung ausgeführt.
Hier die Dateien: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 02.11.2014
Suchlauf-Zeit: 20:11:25
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.3.1025
Malware Datenbank: v2014.11.02.05
Rootkit Datenbank: v2014.11.01.02
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Mark
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 383754
Verstrichene Zeit: 20 Min, 2 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\CrashMon.exe, 5504, Löschen bei Neustart, [f30ab97dbfbdb6807649b3ab8b78a15f]
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\UpdaterService.exe, 1660, Löschen bei Neustart, [f30ab97dbfbdb6807649b3ab8b78a15f]
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\Salus.exe, 1824, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4]
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\upfst_de_180.exe, 4800, Löschen bei Neustart, [9c617abcadcf12247aa6769cb94a7a86]
Module: 4
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\ProtocolFilters.dll, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\libeay32.dll, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nfapi.dll, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\ssleay32.dll, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
Registrierungsschlüssel: 86
PUP.Optional.QuickShare.A, HKLM\SOFTWARE\CLASSES\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKLM\SOFTWARE\CLASSES\IESmartBar.BHO, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\IESmartBar.BHO, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.QuickShare.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}, In Quarantäne, [807d9a9c0c70c96df32931b45aa8966a],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [31ccf93d3c406fc73d7016cffd0554ac],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{733413F4-5FB9-4EE9-8536-BF7AB1731A19}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3DD26F46-6B41-49B2-878E-1883411BBB59}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3DD26F46-6B41-49B2-878E-1883411BBB59}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{733413F4-5FB9-4EE9-8536-BF7AB1731A19}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.TermTutor.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [0cf17cba04780c2a0cd25951d131e11f],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}, In Quarantäne, [7b823105e8944cea8c7de603d32f7a86],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, In Quarantäne, [7b823105e8944cea8c7de603d32f7a86],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [7b823105e8944cea8c7de603d32f7a86],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [7b823105e8944cea8c7de603d32f7a86],
PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{03771AEF-400D-4A13-B712-25878EC4A3F5}, In Quarantäne, [7b823105e8944cea8c7de603d32f7a86],
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, In Quarantäne, [42bb39fd7408f4427d5007a5fe04da26],
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, In Quarantäne, [42bb39fd7408f4427d5007a5fe04da26],
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, In Quarantäne, [42bb39fd7408f4427d5007a5fe04da26],
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, In Quarantäne, [42bb39fd7408f4427d5007a5fe04da26],
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, In Quarantäne, [42bb39fd7408f4427d5007a5fe04da26],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [5da054e2c0bc92a42cdafeebcc369b65],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [5da054e2c0bc92a42cdafeebcc369b65],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [5da054e2c0bc92a42cdafeebcc369b65],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [7b82181e5923e74f8ac52587fc0607f9],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [7b82181e5923e74f8ac52587fc0607f9],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [b845b68016663df9772cc0f0be447d83],
PUP.Optional.Salus.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Salus, In Quarantäne, [9c6105315c200a2c57a3e9495ba86799],
PUP.Optional.UniversalUpdater.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UniversalUpdater, In Quarantäne, [f30ab97dbfbdb6807649b3ab8b78a15f],
PUP.Optional.BrowserChampion.A, HKLM\SOFTWARE\WOW6432NODE\Browser Champion, In Quarantäne, [d32a9b9b77059c9a77b9a1943ac96c94],
PUP.Optional.ClearThink.A, HKLM\SOFTWARE\WOW6432NODE\ClearThink, In Quarantäne, [ca333afc9fdd77bfb5eac6d5788ca15f],
PUP.Optional.Salus.A, HKLM\SOFTWARE\WOW6432NODE\Salus, In Quarantäne, [609d61d5bfbdac8a074e072bf01302fe],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SmdmF, In Quarantäne, [7d802214dd9fe551e55bab89e61dc739],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [8f6e33035f1d2e08ba8d93059f659f61],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [f4095fd7ee8e4bebb8fb73e2689b29d7],
PUP.Optional.CouponArific.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CouponArificService64, In Quarantäne, [ae4fab8b4735b383716ece5854af44bc],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [31cc41f50775ef4792fb2cfbe12260a0],
PUP.Optional.AddLyrics, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WEBINSTR, In Quarantäne, [35c8a88e0676cd6900f3ba7449bae31d],
PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQVP-3.5V29.09, In Quarantäne, [7885fd39c0bce94d4a7573b6996a08f8],
PUP.Optional.InternetSpeedChecker, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Internet Speed Checker, In Quarantäne, [cc3181b54a325cda597b68cd20e359a7],
PUP.Optional.HDVid.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\TheHDvid-Codec V10, In Quarantäne, [c43957df93e9142223af5adf4eb5c13f],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, In Quarantäne, [c439092dfb8153e3dac138410ef6ca36],
PUP.Optional.ClearThink.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ClearThink, In Quarantäne, [18e538fe6418be78118f9efd2cd8b14f],
PUP.Optional.FreeSoftToday.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\freesofttoday, In Quarantäne, [56a7a98da8d4fa3cc9639604b84cf60a],
PUP.Optional.StormWatchApp.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\StormWatchApp, In Quarantäne, [5da0fb3bb7c5bf772dae3eeaaa59a957],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupHpUISoft, In Quarantäne, [8d709f97fd7f0c2a28140c2838cb33cd],
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TutoTag, In Quarantäne, [cb32d2647a021a1c7908afec778de719],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\BlockAndSurf, In Quarantäne, [f20b2e08b3c946f0a1181b1c4fb4a45c],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [47b664d2ceaef244176f612b8c78619f],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [0cf1b97d92ea77bfbf4d4b17d033e61a],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [37c645f1d1abd462004b4038f1133bc5],
PUP.Optional.SuperFish.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, In Quarantäne, [f508b680255780b6722d98a6ea19ae52],
PUP.Optional.Qone8, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [a558f73f027ab383469a592a16eeb749],
PUP.Optional.FastStart.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, In Quarantäne, [3ebfd95d7efeba7cb0e708274bb827d9],
PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, In Quarantäne, [8d70d264f08c2d09a10df8a154b0dd23],
PUP.Optional.SuperFish.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, In Quarantäne, [43bacd693745979fb0ef3806b152e51b],
PUP.Optional.Qone8, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [ac51d85eafcdb3838858e0a35ea612ee],
PUP.Optional.SuperFish.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com, In Quarantäne, [897494a2720a58de0b9478c646bd3cc4],
PUP.Optional.Qone8, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [936a37ff2b513cfad7095c27976d57a9],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [30cd0a2c5b2126109c5e52c041c2d12f],
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, In Quarantäne, [30cd0a2c5b2126109c5e52c041c2d12f],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{034A356D-1278-4F29-B449-8CCC36B1C0CC}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\CLASSES\CLSID\{034A356D-1278-4F29-B449-8CCC36B1C0CC}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{EB431D2A-E2E0-B8C5-E6A9-4510D06F71D2}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{8EF3BF22-85A6-7638-2591-B480B3F35E1D}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{8EF3BF22-85A6-7638-2591-B480B3F35E1D}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{EB431D2A-E2E0-B8C5-E6A9-4510D06F71D2}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{034A356D-1278-4F29-B449-8CCC36B1C0CC}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{034A356D-1278-4F29-B449-8CCC36B1C0CC}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{034A356D-1278-4F29-B449-8CCC36B1C0CC}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{034A356D-1278-4F29-B449-8CCC36B1C0CC}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{034A356D-1278-4F29-B449-8CCC36B1C0CC}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{034A356D-1278-4F29-B449-8CCC36B1C0CC}, In Quarantäne, [f40941f5c5b7280e10a37ebf7491639d],
Registrierungswerte: 14
PUP.Optional.UniversalUpdater.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|CrashMon, "C:\Program Files (x86)\Universal Updater\CrashMon.exe" "UniversalUpdater" "hxxp://log.data-url.com/crash/", In Quarantäne, [f30ab97dbfbdb6807649b3ab8b78a15f]
PUP.Optional.Salus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Salus CrashMon, "C:\Program Files (x86)\Salus\CrashMon.exe" "Salus.exe" "hxxp://log.data-url.com/salus/crash", In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4]
PUP.Optional.Salus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Salus, C:\Program Files (x86)\Salus\Salus.exe, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4]
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [48b561d5abd140f62cfffc352bd8dc24]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [8d70ef47007c191d34f79f928281ec14]
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_de_180, "C:\Program Files (x86)\fst_de_180\fst_de_180.exe", In Quarantäne, [996421152c50c96d20cd8fbf54af3ac6]
PUP.Optional.ConvertAd.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ConvertAd, C:\Users\Mark\AppData\Local\ConvertAd\ConvertAd.exe, In Quarantäne, [41bc7eb8c6b6ec4a17a2d356af54e020]
PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default\extensions\faststartff@gmail.com, In Quarantäne, [b5485cdaf884f442b4ac732430d4da26]
PUP.Optional.UniversalUpdater.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UNIVERSALUPDATER|ImagePath, C:\Program Files (x86)\Universal Updater\UpdaterService.exe, In Quarantäne, [ec119f9777054cea0db3afaf986ba35d]
PUP.Optional.AddLyrics, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WEBINSTR|DisplayName, webinstr, In Quarantäne, [35c8a88e0676cd6900f3ba7449bae31d]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0J1L2U1C1H1Q0R2X1L1R1P0B1P, In Quarantäne, [37c645f1d1abd462004b4038f1133bc5]
PUP.Optional.FastStart.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, In Quarantäne, [3ebfd95d7efeba7cb0e708274bb827d9]
PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, ShoppingHelper, In Quarantäne, [8d70d264f08c2d09a10df8a154b0dd23]
PUP.Optional.FreeSoftToday.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCE|upfst_de_180.exe, C:\Users\Mark\AppData\Local\fst_de_180\upfst_de_180.exe -runonce, In Quarantäne, [9c617abcadcf12247aa6769cb94a7a86]
Registrierungsdaten: 26
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98&q={searchTerms}),Ersetzt,[be3f3df92359989e6d2c74b9fd088080]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98),Ersetzt,[3ebf0e28601c77bf0790f439b74e6a96]
PUP.Optional.WebSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98&q={searchTerms}),Ersetzt,[a756bd79f28aa88e52577f38758cdf21]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[26d7a393542881b517a461d622e334cc]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98&q={searchTerms}),Ersetzt,[2dd063d3ee8e00360b8e5bd219ec56aa]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98),Ersetzt,[a459b77fc5b785b17423b7764db827d9]
PUP.Optional.WebSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98&q={searchTerms}),Ersetzt,[59a4e5514c303105ddcc9c1b42bfeb15]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[86777abc2c50270f0ead1b1c2cd94db3]
PUP.Optional.SnapDo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI-&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI-&q={searchTerms}),Ersetzt,[e11c063082fadf5708f82507a95c6f91]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[3fbe1a1c91eb3ef8778c022a8f764bb5]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98),Ersetzt,[d22b1d19bac2b87e574576b7c54024dc]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98),Ersetzt,[b84586b0304c69cdefa92eff18ed25db]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[76873105314b7cba5ca647e5d62fb947]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[07f6d363215b51e5b05587a501041fe1]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[af4e2e08aad25dd90df969c3d035cc34]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[f10c9e98d6a685b1cb36042840c5639d]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[2ad3a096116b39fdf310b17b6d9823dd]
PUP.Optional.WebsSearches.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1411418543&from=slbnew&uid=WDCXWD7500BPVX-22JC3T0_WD-WX71E33LDU98LDU98),Ersetzt,[708dc571e79544f2e5b30c21dc298c74]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[e51895a147353ef8e02282aacd3834cc]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[fa03a88ecfadd264986d77b5b055c838]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[b14c5bdba8d4e155d03634f88b7a20e0]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[ce2f67cfb5c7c67011f0012bda2b0000]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[8677f1457efed660b9499894d62fe61a]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[00fd6acceb916acc1aebe5478580718f]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[f8053600f08cde58fa0c5bd1d03556aa]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-2613370363-1168659386-1177263031-500-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMAMVs8OpDiAI4zRqymQ2rVgPi5DmnVF2pop_OWXUh3mniwHWDmE04oCDF5stYdBxg6tbMb-9FUHe0Mk2bJLniwcYM04eIBGneEJdXEh1olagZ-E2fecw0Ob6iDXL8JI5&q={searchTerms}),Ersetzt,[35c889adf78562d4e51ca4882dd8ce32]
Ordner: 37
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater, Löschen bei Neustart, [f30ab97dbfbdb6807649b3ab8b78a15f],
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\CrashReports, In Quarantäne, [f30ab97dbfbdb6807649b3ab8b78a15f],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nss, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\Salus, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\Salus\SSL, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
Rogue.Multiple, C:\ProgramData\374311380, In Quarantäne, [b84596a04e2e7cba29618d5c679b5ba5],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, In Quarantäne, [fffed0666913b3832ce0c24f30d334cc],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [fffed0666913b3832ce0c24f30d334cc],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [fffed0666913b3832ce0c24f30d334cc],
PUP.Optional.SystemSpeedup, C:\Users\Mark\AppData\Roaming\Systweak\ssd, In Quarantäne, [45b83303d2aade580f9ed53cab581fe1],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180, Löschen bei Neustart, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\Download, In Quarantäne, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\fst_de_180, In Quarantäne, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\fst_de_180\1.20, In Quarantäne, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.196222, In Quarantäne, [30cd0a2c5b2126109c5e52c041c2d12f],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.461240, In Quarantäne, [b944ee4892ea0e28ad4d829037ccab55],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\smdmf, In Quarantäne, [3bc23df96f0d5ed8b1868491c0436d93],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\smdmf\x64, In Quarantäne, [3bc23df96f0d5ed8b1868491c0436d93],
PUP.Optional.Linkey.A, C:\Users\Mark\AppData\Local\Linkey\IEExtension, In Quarantäne, [0bf268ceed8fcd69c17975a0798a659b],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector, In Quarantäne, [cf2eef47700c84b2103784937192c33d],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\2.1.1000.13665, In Quarantäne, [cf2eef47700c84b2103784937192c33d],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures, In Quarantäne, [cf2eef47700c84b2103784937192c33d],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Mark\AppData\Roaming\Systweak\Advanced-System-Protector, In Quarantäne, [7a8394a20775f93dcd7a66b1eb187d83],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Mark\AppData\Roaming\Systweak\Advanced-System-Protector\2.1.1000.13665, In Quarantäne, [7a8394a20775f93dcd7a66b1eb187d83],
PUP.Optional.SettingsManager.A, C:\Users\Mark\AppData\Roaming\FirefoxToolbar\Settings Manager, In Quarantäne, [6d904ee8dca020164f2544d6689ba55b],
PUP.Optional.Astromenda.A, C:\Users\Mark\AppData\Roaming\WSE_Astromenda, In Quarantäne, [7984c571512bd561d251fe1e2bd8926e],
PUP.Optional.Astromenda.A, C:\Users\Mark\AppData\Roaming\WSE_Astromenda\icons_3.2.1.5, In Quarantäne, [7984c571512bd561d251fe1e2bd8926e],
PUP.Optional.Astromenda.A, C:\Users\Mark\AppData\Roaming\WSE_Astromenda\UpdateProc, In Quarantäne, [7984c571512bd561d251fe1e2bd8926e],
PUP.Optional.FLVMPlayer, C:\Program Files (x86)\FLVM Player, In Quarantäne, [9c61270f99e38bab64da20fdae5504fc],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro, In Quarantäne, [f10c0432cfad0a2cbd901b0230d354ac],
PUP.Optional.CouponArific, C:\Program Files\CouponArific, In Quarantäne, [c03d55e15f1d9c9a23c75dc8689b60a0],
PUP.Optional.CouponArific, C:\Program Files\CouponArific\SSL, In Quarantäne, [c03d55e15f1d9c9a23c75dc8689b60a0],
PUP.Optional.CouponArific.A, C:\Program Files (x86)\35556262-902E-49AE-8622-66E14F1F041C, In Quarantäne, [9f5e5fd73b413303818a071fd132db25],
Dateien: 125
PUP.Optional.CrossRider.A, C:\Program Files (x86)\FLVPlayer\hdfextsetup.exe, In Quarantäne, [c23b77bfaad25bdbeb4624a921e011ef],
PUP.Optional.Firseria, C:\Program Files (x86)\PC Speed Up\Uninstall_PCSpeedUp.exe, In Quarantäne, [db2252e417656accd22e4f7f8c7521df],
PUP.Optional.MyPCBackup.A, C:\Users\Mark\AppData\Local\Temp\CloudBackup7567.exe, In Quarantäne, [6994fb3b2557a5919f73677534cd0cf4],
PUP.Optional.MyPCBackup.A, C:\Users\Mark\AppData\Local\Temp\BackupSetup.exe, In Quarantäne, [b449cc6a314bee480012b329e1204eb2],
PUP.Optional.IBryte, C:\Users\Mark\AppData\Local\Temp\bs.exe, In Quarantäne, [b24bd95dd6a6d363ee36fac40ff214ec],
PUP.Optional.MyPCBackup.A, C:\Users\Mark\AppData\Local\Temp\CloudBackup5309.exe, In Quarantäne, [68951422116b5cda888a5587d52c6a96],
PUP.Optional.Conduit.A, C:\Users\Mark\AppData\Local\Temp\SearchProtectINT.exe, In Quarantäne, [b34a4aec720a48eea541b57e06fbc43c],
PUP.Optional.CrossRider, C:\Users\Mark\AppData\Local\Temp\Install_30458\cr.exe, In Quarantäne, [2cd15bdb3d3f3ff7205d4091da27ec14],
PUP.Optional.CrossRider, C:\Users\Mark\AppData\Local\Temp\Install_30458\iwebar.exe, In Quarantäne, [d32ab3835824be78037ad2ff639e60a0],
PUP.Optional.SmartBar, C:\Users\Mark\AppData\Local\Temp\MSI790B.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [fc010531b2ca3ff79bb9e648ee12669a],
PUP.Optional.GratifyingApps.A, C:\Users\Mark\AppData\Local\Temp\nstF1B1.tmp\BCSetup.exe, In Quarantäne, [1be2eb4b512bde58519b3f829e63db25],
PUP.Optional.OutBrowse, C:\Users\Mark\AppData\Local\Temp\nsx43FE.tmp\rece.dll, In Quarantäne, [619cea4ce39976c0f9a8e6e3d9286898],
PUP.Optional.StormWatch.A, C:\Users\Mark\AppData\Local\Temp\91412180967\1_Offer_14.exe, In Quarantäne, [17e6ee480b71241227640253b05042be],
PUP.Optional.StormWatch.A, C:\Users\Mark\AppData\Local\Temp\91412180986\1_Offer_14.exe, In Quarantäne, [e8157fb7fa8254e2c7c4afa68f71da26],
PUP.Optional.OutBrowse, C:\Users\Mark\AppData\Local\Temp\nsd9182.tmp\rece.dll, In Quarantäne, [d429e650cab2f244b5ec7851b44d31cf],
PUP.Optional.VOPackage.Gen, C:\Users\Mark\AppData\Local\Temp\n2554\VOPackage.exe, In Quarantäne, [7f7e57dfc7b5bd79ebdb7859f20fc33d],
Trojan.MSIL.Bladabindi, C:\Users\Mark\AppData\Local\Temp\n5715\Installer.exe, In Quarantäne, [b74634024933c175de564f78a85945bb],
PUP.Optional.Salus.A, C:\Users\Mark\AppData\Local\Temp\n5715\salus_1_0_0_1.exe, In Quarantäne, [7c8164d294e8aa8cf11b239433ce02fe],
PUP.Optional.SearchHijacker.A, C:\Users\Mark\AppData\Local\Temp\n7532\webssearches_1209-c61a659a.exe, In Quarantäne, [29d4f83e7ffd171f7d5ccde807fa3ec2],
PUP.Optional.BPlug, C:\Users\Mark\AppData\Local\Temp\is281105613\1049053_stp.EXE, In Quarantäne, [b746a5915c20fc3aa0f2dbe66a9733cd],
PUP.Optional.SearchHijacker.A, C:\Users\Mark\AppData\Local\Temp\is45637729\2237253_stp\cor_sweet-page.exe, In Quarantäne, [35c8f640df9d96a029b006afcb365da3],
PUP.Optional.Salus.A, C:\WINDOWS\Temp\9AB4.tmp, In Quarantäne, [b5483bfb99e375c1b390a524fe0307f9],
PUP.Optional.Linkey.A, C:\Users\Mark\AppData\Local\Linkey\IEExtension\iedll64.dll, In Quarantäne, [7c81c2744933c07690179ee416eb8080],
PUP.Optional.SmartBar, C:\WINDOWS\Installer\MSI790B.tmp, In Quarantäne, [05f873c382fac86e9bb92608c13fd12f],
PUP.Optional.Astromenda.A, C:\WINDOWS\System32\Tasks\WSE_Astromenda, In Quarantäne, [9667f14568149b9b06352cfe52b11be5],
PUP.Optional.Astromenda.A, C:\WINDOWS\Tasks\WSE_Astromenda.job, In Quarantäne, [1de078be47353cfa61db53d7a95ac838],
PUP.Optional.Salus.A, C:\WINDOWS\System32\Drivers\salus.sys, In Quarantäne, [9c6105315c200a2c57a3e9495ba86799],
PUP.Optional.RegCleanerPro, C:\WINDOWS\System32\Tasks\ASP, In Quarantäne, [33ca15214339de58fb4e0b2a41c2966a],
PUP.Optional.BlockAndSurf.A, C:\WINDOWS\System32\Tasks\BlockAndSurf Update, In Quarantäne, [27d62c0aef8d80b6ba363f006b987789],
PUP.Optional.Trovi.A, C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default\searchplugins\trovi-search.xml, In Quarantäne, [4db063d3e99381b5b38dd27837cc39c7],
PUP.Optional.BlockAndSurf.A, C:\WINDOWS\Tasks\BlockAndSurf Update.job, In Quarantäne, [3fbe87af87f577bfaa9d5df76f941ee2],
PUP.Optional.DefaultSearch.A, C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default\searchplugins\default-search.xml, In Quarantäne, [fb02bf775c20d46287719fb508fb0ff1],
PUP.Optional.DefaultSearch.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml, In Quarantäne, [42bbd2643d3f59ddbb3e292be221728e],
PUP.Optional.WebsSearches.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml, In Quarantäne, [de1f9c9a0e6eed49a70e63f25da6cd33],
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\settings.json, In Quarantäne, [f30ab97dbfbdb6807649b3ab8b78a15f],
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\CrashMon.exe, Löschen bei Neustart, [f30ab97dbfbdb6807649b3ab8b78a15f],
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\CrashMon.log, In Quarantäne, [f30ab97dbfbdb6807649b3ab8b78a15f],
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\UpdaterService.exe, Löschen bei Neustart, [f30ab97dbfbdb6807649b3ab8b78a15f],
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\UpdaterService.log, Löschen bei Neustart, [f30ab97dbfbdb6807649b3ab8b78a15f],
PUP.Optional.UniversalUpdater.A, C:\Program Files (x86)\Universal Updater\CrashReports\UpdaterService1.4.3.19.dmp, In Quarantäne, [f30ab97dbfbdb6807649b3ab8b78a15f],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\ProtocolFilters.dll, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\CrashMon.exe, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\libeay32.dll, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nfapi.dll, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\Salus.exe, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\Salus.log, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\ssleay32.dll, Löschen bei Neustart, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nss\certutil.exe, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nss\mozcrt19.dll, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nss\nspr4.dll, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nss\nss3.dll, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nss\plc4.dll, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nss\plds4.dll, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nss\smime3.dll, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\nss\softokn3.dll, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\Salus\SSL\Salus CA.cer, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.Salus.A, C:\Program Files (x86)\Salus\Salus\SSL\Salus CA.pvk, In Quarantäne, [7786f0469fddcb6b6d4369321de75ca4],
PUP.Optional.CouponArific.A, C:\Program Files (x86)\35556262-902E-49AE-8622-66E14F1F041C\arrmeapsie64.exe, In Quarantäne, [ae4fab8b4735b383716ece5854af44bc],
PUP.Optional.AddLyrics, C:\WINDOWS\System32\Drivers\webinstr.sys, In Quarantäne, [35c8a88e0676cd6900f3ba7449bae31d],
Rogue.Multiple, C:\ProgramData\374311380\BIT1938.tmp, In Quarantäne, [b84596a04e2e7cba29618d5c679b5ba5],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-09-21[21-42-02-671].log, In Quarantäne, [fffed0666913b3832ce0c24f30d334cc],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-09-22[22-43-24-178].log, In Quarantäne, [fffed0666913b3832ce0c24f30d334cc],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [fffed0666913b3832ce0c24f30d334cc],
PUP.Optional.SystemSpeedup, C:\Users\Mark\AppData\Roaming\Systweak\ssd\SSDPTstub.exe, In Quarantäne, [45b83303d2aade580f9ed53cab581fe1],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\upfst_de_180.cyl, In Quarantäne, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\upfst_de_180.exe, Löschen bei Neustart, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\user_profil.cyp, In Quarantäne, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\Download\majmp_gentleeu.exe, In Quarantäne, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\fst_de_180\1.20\cnf.cyl, In Quarantäne, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.FreeSoftToday.A, C:\Users\Mark\AppData\Local\fst_de_180\fst_de_180\1.20\eorezo.cyl, In Quarantäne, [9c617abcadcf12247aa6769cb94a7a86],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.196222\GoogleCrashHandler.exe, In Quarantäne, [30cd0a2c5b2126109c5e52c041c2d12f],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.196222\GoogleUpdate.exe, In Quarantäne, [30cd0a2c5b2126109c5e52c041c2d12f],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\GoogleCrashHandler.exe, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\GoogleUpdate.exe, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\GoogleUpdateBroker.exe, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\GoogleUpdateHelper.msi, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\GoogleUpdateOnDemand.exe, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\goopdate.dll, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\goopdateres_en.dll, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\npGoogleUpdate4.dll, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\psmachine.dll, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.264971\psuser.dll, In Quarantäne, [be3f290db4c89a9c8a70957dc63d2bd5],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\GoogleCrashHandler.exe, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\GoogleUpdate.exe, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\GoogleUpdateBroker.exe, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\GoogleUpdateHelper.msi, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\GoogleUpdateOnDemand.exe, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\goopdate.dll, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\goopdateres_en.dll, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\npGoogleUpdate4.dll, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\psmachine.dll, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.406286\psuser.dll, In Quarantäne, [e11c67cf027ade588a7068aa07fce31d],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.461240\GoogleCrashHandler.exe, In Quarantäne, [b944ee4892ea0e28ad4d829037ccab55],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.461240\GoogleUpdate.exe, In Quarantäne, [b944ee4892ea0e28ad4d829037ccab55],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.461240\GoogleUpdateBroker.exe, In Quarantäne, [b944ee4892ea0e28ad4d829037ccab55],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.461240\GoogleUpdateHelper.msi, In Quarantäne, [b944ee4892ea0e28ad4d829037ccab55],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\GoogleCrashHandler.exe, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\GoogleUpdate.exe, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\GoogleUpdateBroker.exe, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\GoogleUpdateHelper.msi, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\GoogleUpdateOnDemand.exe, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\goopdate.dll, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\goopdateres_en.dll, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\npGoogleUpdate4.dll, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\psmachine.dll, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.GlobalUpdate.A, C:\Users\Mark\AppData\Local\Temp\comh.474771\psuser.dll, In Quarantäne, [c33aa88ec8b4310525d5769c13f08c74],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\smdmf\del_DM_LL_nsaA3E9.dll, In Quarantäne, [3bc23df96f0d5ed8b1868491c0436d93],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\smdmf\x64\del_DM_LL_nsaA3E9.dll, In Quarantäne, [3bc23df96f0d5ed8b1868491c0436d93],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Mark\AppData\Roaming\Systweak\Advanced-System-Protector\Settings.db, In Quarantäne, [7a8394a20775f93dcd7a66b1eb187d83],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Mark\AppData\Roaming\Systweak\Advanced-System-Protector\2.1.1000.13665\ASPLog.txt, In Quarantäne, [7a8394a20775f93dcd7a66b1eb187d83],
PUP.Optional.Astromenda.A, C:\Users\Mark\AppData\Roaming\WSE_Astromenda\icons_3.2.1.5\ctr.ico, In Quarantäne, [7984c571512bd561d251fe1e2bd8926e],
PUP.Optional.Astromenda.A, C:\Users\Mark\AppData\Roaming\WSE_Astromenda\UpdateProc\bkup.dat, In Quarantäne, [7984c571512bd561d251fe1e2bd8926e],
PUP.Optional.Astromenda.A, C:\Users\Mark\AppData\Roaming\WSE_Astromenda\UpdateProc\config.dat, In Quarantäne, [7984c571512bd561d251fe1e2bd8926e],
PUP.Optional.Astromenda.A, C:\Users\Mark\AppData\Roaming\WSE_Astromenda\UpdateProc\info.dat, In Quarantäne, [7984c571512bd561d251fe1e2bd8926e],
PUP.Optional.Astromenda.A, C:\Users\Mark\AppData\Roaming\WSE_Astromenda\UpdateProc\STTL.DAT, In Quarantäne, [7984c571512bd561d251fe1e2bd8926e],
PUP.Optional.Astromenda.A, C:\Users\Mark\AppData\Roaming\WSE_Astromenda\UpdateProc\TTL.DAT, In Quarantäne, [7984c571512bd561d251fe1e2bd8926e],
PUP.Optional.ShopperPro, C:\ProgramData\ShopperPro\spbihe.js, In Quarantäne, [f10c0432cfad0a2cbd901b0230d354ac],
PUP.Optional.CouponArific.A, C:\Program Files (x86)\35556262-902E-49AE-8622-66E14F1F041C\libeay32.dll, In Quarantäne, [9f5e5fd73b413303818a071fd132db25],
PUP.Optional.CouponArific.A, C:\Program Files (x86)\35556262-902E-49AE-8622-66E14F1F041C\nfapi.dll, In Quarantäne, [9f5e5fd73b413303818a071fd132db25],
PUP.Optional.CouponArific.A, C:\Program Files (x86)\35556262-902E-49AE-8622-66E14F1F041C\ProtocolFilters.dll, In Quarantäne, [9f5e5fd73b413303818a071fd132db25],
PUP.Optional.CouponArific.A, C:\Program Files (x86)\35556262-902E-49AE-8622-66E14F1F041C\ssleay32.dll, In Quarantäne, [9f5e5fd73b413303818a071fd132db25],
PUP.Optional.QuickStart.A, C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), Ersetzt,[5e9fee48d8a4bb7b42d09bd1dc29e020]
PUP.Optional.Trovi, C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.defaultenginename", "Trovi search");), Ersetzt,[ac518fa7562686b068fd6804c441629e]
PUP.Optional.Trovi, C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.selectedEngine", "Trovi search");), Ersetzt,[50ad122498e41323e086a0cc2fd6e61a]
PUP.Optional.Trovi.A, C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3319709&octid=EB_ORIGINAL_CTID&ISID=M36242DC1-51E2-41E1-BEF7-92104E5ABCF7&SearchSource=55&CUI=&UM=6&UP=SP7DE26576-1157-464E-B46D-0977A5C43144&SSPV=");), Ersetzt,[da233303b3c968ced51eb2ba21e4a060]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
# AdwCleaner v4.002 - Bericht erstellt am 02/11/2014 um 21:14:35
# DB v2014-10-26.6
# Aktualisiert 27/10/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Mark - ACER
# Gestartet von : C:\Users\Mark\Desktop\AdwCleaner_4.002.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : netfilter64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Mark\AppData\Roaming\1H1Q
Ordner Gelöscht : C:\Users\Mark\AppData\Roaming\ap_logs
Ordner Gelöscht : C:\Users\Mark\AppData\Local\Astromenda
Ordner Gelöscht : C:\Users\Mark\AppData\Roaming\FirefoxToolbar
Ordner Gelöscht : C:\Program Files (x86)\FlvPlayer
Ordner Gelöscht : C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FlvPlayer
Ordner Gelöscht : C:\Program Files (x86)\FoxTab
Ordner Gelöscht : C:\Users\Mark\AppData\Local\globalUpdate
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InetStat
Ordner Gelöscht : C:\Users\Mark\AppData\Local\Linkey
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro v3.2
Ordner Gelöscht : C:\Users\Mark\AppData\Roaming\Optimizer Pro
Ordner Gelöscht : C:\Users\Mark\Documents\Optimizer Pro
Ordner Gelöscht : C:\Program Files (x86)\pc speed up
Ordner Gelöscht : C:\Program Files (x86)\Settings Manager
Ordner Gelöscht : C:\Users\Public\Documents\ShopperPro
Ordner Gelöscht : C:\Users\Mark\AppData\LocalLow\SiteRanker
Ordner Gelöscht : C:\Users\Sabiye\AppData\LocalLow\SiteRanker
Ordner Gelöscht : C:\SmootherWeb
Ordner Gelöscht : C:\Users\Mark\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\ProgramData\Systweak
Ordner Gelöscht : C:\WINDOWS\SysWOW64\config\systemprofile\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Mark\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Program Files (x86)\Yawtix
Ordner Gelöscht : C:\Users\Mark\AppData\Local\Temp\Yawtix
Ordner Gelöscht : C:\Users\Mark\AppData\Local\Temp\ClearThink
Ordner Gelöscht : C:\Users\Mark\AppData\Local\CrashRpt
Ordner Gelöscht : C:\ProgramData\ttpErfectceoupuOn
Ordner Gelöscht : C:\Program Files (x86)\ttpErfectceoupuOn
Datei Gelöscht : C:\Users\Mark\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\END
Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe
Datei Gelöscht : C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default\invalidprefs.js
Datei Gelöscht : C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default\user.js
***** [ Tasks ] *****
Task Gelöscht : APSnotifierPP1
Task Gelöscht : APSnotifierPP2
Task Gelöscht : APSnotifierPP3
Task Gelöscht : ASP
Task Gelöscht : LaunchSignup
Task Gelöscht : YTDownloader
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
Verknüpfung Desinfiziert : C:\Users\Mark\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Mark\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{56ECA8F3-137B-5B92-3D29-079D46759E21}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\.
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\..9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{71eaa7b3-4428-4727-8884-c48b565064a2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{71eaa7b3-4428-4727-8884-c48b565064a2}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{71eaa7b3-4428-4727-8884-c48b565064a2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\clicup
Schlüssel Gelöscht : HKCU\Software\InetStat
Schlüssel Gelöscht : HKCU\Software\Linkey
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\Tutorials
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\AdvertisingSupport
Schlüssel Gelöscht : HKLM\SOFTWARE\InstallCore
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Tutorials
Schlüssel Gelöscht : HKLM\SOFTWARE\TermTutor
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\SmootherWeb
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\ShopperPro
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.17116
-\\ Mozilla Firefox v33.0.2 (x86 de)
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [8766 octets] - [02/11/2014 20:49:43]
AdwCleaner[S0].txt - [8511 octets] - [02/11/2014 21:14:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8571 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.5 (10.31.2014:1)
OS: Windows 8 x64
Ran by Mark on 02.11.2014 at 21:23:00,31
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ytdownloader
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update clearthink
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util clearthink
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Mark\AppData\Roaming\mozilla\firefox\profiles\0r42q1se.default\prefs.js
user_pref("extensions.xUrnMXk4nzZwkm3G.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11
Emptied folder: C:\Users\Mark\AppData\Roaming\mozilla\firefox\profiles\0r42q1se.default\minidumps [7 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 02.11.2014 at 21:26:01,42
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-11-2014
Ran by Mark (administrator) on ACER on 02-11-2014 21:28:19
Running from C:\Users\Mark\Desktop
Loaded Profile: Mark (Available profiles: Mark & Sabiye & Administrator)
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\WINDOWS\System32\igfxCUIService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Dritek System INC.) C:\WINDOWS\RfBtnSvc64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
(Microsoft Corporation) C:\WINDOWS\System32\dasHost.exe
(Intel Corporation) C:\WINDOWS\System32\igfxEM.exe
(Intel Corporation) C:\WINDOWS\System32\igfxHK.exe
(Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(Spotify Ltd) C:\Users\Mark\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\WINDOWS\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
() C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\WINDOWS\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.17074_none_6233bc1f5106b696\TiWorker.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [124720 2014-10-09] (Avira Operations GmbH & Co. KG)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-01-28] ( (Atheros Communications))
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2613370363-1168659386-1177263031-1001\...\Run: [Spotify Web Helper] => C:\Users\Mark\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1514040 2014-10-03] (Spotify Ltd)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-2613370363-1168659386-1177263031-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
SearchScopes: HKLM - {B8D7FB5F-AA1F-4CDD-8C7F-D2394C074E47} URL = hxxp://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_dsites_14_38_ie&cd=2XzuyEtN2Y1L1QzuyDyE0B0E0FyByEtB0A0D0C0Czz0D0A0BtN0D0Tzu0SzyzyyDtN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyEtA0CtD0CyDzz0EtG0B0AtAtBtGtA0CyEtCtGtDzytD0AtGyByB0AtA0A0EyC0CtB0FtCyD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyBzy0BzyyBtB0EyEtGtC0E0EyDtGyEtC0CyDtG0BtCtB0EtG0EtCtByEtDyB0DtAzz0D0ByE2Q&cr=1526756493&ir=
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Mark\AppData\Roaming\Mozilla\Firefox\Profiles\0r42q1se.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
Chrome:
=======
CHR Profile: C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-10-28]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227456 2013-01-28] (Qualcomm Atheros Commnucations)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [162096 2014-10-09] (Avira Operations GmbH & Co. KG)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-19] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [469648 2012-11-16] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-15] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [255040 2014-08-25] (WildTangent)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-20] (Intel Corporation)
S3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [43520 2012-07-26] (Microsoft Corporation)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [634368 2012-07-26] (Microsoft Corporation)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2013-08-24] (Dritek System INC.)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18432 2012-07-26] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-01-28] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
S3 IntcDAud; C:\Windows\system32\DRIVERS\IntcDAud.sys [342528 2012-06-19] (Intel(R) Corporation) [File not signed]
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-10-01] (Malwarebytes Corporation)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2013-08-24] (Dritek System Inc.)
S3 RFCOMM; C:\Windows\System32\drivers\rfcomm.sys [156672 2013-03-01] (Microsoft Corporation) [File not signed]
S3 IntcAzAudAddService; \SystemRoot\system32\drivers\RTKVHD64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-02 21:28 - 2014-11-02 21:28 - 00000000 ____D () C:\Users\Mark\Desktop\FRST-OlderVersion
2014-11-02 21:26 - 2014-11-02 21:26 - 00001541 _____ () C:\Users\Mark\Desktop\JRT.txt
2014-11-02 21:22 - 2014-11-02 21:22 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-11-02 21:21 - 2014-11-02 21:22 - 01706359 _____ (Thisisu) C:\Users\Mark\Desktop\JRT.exe
2014-11-02 21:19 - 2014-11-02 21:19 - 00001005 _____ () C:\Users\Mark\Desktop\AdwCleaner[S0].txt - Verknüpfung.lnk
2014-11-02 20:49 - 2014-11-02 21:14 - 00000000 ____D () C:\AdwCleaner
2014-11-02 20:47 - 2014-11-02 20:47 - 01998336 _____ () C:\Users\Mark\Desktop\AdwCleaner_4.002.exe
2014-11-02 20:41 - 2014-11-02 20:41 - 00060808 _____ () C:\Users\Mark\Desktop\mbam.txt
2014-11-02 20:10 - 2014-11-02 21:17 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-11-02 20:10 - 2014-11-02 20:10 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-02 20:10 - 2014-11-02 20:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-02 20:09 - 2014-11-02 20:10 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-02 20:09 - 2014-11-02 20:09 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-02 20:09 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-11-02 20:09 - 2014-10-01 11:11 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-11-02 20:09 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-11-02 20:05 - 2014-11-02 20:05 - 00001272 _____ () C:\Users\Mark\Desktop\Revo Uninstaller.lnk
2014-11-02 20:05 - 2014-11-02 20:05 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-11-02 20:04 - 2014-11-02 20:04 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Mark\Desktop\revosetup95.exe
2014-11-02 10:01 - 2014-11-02 10:01 - 00023633 _____ () C:\Users\Mark\Desktop\Addition.txt
2014-11-02 10:00 - 2014-11-02 21:28 - 00009092 _____ () C:\Users\Mark\Desktop\FRST.txt
2014-11-02 09:59 - 2014-11-02 21:28 - 00000000 ____D () C:\FRST
2014-11-02 09:58 - 2014-11-02 21:28 - 02114560 _____ (Farbar) C:\Users\Mark\Desktop\FRST64.exe
2014-11-01 20:17 - 2014-11-01 20:18 - 00000000 ____D () C:\NPE
2014-11-01 20:15 - 2014-11-01 20:39 - 00000000 ____D () C:\Users\Mark\AppData\Local\NPE
2014-11-01 13:09 - 2014-11-01 13:09 - 00001167 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-01 13:09 - 2014-11-01 13:09 - 00001155 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-01 13:09 - 2014-11-01 13:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-10-29 23:19 - 2014-10-29 23:19 - 00000303 _____ () C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heimnetzgruppe.lnk
2014-10-28 21:43 - 2014-10-29 21:17 - 00000000 ____D () C:\WINDOWS\system32\AutoUpdateLicense
2014-10-28 20:29 - 2014-10-22 04:34 - 00010777 _____ () C:\WINDOWS\system32\AutoconfigV2.cab
2014-10-28 20:29 - 2014-10-22 04:33 - 00581016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AutoUpdate.exe
2014-10-28 20:29 - 2014-10-22 04:33 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationUI.exe
2014-10-28 20:29 - 2014-10-22 02:08 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-10-28 20:29 - 2014-10-22 02:08 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-28 20:29 - 2014-10-22 02:01 - 00695808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-10-28 20:29 - 2014-10-22 02:01 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2014-10-28 20:29 - 2014-10-22 02:01 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-10-28 20:29 - 2014-10-22 02:00 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2014-10-26 21:50 - 2014-10-26 21:51 - 00001568 _____ () C:\WINDOWS\comsetup.log
2014-10-26 21:14 - 2014-10-26 21:14 - 00013312 ___SH () C:\Users\Mark\Documents\Thumbs.db
2014-10-26 10:09 - 2014-10-26 10:09 - 04585472 _____ (Avira Operations GmbH & Co. KG) C:\Users\Mark\Downloads\avira_de_av___ws (1).exe
2014-10-26 10:09 - 2014-10-26 10:09 - 00001141 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-26 10:09 - 2014-10-26 10:09 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-26 10:09 - 2014-10-26 10:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-26 10:09 - 2014-10-26 10:09 - 00000000 ____D () C:\ProgramData\Avira
2014-10-26 10:09 - 2014-10-26 10:09 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-10-26 10:08 - 2014-10-30 12:25 - 00275080 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2014-10-26 10:08 - 2014-10-26 10:08 - 04585472 _____ (Avira Operations GmbH & Co. KG) C:\Users\Mark\Downloads\avira_de_av___ws.exe
2014-10-26 09:53 - 2014-10-26 09:53 - 00003090 _____ () C:\WINDOWS\System32\Tasks\{4BA85958-647D-4D3D-AC14-3B37BCBD526B}
2014-10-23 21:04 - 2014-11-01 13:08 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-23 21:04 - 2014-10-23 21:05 - 00000000 ____D () C:\Users\Mark\AppData\Local\Google
2014-10-19 19:10 - 2014-10-20 20:09 - 00000000 ____D () C:\ProgramData\LizardSales
2014-10-19 09:13 - 2014-10-20 20:09 - 00000000 ____D () C:\ProgramData\19c72af7068c06b2
2014-10-16 22:42 - 2014-10-17 19:20 - 00202752 ___SH () C:\Users\Mark\Desktop\Thumbs.db
2014-10-16 18:59 - 2014-10-16 18:59 - 00281784 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-10-16 18:32 - 2014-09-29 23:49 - 00705480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-10-16 18:32 - 2014-09-29 23:49 - 00104904 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-15 17:15 - 2014-09-18 00:24 - 02416128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2014-10-15 17:15 - 2014-09-17 23:56 - 02885120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2014-10-15 16:08 - 2014-07-12 05:41 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDRUM.DLL
2014-10-15 16:08 - 2014-07-12 05:41 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDYAK.DLL
2014-10-15 16:08 - 2014-07-12 05:41 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDTAT.DLL
2014-10-15 16:08 - 2014-07-12 05:41 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDRU1.DLL
2014-10-15 16:08 - 2014-07-12 05:41 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDRU.DLL
2014-10-15 16:08 - 2014-07-12 05:41 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDBASH.DLL
2014-10-15 16:08 - 2014-07-12 05:16 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDRUM.DLL
2014-10-15 16:08 - 2014-07-12 05:16 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDYAK.DLL
2014-10-15 16:08 - 2014-07-12 05:16 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDTAT.DLL
2014-10-15 16:08 - 2014-07-12 05:16 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDRU1.DLL
2014-10-15 16:08 - 2014-07-12 05:16 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDRU.DLL
2014-10-15 16:08 - 2014-07-12 05:15 - 00006144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDBASH.DLL
2014-10-15 16:08 - 2014-07-12 01:02 - 00478352 _____ () C:\WINDOWS\SysWOW64\locale.nls
2014-10-15 16:08 - 2014-07-12 01:00 - 00478352 _____ () C:\WINDOWS\system32\locale.nls
2014-10-15 16:08 - 2014-07-08 23:33 - 00181248 _____ (Microsoft Corp.) C:\WINDOWS\system32\Defrag.exe
2014-10-15 16:08 - 2014-07-08 23:32 - 01539584 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2014-10-15 16:08 - 2014-07-08 23:32 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2014-10-15 16:08 - 2014-07-08 23:30 - 01220608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2014-10-15 16:08 - 2014-07-07 06:52 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2014-10-15 16:08 - 2014-07-07 06:52 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2014-10-15 16:08 - 2014-07-04 11:52 - 00328000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2014-10-15 16:08 - 2014-07-03 02:59 - 01824784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2014-10-15 16:08 - 2014-07-03 01:30 - 01408952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2014-10-15 16:08 - 2014-06-28 08:01 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2014-10-15 16:08 - 2014-06-28 07:57 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2014-10-15 16:08 - 2014-06-28 07:56 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2014-10-15 16:08 - 2014-06-25 08:09 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2014-10-15 16:08 - 2014-06-25 08:07 - 01023488 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2014-10-15 16:08 - 2014-06-18 00:27 - 02032640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2014-10-15 16:08 - 2014-06-18 00:23 - 02238464 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2014-10-15 16:08 - 2014-06-13 00:34 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2014-10-15 16:08 - 2014-06-13 00:29 - 02146304 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2014-10-15 16:08 - 2014-06-11 15:47 - 02842112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2014-10-15 16:08 - 2014-06-11 05:40 - 02620928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2014-10-15 16:08 - 2014-06-10 23:44 - 01403896 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2014-10-15 16:08 - 2014-05-30 00:31 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2014-10-15 16:08 - 2014-05-30 00:03 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2014-10-15 16:08 - 2014-02-04 11:57 - 01271664 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2014-10-15 16:07 - 2014-09-20 06:16 - 19280896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-10-15 16:07 - 2014-09-13 06:29 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\packager.dll
2014-10-15 16:07 - 2014-09-13 05:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\packager.dll
2014-10-15 16:07 - 2014-09-03 03:48 - 00510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2014-10-15 16:07 - 2014-09-03 03:21 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2014-10-15 16:07 - 2014-07-07 06:53 - 01125376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2014-10-15 16:07 - 2014-07-07 06:52 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2014-10-15 16:07 - 2014-07-07 06:52 - 00724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2014-10-15 16:07 - 2014-07-07 06:52 - 00300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsta.dll
2014-10-15 16:07 - 2014-07-07 06:51 - 05982208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2014-10-15 16:07 - 2014-07-07 05:01 - 01049600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2014-10-15 16:07 - 2014-07-07 05:01 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winsta.dll
2014-10-15 16:07 - 2014-07-07 05:00 - 05095424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2014-10-15 16:07 - 2014-07-07 04:59 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aaclient.dll
2014-10-15 16:06 - 2014-09-28 05:18 - 04068352 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-10-15 16:06 - 2014-09-20 06:18 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-10-15 16:06 - 2014-09-20 06:17 - 02236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-10-15 16:06 - 2014-09-20 06:17 - 01407488 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-10-15 16:06 - 2014-09-20 06:17 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2014-10-15 16:06 - 2014-09-20 06:17 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 15399424 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 03959296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 02655232 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-10-15 16:06 - 2014-09-20 06:16 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-10-15 16:06 - 2014-09-20 06:15 - 01508864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-10-15 16:06 - 2014-09-20 06:15 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-10-15 16:06 - 2014-09-20 06:15 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 14368768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 13757952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 02861568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 01762816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 01180672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-10-15 16:06 - 2014-09-20 04:57 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-10-15 16:06 - 2014-09-20 04:56 - 01440768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-10-15 16:06 - 2014-09-20 04:56 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-10-15 16:06 - 2014-09-20 04:56 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-10-15 16:06 - 2014-09-20 04:38 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-10-15 16:06 - 2014-09-20 04:33 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-10-15 16:06 - 2014-09-20 02:06 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2014-10-15 16:06 - 2014-08-30 06:48 - 10115072 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-10-15 16:06 - 2014-08-30 06:46 - 02306560 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2014-10-15 16:06 - 2014-08-30 05:05 - 08858112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-10-15 16:06 - 2014-08-30 05:03 - 02037760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2014-10-15 16:06 - 2014-08-01 23:08 - 00388729 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2014-10-15 16:06 - 2014-07-24 14:50 - 00447296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2014-10-15 16:06 - 2014-07-17 00:28 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sscore.dll
2014-10-15 16:06 - 2014-07-16 23:59 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2014-10-15 16:06 - 2014-07-16 23:59 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscore.dll
2014-10-15 16:06 - 2014-07-12 07:45 - 01549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2014-10-15 16:06 - 2014-07-12 05:36 - 00674304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2014-10-15 16:06 - 2014-07-12 05:36 - 00211456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2014-10-15 16:06 - 2014-07-12 05:34 - 00404480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2014-10-15 16:06 - 2014-07-12 05:34 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2014-10-15 16:06 - 2014-06-28 07:57 - 01341952 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2014-10-15 16:06 - 2014-06-28 03:23 - 01126400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2014-10-03 14:10 - 2014-10-03 14:10 - 00000144 _____ () C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-02 21:28 - 2013-08-24 15:21 - 01878357 _____ () C:\WINDOWS\WindowsUpdate.log
2014-11-02 21:22 - 2014-09-21 20:17 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2613370363-1168659386-1177263031-1001
2014-11-02 21:21 - 2013-08-25 01:00 - 00753134 _____ () C:\WINDOWS\system32\perfh007.dat
2014-11-02 21:21 - 2013-08-25 01:00 - 00155826 _____ () C:\WINDOWS\system32\perfc007.dat
2014-11-02 21:21 - 2012-07-26 08:28 - 01745416 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-11-02 21:17 - 2012-07-26 08:22 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-11-02 21:16 - 2013-04-18 03:46 - 00349938 _____ () C:\WINDOWS\PFRO.log
2014-11-02 21:16 - 2012-07-26 06:26 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-11-02 21:14 - 2014-09-21 20:31 - 00001087 _____ () C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-11-02 21:14 - 2014-09-21 20:11 - 00000957 _____ () C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-02 21:00 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-11-02 20:39 - 2014-10-02 23:57 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-11-01 20:35 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Common Files\System
2014-11-01 19:40 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-11-01 13:10 - 2014-09-21 20:21 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-01 11:24 - 2014-09-21 20:11 - 00000000 ____D () C:\Users\Mark\AppData\Local\CrashDumps
2014-10-31 16:33 - 2014-09-22 21:43 - 00000000 ____D () C:\Users\Mark\AppData\Roaming\Spotify
2014-10-30 18:01 - 2013-12-15 01:47 - 00000000 ____D () C:\Users\Mark\Desktop\Telekomrechnungen
2014-10-30 17:55 - 2013-12-10 20:55 - 00000000 ____D () C:\Users\Mark\Downloads\Rechnungen Telekom
2014-10-30 17:24 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\rescache
2014-10-29 22:18 - 2014-09-27 20:09 - 00955904 ___SH () C:\Users\Mark\Downloads\Thumbs.db
2014-10-28 21:43 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\WinStore
2014-10-28 21:43 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-10-26 23:00 - 2014-09-24 16:19 - 00000000 ___HD () C:\$Windows.~BT
2014-10-26 22:14 - 2014-02-07 23:40 - 00000000 __SHD () C:\Recovery
2014-10-26 21:54 - 2014-09-21 20:04 - 00064773 _____ () C:\WINDOWS\diagwrn.xml
2014-10-26 21:54 - 2014-09-21 20:04 - 00064773 _____ () C:\WINDOWS\diagerr.xml
2014-10-26 21:54 - 2012-07-26 08:21 - 00686186 _____ () C:\WINDOWS\setupact.log
2014-10-26 21:53 - 2012-07-26 09:13 - 00003611 _____ () C:\WINDOWS\DtcInstall.log
2014-10-26 21:50 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\Registration
2014-10-26 21:36 - 2012-07-26 09:12 - 00000000 ____D () C:\WINDOWS\AUInstallAgent
2014-10-26 21:25 - 2014-09-21 20:09 - 00000000 ____D () C:\Users\Mark\AppData\Local\Packages
2014-10-26 10:08 - 2012-07-26 06:26 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-10-26 09:57 - 2013-04-18 05:36 - 00000000 ____D () C:\ProgramData\McAfee
2014-10-26 09:56 - 2013-04-18 05:36 - 00000000 ____D () C:\Program Files\mcafee
2014-10-26 09:56 - 2013-04-18 05:36 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-10-26 09:53 - 2012-07-26 09:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2014-10-23 23:02 - 2012-07-26 09:12 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-10-23 23:02 - 2012-07-26 08:52 - 00000000 ____D () C:\Program Files\Windows Journal
2014-10-22 20:22 - 2012-07-26 09:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-10-16 18:28 - 2014-09-24 19:25 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-10-16 18:28 - 2012-07-26 09:12 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-10-16 18:26 - 2014-09-24 19:24 - 103265616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-10-09 21:43 - 2014-09-22 21:44 - 00000000 ____D () C:\Users\Mark\AppData\Local\Spotify
2014-10-06 20:11 - 2014-09-29 22:42 - 00000451 _____ () C:\WINDOWS\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2014-10-06 19:00 - 2013-04-18 05:31 - 00000000 ____D () C:\Program Files (x86)\Intel
Some content of TEMP:
====================
C:\Users\Mark\AppData\Local\Temp\avgnt.exe
C:\Users\Mark\AppData\Local\Temp\babcabebbbce.exe
C:\Users\Mark\AppData\Local\Temp\bwvw_n1a.dll
C:\Users\Mark\AppData\Local\Temp\crossrider_uninstaller.exe
C:\Users\Mark\AppData\Local\Temp\optprosetup.exe
C:\Users\Mark\AppData\Local\Temp\Quarantine.exe
C:\Users\Mark\AppData\Local\Temp\sqlite3.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite24813.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite27342.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite29441.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite30974.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite35178.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite49474.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite50022.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite50849.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite51136.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite59590.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite61605.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite63611.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite66088.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite66355.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite67355.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite67673.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite72319.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite72499.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite78697.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite82926.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite84745.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite89281.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite93476.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite95969.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite96205.dll
C:\Users\Mark\AppData\Local\Temp\System.Data.SQLite97066.dll
C:\Users\Mark\AppData\Local\Temp\ttap2.dll
C:\Users\Mark\AppData\Local\Temp\ttap2.exe
C:\Users\Mark\AppData\Local\Temp\tu17p84.exe
C:\Users\Mark\AppData\Local\Temp\uoEK5.exe
C:\Users\Mark\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-01 19:37
==================== End Of Log ============================ --- --- ---
Wir schauen nun mal, ob sich Firefox wieder normal öffnen lässt.
Danke! |