Das hat nun endlich funktioniert :-D Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 21.04.2015
Suchlauf-Zeit: 15:49:54
Logdatei: mbam.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.04.21.03
Rootkit Datenbank: v2015.04.20.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: xxx
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 584417
Verstrichene Zeit: 22 Min, 6 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 40
PUP.Optional.SofTonic.A, HKU\S-1-5-21-4067268467-3182437459-1756596644-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}, In Quarantäne, [52e5ff709bef270f84301866e81be61a],
PUP.Optional.SofTonic.A, HKU\S-1-5-21-4067268467-3182437459-1756596644-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}, In Quarantäne, [52e5ff709bef270f84301866e81be61a],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataContainer, In Quarantäne, [45f257187b0fff37ed0afcc529da8c74],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataContainer.1, In Quarantäne, [cc6b97d8b8d259dda453418046bd7d83],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataController, In Quarantäne, [51e6432cbad00333f502536e50b3d32d],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataController.1, In Quarantäne, [0d2a98d73654dd59f9fe744d42c1f709],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTable, In Quarantäne, [3bfcd897305ae45247b06e53de258779],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTable.1, In Quarantäne, [4dea77f81f6be254698edfe231d2768a],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTableFields, In Quarantäne, [7eb9145be3a775c103f4dfe2d82be818],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTableFields.1, In Quarantäne, [7eb9fe71563437ffe2152998d03305fb],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTableHolder, In Quarantäne, [e05747287119c175db1ca21f1de69868],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.DataTableHolder.1, In Quarantäne, [c4733f30b9d189aded0acff2679c8e72],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.LSPLogic, In Quarantäne, [39febab5cfbbff37e80f259ccc37a858],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.LSPLogic.1, In Quarantäne, [39fea7c808823204787fcef31be88d73],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.ReadOnlyManager, In Quarantäne, [71c6026d9af0ef4776812998e51e2bd5],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.ReadOnlyManager.1, In Quarantäne, [f6414a2588020630a84ff1d03ec5966a],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.WFPController, In Quarantäne, [65d2125d85058ea8c136833e7093dc24],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\CLASSES\GambaliLib.WFPController.1, In Quarantäne, [a592fd725b2fbc7a4aad7d442fd4e51b],
PUP.Optional.Gambali.A, HKLM\SOFTWARE\CLASSES\APPID\Gambali.EXE, In Quarantäne, [d166234c79112b0bf8d7d2f0699a728e],
PUP.Optional.Gambali.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\Gambali.EXE, In Quarantäne, [e4534c23820873c303ccdee49f64c23e],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataContainer, In Quarantäne, [fb3cf9768cfea195bd3a4b76a75ccc34],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataContainer.1, In Quarantäne, [69ce6609602a81b5f3049b26be454bb5],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataController, In Quarantäne, [2e09254a4f3bd46293641fa2ba490df3],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataController.1, In Quarantäne, [1522e18e1b6ff640886f4f72d52ef60a],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTable, In Quarantäne, [f245db943b4fea4ca354d8e9f310c937],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTable.1, In Quarantäne, [d760f37c1e6c2214966102bf0ef5a45c],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTableFields, In Quarantäne, [f34493dc13776fc71addedd40ff4ac54],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTableFields.1, In Quarantäne, [cf68442bbdcdc76fd0278c35907314ec],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTableHolder, In Quarantäne, [57e095da9ceea98d8077566ba55eed13],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.DataTableHolder.1, In Quarantäne, [2314c7a88307b2845a9d60617e85e818],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.LSPLogic, In Quarantäne, [f542abc4bad0f6402ec98041dc27d729],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.LSPLogic.1, In Quarantäne, [cc6b3c337812b581ce290cb54ab9728e],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.ReadOnlyManager, In Quarantäne, [cd6a115e2a60a88e76818b361de6c43c],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.ReadOnlyManager.1, In Quarantäne, [0631333c3555360001f6843d1de625db],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.WFPController, In Quarantäne, [85b218571d6dca6c55a2dbe60003e917],
PUP.Optional.Gambali.C, HKLM\SOFTWARE\WOW6432NODE\CLASSES\GambaliLib.WFPController.1, In Quarantäne, [ec4b4629bcce8aacac4b9b26c43fbe42],
PUP.Optional.Gambali.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\Gambali.EXE, In Quarantäne, [87b0a9c6266426102ca3f0d2f90a946c],
PUP.Optional.MediaPlayer.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\Mediaa_Play_AIR_1.4, In Quarantäne, [2413511eed9d0135b6d606edd72c43bd],
PUP.Optional.PicBadges.A, HKU\S-1-5-21-4067268467-3182437459-1756596644-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\mgjkknncnlepghplinfpikcijdbmidbg, In Quarantäne, [64d31e519bef82b4e8d4c9027e85ac54],
PUP.Optional.Softonic.A, HKU\S-1-5-21-4067268467-3182437459-1756596644-500\SOFTWARE\APPDATALOW\SOFTWARE\softonic-de3, In Quarantäne, [c6713d327b0f6bcb2f321cb39271e31d],
Registrierungswerte: 5
PUP.Optional.SofTonic.A, HKU\S-1-5-21-4067268467-3182437459-1756596644-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}, 㣠Ã?Ã?dòJ¿Ã¯
f¶Âe, In Quarantäne, [52e5ff709bef270f84301866e81be61a]
PUP.Optional.SofTonic.A, HKU\S-1-5-21-4067268467-3182437459-1756596644-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}, In Quarantäne, [52e5ff709bef270f84301866e81be61a],
PUP.Optional.SofTonic.A, HKU\S-1-5-21-4067268467-3182437459-1756596644-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER\{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065}, In Quarantäne, [ee499cd33f4b33036e469ee0a360fe02],
PUP.Optional.SofTonic.A, HKU\S-1-5-21-4067268467-3182437459-1756596644-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}, In Quarantäne, [3502b0bf6a205bdba80cb5c9de2537c9],
PUP.Optional.Conduit.A, HKU\S-1-5-21-4067268467-3182437459-1756596644-500\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|URL, hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245, In Quarantäne, [2b0c71fedcaebe7862e515ae748f44bc]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 5
PUP.Optional.FoxySecure.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\b8k4buhw.default-1428421863067\extensions\fx@foxysecureKDJJHVLSDUVFU.com, In Quarantäne, [77c0c8a739510f270e40773d5fa4cc34],
PUP.Optional.FoxySecure.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\b8k4buhw.default-1428421863067\extensions\fx@foxysecureKDJJHVLSDUVFU.com\chrome, In Quarantäne, [77c0c8a739510f270e40773d5fa4cc34],
PUP.Optional.FoxySecure.A, C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\b8k4buhw.default-1428421863067\extensions\fx@foxysecureKDJJHVLSDUVFU.com\chrome\content, In Quarantäne, [77c0c8a739510f270e40773d5fa4cc34],
PUP.Optional.PicBadges.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg, In Quarantäne, [3ef9e18efc8ef34375ed7a4114ef9967],
PUP.Optional.PicBadges.A, C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg\1.8_0, In Quarantäne, [3ef9e18efc8ef34375ed7a4114ef9967],
Dateien: 12
PUP.Optional.DomalIQ.SID.A, C:\Users\xxx\Downloads\Setup.exe, In Quarantäne, [0037a0cf5f2b51e5d76e67d79571e51b],
PUP.Optional.FoxySecure.A, C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\b8k4buhw.default-1428421863067\extensions\fx@foxysecureKDJJHVLSDUVFU.com\chrome.manifest, In Quarantäne, [77c0c8a739510f270e40773d5fa4cc34],
PUP.Optional.FoxySecure.A, C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\b8k4buhw.default-1428421863067\extensions\fx@foxysecureKDJJHVLSDUVFU.com\install.rdf, In Quarantäne, [77c0c8a739510f270e40773d5fa4cc34],
PUP.Optional.FoxySecure.A, C:\Users\xxx\AppData\Roaming\Mozilla\Firefox\Profiles\b8k4buhw.default-1428421863067\extensions\fx@foxysecureKDJJHVLSDUVFU.com\chrome\content\background.js, In Quarantäne, [77c0c8a739510f270e40773d5fa4cc34],
PUP.Optional.FoxySecure.A, C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\b8k4buhw.default-1428421863067\extensions\fx@foxysecureKDJJHVLSDUVFU.com\chrome\content\background.xul, In Quarantäne, [77c0c8a739510f270e40773d5fa4cc34],
PUP.Optional.PicBadges.A, C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg\1.8_0\background.js, In Quarantäne, [3ef9e18efc8ef34375ed7a4114ef9967],
PUP.Optional.PicBadges.A, C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg\1.8_0\icon.png, In Quarantäne, [3ef9e18efc8ef34375ed7a4114ef9967],
PUP.Optional.PicBadges.A, C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg\1.8_0\icon128.png, In Quarantäne, [3ef9e18efc8ef34375ed7a4114ef9967],
PUP.Optional.PicBadges.A, C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg\1.8_0\icon16.png, In Quarantäne, [3ef9e18efc8ef34375ed7a4114ef9967],
PUP.Optional.PicBadges.A, C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg\1.8_0\icon48.png, In Quarantäne, [3ef9e18efc8ef34375ed7a4114ef9967],
PUP.Optional.PicBadges.A, C:\Users\xxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg\1.8_0\manifest.json, In Quarantäne, [3ef9e18efc8ef34375ed7a4114ef9967],
PUP.Optional.PicBadges.A, C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgjkknncnlepghplinfpikcijdbmidbg\1.8_0\trackPlugin.js, In Quarantäne, [3ef9e18efc8ef34375ed7a4114ef9967],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Versuche es jetzt dann noch einmal mit ESET
Nachdem ESET nun über 20 Std lief habe ich es bei 99% abgebrochen...da stand es nämlich heute Morgen bereits.
Herausgekommen ist das: Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=1f76f95bc6c5b24da10c142e59caa0f8
# engine=23492
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-04-22 01:21:18
# local_time=2015-04-22 03:21:18 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 76504 181338728 0 0
# scanned=436060
# found=19
# cleaned=0
# scan_time=74170
sh=01C53FBC0030066FE9032FEC431D9EA26B5811CC ft=1 fh=af8c82510ee8e748 vn="Win32/AlteredSoftware.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe.vir"
sh=0E7CC420B0BE38296EF8516DC3786361119F1F5F ft=1 fh=02f58beb2edcfbd2 vn="Win32/AlteredSoftware.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe.vir"
sh=01C53FBC0030066FE9032FEC431D9EA26B5811CC ft=1 fh=af8c82510ee8e748 vn="Win32/AlteredSoftware.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe.vir"
sh=A565AA91F7873179776579995E9F4D2B2894AE5A ft=1 fh=22e3a81795d8fb05 vn="Variante von Win32/AlteredSoftware.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe.vir"
sh=F1A0D0D29F924A24AF0F0521CF6F9A9150A10ECC ft=1 fh=22e3a817befc6b5a vn="Variante von Win32/AlteredSoftware.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe.vir"
sh=9E2BB88A6A67D7785C14FC594CB672E8C8C2872E ft=1 fh=c71c00112372d0ea vn="Variante von Win32/AlteredSoftware.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdate.dll.vir"
sh=0A6DCC2D1FD48FFD8E530E36853B99DCDF597257 ft=1 fh=d9cdf1c8ff17595a vn="Variante von Win32/AlteredSoftware.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\goopdateres_en.dll.vir"
sh=58FEF548C9FE5AB9F393BDFD0EDC49F240DA03D1 ft=1 fh=c71c001182a9b069 vn="Variante von Win32/AlteredSoftware.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll.vir"
sh=EDB4A6C7E75E18ACB805418EFFD78267BB2F37C4 ft=1 fh=c71c001126306ac8 vn="Variante von Win32/AlteredSoftware.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\psmachine.dll.vir"
sh=399CE73FBD27EABB303FD899656E3C66C55B3F29 ft=1 fh=c71c001160921a34 vn="Variante von Win32/AlteredSoftware.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\globalUpdate\Update\1.3.25.0\psuser.dll.vir"
sh=84D71ECEE62C4141F1D0B4A24D925F3EBA7180A8 ft=1 fh=737f51bd30d7d258 vn="Variante von Win32/MyPCBackup.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\DEL_MPCBClient.dll.vir"
sh=171D0DFAD4ABC8BFCFC3DE6AD9EB03DBA9CB60AC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.C evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\xxxx\AppData\Roaming\n8WoXTR.xBAD"
sh=171D0DFAD4ABC8BFCFC3DE6AD9EB03DBA9CB60AC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.C evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Users\xxx\AppData\Roaming\xqi4HgB8PWds.xBAD"
sh=3A177006C5DE14DA54414DD987C1BD59B35BBE7E ft=0 fh=0000000000000000 vn="Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\eMule\Incoming\Uniblue RegistryBooster 2011 5.0.12.1 + serial.rar"
sh=401D0F3679A4FFB9353F814E22C3E9E8924B130A ft=0 fh=0000000000000000 vn="Variante von Android/AdDisplay.Youmi.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\xxxx\Backup_Stairway\Messenger_1.2.2.apk"
sh=401D0F3679A4FFB9353F814E22C3E9E8924B130A ft=0 fh=0000000000000000 vn="Variante von Android/AdDisplay.Youmi.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\xxx\Documents\Backups\Backup_Handy\Messenger_1.2.2.apk"
sh=401D0F3679A4FFB9353F814E22C3E9E8924B130A ft=0 fh=0000000000000000 vn="Variante von Android/AdDisplay.Youmi.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\xxxx\Documents\Backups\Backup_Handy\neu_08.01.15\Messenger_1.2.2.apk"
sh=7539BAA7DBA23263EFF76D36F84B3343422CDE55 ft=0 fh=0000000000000000 vn="Variante von Android/AdDisplay.Youmi.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\xxxx\Documents\Backups\Backup_Wiko_1214\BackupYourMobile\applications\com.outfit7.tomsmessengerfree-1"
sh=B373A7DA30E42837DB643EA542F63ABA797F55ED ft=1 fh=f36215a44e811eb8 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\xxxx\Downloads\Revo Uninstaller - CHIP-Installer.exe" |