ReneMuxler | 26.05.2015 18:12 | Code:
# AdwCleaner v4.205 - Bericht erstellt 26/05/2015 um 17:46:06
# Aktualisiert 21/05/2015 von Xplode
# Datenbank : 2015-05-25.3 [Server]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (x86)
# Benutzername : PRIVAT - PRIVAT-PC
# Gestarted von : C:\Users\PRIVAT\Downloads\AdwCleaner_4.205.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : globalUpdate
[#] Dienst Gelöscht : globalUpdatem
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\CS Browser Assistant 2.0
Ordner Gelöscht : C:\Program Files\CSBrowserHelper
Ordner Gelöscht : C:\Program Files\globalUpdate
Ordner Gelöscht : C:\Program Files\predm
Ordner Gelöscht : C:\Program Files\Rock Turner
Ordner Gelöscht : C:\Program Files\web disco
Ordner Gelöscht : C:\Program Files\re-markit
Ordner Gelöscht : C:\Users\PRIVAT\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\PRIVAT\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\PRIVAT\AppData\Local\DownloadManager
Ordner Gelöscht : C:\Users\PRIVAT\AppData\Roaming\Activeris
Ordner Gelöscht : C:\Users\PRIVAT\AppData\Roaming\ExpressFiles
Ordner Gelöscht : C:\Users\PRIVAT\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\Extensions\f642a7a0-3e89-45d2-875f-8394cf2f7196@2c30b4c2-9e83-4875-a4ca-6acd1e9923b2.com
Ordner Gelöscht : C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Extensions\didlppefmhmoiaeemeffjchbieeghlan
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\PRIVAT\AppData\Local\AnyProtectScannerSetup.exe
Datei Gelöscht : C:\Users\PRIVAT\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\user.js
Datei Gelöscht : C:\Program Files\Mozilla Firefox\my.cfg
Datei Gelöscht : C:\Program Files\Mozilla Firefox\browser\defaults\preferences\my-prefs.js
Datei Gelöscht : C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage
Datei Gelöscht : C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.selectgo00.selectgo.net_0.localstorage-journal
***** [ Geplante Tasks ] *****
Task Gelöscht : Express FilesUpdate
Task Gelöscht : globalUpdateUpdateTaskMachineCore
Task Gelöscht : globalUpdateUpdateTaskMachineUA
Task Gelöscht : web_disco_updating_service
Task Gelöscht : web_disco_notification_service
Task Gelöscht : CS Browser Assistant 2.0-codedownloader
Task Gelöscht : CS Browser Assistant 2.0-updater
Task Gelöscht : Media_Play_AIR+-firefoxinstaller
Task Gelöscht : Media_Play_AIR+-updater
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickCtrl.10
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdate.Update3WebControl.4
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=10
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@staging.google.com/globalUpdate Update;version=4
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0044286.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0044286.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0044286.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0044286.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6EC77D09-02CB-4E1F-E3C4-FB141B2610B3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110411421186}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220422422286}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A45E3FA8-5048-4372-94AD-C6661671F7FC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411421186}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A45E3FA8-5048-4372-94AD-C6661671F7FC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411421186}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{30cf102f-182c-4447-baa0-bbb212afad8c}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{52ab7886-6907-445d-8e7d-6c83f62c2514}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9bf4b325-6596-4ef1-a40d-d16b4a2b7a40}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9f0a7c4a-13b3-4b10-941f-3947e3aa5152}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\ExpressFiles
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Re_Markit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\CS Browser Assistant 2.0
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\ExpressFiles
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledBrowserExtensions
Schlüssel Gelöscht : HKLM\SOFTWARE\Tutorials
Schlüssel Gelöscht : HKLM\SOFTWARE\CS Browser Assistant 2.0
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CS Browser Assistant 2.0
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17801
-\\ Mozilla Firefox v30.0 (de)
[643me9il.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.af642a7a03e8945d2875f8394cf2f71962c30b4c29e834875a4ca6acd1e9923b2com44286.44286.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
[643me9il.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.afaf73efed6aa46eb8014e0b47ac07eada90d6ab4be694e96a9791fd9c1ae6f92com58488.58488.internaldb.monetization_plugin_bundledUrls.value", "%7B%22dealply_s%22%3A%7B%22urls%22%3A%5B%22ssf[...]
[643me9il.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.crossrider.bic", "14279a3945a5c82986741738bb737b65");
-\\ Google Chrome v43.0.2357.81
*************************
AdwCleaner[R0].txt - [12196 Bytes] - [26/05/2015 17:44:17]
AdwCleaner[S0].txt - [12089 Bytes] - [26/05/2015 17:46:06]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [12149 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.8.0 (05.25.2015:1)
OS: Windows 7 Ultimate x86
Ran by PRIVAT on 26.05.2015 at 18:01:06,69
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
Successfully deleted: [Task] C:\Windows\System32\tasks\globalUpdateUpdateTaskMachineCore1cf7c22a3015336
Successfully deleted: [Task] C:\Windows\System32\tasks\globalUpdateUpdateTaskMachineUA1cf7c22a6ade2e7
Successfully deleted: [Task] C:\Windows\tasks\globalUpdateUpdateTaskMachineCore1cf7c22a3015336.job
Successfully deleted: [Task] C:\Windows\tasks\globalUpdateUpdateTaskMachineUA1cf7c22a6ade2e7.job
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\Users\PRIVAT\appdata\local\nsd5ED0.tmp
Successfully deleted: [File] C:\Users\PRIVAT\appdata\local\google\chrome\user data\default\local storage\http_static.select-n-go00.select-n-go.com_0.localstorage
Successfully deleted: [File] C:\Users\PRIVAT\appdata\local\google\chrome\user data\default\local storage\http_static.select-n-go00.select-n-go.com_0.localstorage-journal
~~~ Folders
Successfully deleted: [Folder] C:\Users\PRIVAT\documents\optimizer pro
~~~ FireFox
Emptied folder: C:\Users\PRIVAT\AppData\Roaming\mozilla\firefox\profiles\643me9il.default\minidumps [23 files]
~~~ Chrome
[C:\Users\PRIVAT\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
[C:\Users\PRIVAT\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
didlppefmhmoiaeemeffjchbieeghlan
[C:\Users\PRIVAT\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
[C:\Users\PRIVAT\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[
didlppefmhmoiaeemeffjchbieeghlan
]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26.05.2015 at 18:12:02,81
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 26.05.2015
Suchlauf-Zeit: 18:21:05
Logdatei: AntiMal.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.05.26.04
Rootkit Datenbank: v2015.05.24.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: PRIVAT
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 299077
Verstrichene Zeit: 12 Min, 32 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 1
PUP.Optional.FirstSeenToday.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|fst_de_28, In Quarantäne, [3efe8c0cc5c5af879d7ab66609fbdc24],
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 16
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\defaults, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\defaults\preferences, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\userCode, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\locale, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\locale\en-US, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
Rogue.Multiple, C:\ProgramData\2308189059, In Quarantäne, [a09cebad78120333dc7e1389dd260ef2],
PUP.Optional.NewPlayer.A, C:\Users\PRIVAT\AppData\Local\com\NewPlayer.exe_Url_wmgtxqntq5fklrr4bpxvxljadclrhvq0, In Quarantäne, [dd5f395f01893ff77c993c98a2619b65],
PUP.Optional.NewPlayer.A, C:\Users\PRIVAT\AppData\Local\com\NewPlayer.exe_Url_wmgtxqntq5fklrr4bpxvxljadclrhvq0\2.1.1.7, In Quarantäne, [dd5f395f01893ff77c993c98a2619b65],
Dateien: 137
PUP.Optional.InstallCore, C:\$Recycle.Bin\S-1-5-21-1417849773-3099944400-2066547467-1000\$R2VKLOZ.Uninstall\uninstaller.exe, In Quarantäne, [90ac7e1a3357c86e6cc2adc12cd66b95],
PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-1417849773-3099944400-2066547467-1000\$R7LXR6E.tmp\Au_.exe, In Quarantäne, [c874d3c54e3cd95dfc7d305a1ce5f907],
PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-1417849773-3099944400-2066547467-1000\$R7MFNPF.7\utils.exe, In Quarantäne, [06362c6c1e6c3bfb42e458ead32dfd03],
PUP.Optional.MediaPlayerPlus.A, C:\$Recycle.Bin\S-1-5-21-1417849773-3099944400-2066547467-1000\$RSSEJNA\Media_Play_AIR+-firefoxinstaller.exe, In Quarantäne, [e4588b0d5c2eef47983bdbdbe31e02fe],
PUP.Optional.MediaPlayerPlus.A, C:\$Recycle.Bin\S-1-5-21-1417849773-3099944400-2066547467-1000\$RSSEJNA\Media_Play_AIR+-updater.exe, In Quarantäne, [ff3d5f397119b680dbf82f875ca5ac54],
PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-1417849773-3099944400-2066547467-1000\$RSSEJNA\utils.exe, In Quarantäne, [a19badebf29883b35b1ed3b7d829c33d],
PUP.Optional.InstallCore, C:\$Recycle.Bin\S-1-5-21-1417849773-3099944400-2066547467-1000\$RXHUZBM\uninstaller.exe, In Quarantäne, [6dcf1e7a2b5fd95d68c6b8b619e937c9],
PUP.Optional.DomaIQ, C:\Users\PRIVAT\Downloads\Setup (1).exe, In Quarantäne, [a09c930584068caac7dc3d9dec1552ae],
PUP.Optional.DomaIQ, C:\Users\PRIVAT\Downloads\Setup (2).exe, In Quarantäne, [72ca9cfcb1d99f976d365a80d031b749],
PUP.Optional.DomaIQ, C:\Users\PRIVAT\Downloads\Setup.exe, In Quarantäne, [62daebadc6c4ef47dcc7aa30669b8977],
PUP.Optional.Bandoo, C:\Users\PRIVAT\Downloads\iLividSetup-r1796-n-bc.exe, In Quarantäne, [da62b2e6eaa0ee48f00589b5e02101ff],
PUP.Optional.ExpressFiles.A, C:\Users\PRIVAT\Downloads\win_7_ultimate_sp1_iso_download_deutsch_downloader_de_99259.exe, In Quarantäne, [d468abedd5b555e1049f47e3fb058878],
PUP.Optional.PricePeep.A, C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage, In Quarantäne, [013bfb9d5931e155bb3c9846a75c837d],
PUP.Optional.PricePeep.A, C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.pricepeep00.pricepeep.net_0.localstorage-journal, In Quarantäne, [4bf13d5b94f684b27d7ab32be320e41c],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\crossrider_statusbar.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\button1.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\button2.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\button3.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\button4.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\button5.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\icon128.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\icon16.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\icon24.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\icon48.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\panelarrow-up.png, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\popup.html, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\skin.css, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\skin\update.css, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome.manifest, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\install.rdf, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\1de9c0e41efb53969adae9c54f0cebe0.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\1f0b73fc123b0ca58bcf54890a7197c9.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\adb274e6aeef927cfe6b19bca418a857.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\background.html, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\browser.xul, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\c24546c6335664e8cf327d7a5dbced86.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\c801fb57d954740b5b1a55fbe5db039d.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\dialog.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\ffCoreFilesIndex.txt, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\options.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\options.xul, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\search_dialog.xul, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\1e917e61312180981e4948ddaefff568.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\2720d571235258a11255c1676d8d13b3.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\4385d3d748c9cbc843a93e8f3d16ac7f.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\4bf58d5d8b78fb5f87effbabb8f51e53.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\578c179f3eaac23d02cedcffff527507.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\6a14a5530561b287c6a3709c03319772.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\6ce0df4e69f73cafee076c57ece49b5a.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\868448df4eac5086a8541a479d6096ac.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\8c0057d5295ad0313edad5aed8e8a5a3.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\8c9ba5b19e01d5775fb8c3faec8ee6ab.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\96f4cc48357b4aa395beb454f381fb6a.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\9fe9ad7603beb9916bcc06ee00e9319a.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\ac5a4de8c912a0467df81bf2adfdfe61.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\ca850da2937652f5633e346c265678af.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\d54c35588f5d1b07174e503382703016.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\api\dafb3e54ce718b41d385292d10a362be.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\afe311532d54e534846a2b41c3a1be77.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\0104b775a8a314d63ee17b55e85e2ba1.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\2091dacca9882f39f99c5ec41c8e28e8.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\2736c83b5f775f575c803b5b9580fd37.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\276670ee1b33b2251b60e7fb7a87be76.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\444f9812b3aa3740617da1650def154d.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\4979601b93cf3647a55728afee03348c.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\5cdfb3384e9c530cff73ae314c6d85f8.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\646576c5b2768989c02f9d14dda44093.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\663e4fedbf04beff7c758925f6a4ba52.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\82442fdbfc58e71464de3ef0083a7b10.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\8dce9a92340bc887c3725c1eed378f41.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\93a92d46231fc4dfc38df546538d71ca.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\a96b636274a603489d8cc89f6c9bb743.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\c20ef1eddaa017eac1b70d1deed75955.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\dca70e67640f97dcb40b5dcbd4aea52e.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\e073e5db42428d0bcab3c761259f5620.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\e30554e1140da738347c0a894b38443f.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\eb4b30e6c12abf040099cc92580bc65b.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\ee45695e50fb0c3947d74958514adfae.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\chrome\content\core\installer.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\defaults\preferences\prefs.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\manifest.xml, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins.json, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\22.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\1.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\102.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\104.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\13.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\14.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\155.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\16.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\17.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\180.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\182.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\183.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\184.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\190.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\191.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\193.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\195.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\200.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\207.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\21.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\211.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\220.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\221.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\223.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\226.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\230.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\233.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\246.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\257.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\260.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\262.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\263.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\268.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\273.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\275.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\28.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\281.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\289.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\301.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\345.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\354.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\4.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\47.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\64.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\7.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\72.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\78.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\9.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\91.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\93.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\plugins\98.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\userCode\background.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\extensionData\userCode\extension.js, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.CrossRider.A, C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com\locale\en-US\translations.dtd, In Quarantäne, [1c20d7c1f7930036a554393801044db3],
PUP.Optional.NewPlayer.A, C:\Users\PRIVAT\AppData\Local\com\NewPlayer.exe_Url_wmgtxqntq5fklrr4bpxvxljadclrhvq0\2.1.1.7\user.config, In Quarantäne, [dd5f395f01893ff77c993c98a2619b65],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-05-2015
Ran by PRIVAT (administrator) on PRIVAT-PC on 26-05-2015 19:08:46
Running from C:\Users\PRIVAT\Downloads
Loaded Profiles: PRIVAT (Available Profiles: PRIVAT)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\vsserv.exe
() C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdagent.exe
(Samsung Electronics Co., Ltd.) C:\Users\PRIVAT\Desktop\Root Programme\Kies\KiesTrayAgent.exe
() C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\bdapppassmgr.exe
(Samsung) C:\Users\PRIVAT\Desktop\Root Programme\Kies\Kies.exe
(Samsung) C:\Users\PRIVAT\Desktop\Root Programme\Kies\External\FirmwareUpdate\KiesPDLR.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Bitdefender) C:\Program Files\Bitdefender\Bitdefender\pmbxcrnmh.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Bdagent] => C:\Program Files\Bitdefender\Bitdefender\bdagent.exe [1918176 2015-02-06] (Bitdefender)
HKLM\...\Run: [KiesTrayAgent] => C:\Users\PRIVAT\Desktop\Root Programme\Kies\KiesTrayAgent.exe [311152 2013-07-26] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [AgentMonitor] => C:\Program Files\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKU\S-1-5-21-1417849773-3099944400-2066547467-1000\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [482392 2015-02-06] (Bitdefender)
HKU\S-1-5-21-1417849773-3099944400-2066547467-1000\...\Run: [Bitdefender-Geldbörse] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [901608 2014-11-20] (Bitdefender)
HKU\S-1-5-21-1417849773-3099944400-2066547467-1000\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => C:\Program Files\Bitdefender\Bitdefender\bdapppassmgr.exe [615256 2014-11-20] (Bitdefender)
HKU\S-1-5-21-1417849773-3099944400-2066547467-1000\...\Run: [KiesPreload] => C:\Users\PRIVAT\Desktop\Root Programme\Kies\Kies.exe [1564016 2013-07-26] (Samsung)
HKU\S-1-5-21-1417849773-3099944400-2066547467-1000\...\Run: [] => C:\Users\PRIVAT\Desktop\Root Programme\Kies\External\FirmwareUpdate\KiesPDLR.exe [844656 2013-07-26] (Samsung)
HKU\S-1-5-21-1417849773-3099944400-2066547467-1000\...\MountPoints2: {e3e1120a-3180-11e3-9ff3-806e6f6e6963} - D:\autorun.exe
HKU\S-1-5-18\...\Run: [Bitdefender-Geldbörse-Agent] => C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe [482392 2015-02-06] (Bitdefender)
HKU\S-1-5-18\...\Run: [Bitdefender-Geldbörse] => C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe [901608 2014-11-20] (Bitdefender)
HKU\S-1-5-18\...\Run: [Bitdefender-Geldbörse-Anwendungs-Agent] => C:\Program Files\Bitdefender\Bitdefender\bdapppassmgr.exe [615256 2014-11-20] (Bitdefender)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2013-10-17]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1417849773-3099944400-2066547467-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1417849773-3099944400-2066547467-1000\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://go.microsoft.com/fwlink/?LinkID=226786&Mkt=de-DE&Src=MSRT&Tid=80033373&OHP=about%3Ablank&OSP=http%3A%2F%2Fde.search.yahoo.com%2Fsearch%3Ffr%3Dmcafee%26p%3D%7BSearchTerms%7D
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1417849773-3099944400-2066547467-1000 -> {ECAF07EC-602E-4224-A0A7-22DDD9CE6034} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1
BHO: Bitdefender-Geldbörse -> {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -> C:\Program Files\Bitdefender\Bitdefender\pmbxie.dll [2014-11-20] (Bitdefender)
Tcpip\Parameters: [DhcpNameServer] 217.0.43.145 217.0.43.129
FireFox:
========
FF ProfilePath: C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default
FF DefaultSearchEngine: Sichere Suche
FF SearchEngineOrder.1: Sichere Suche
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1207148.dll [2013-12-05] (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-26] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-26] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-05-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1417849773-3099944400-2066547467-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\PRIVAT\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2013-11-25] (Unity Technologies ApS)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\McSiteAdvisor.xml [2013-11-23]
FF Extension: sbconformingmasahalinfo - C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\Extensions\sbconforming@masahal.info [2015-04-03]
FF HKLM\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\ffpwdman
FF Extension: Bitdefender Wallet - C:\Program Files\Bitdefender\Bitdefender\ffpwdman [2014-02-07]
FF Extension: No Name - C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\f642a7a0-3e89-45d2-875f-8394cf2f7196@2c30b4c2-9e83-4875-a4ca-6acd1e9923b2.com [not found]
FF Extension: No Name - C:\Users\PRIVAT\AppData\Roaming\Mozilla\Firefox\Profiles\643me9il.default\extensions\faf73efe-d6aa-46eb-8014-e0b47ac07ead@a90d6ab4-be69-4e96-a979-1fd9c1ae6f92.com [not found]
Chrome:
=======
CHR Profile: C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bitdefender Wallet) - C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccahoghmggldkcdjiebjkidpfongdfbl [2014-02-07]
CHR Extension: (Bookmark Manager) - C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-05-17]
CHR Extension: (kajibbejlbohfaggdiogboambcijhkke) - C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Extensions\kajibbejlbohfaggdiogboambcijhkke [2015-04-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-05-17]
CHR Extension: (Google Wallet) - C:\Users\PRIVAT\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-14]
CHR HKLM\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - C:\Program Files\Bitdefender\Bitdefender\pmbxcr.crx [2015-02-06]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 DiagTrack; C:\Windows\system32\diagtrack.dll [851456 2015-04-27] (Microsoft Corporation)
R3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [225280 2006-12-11] (Hewlett-Packard Co.) []
R2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [131072 2006-12-11] (Hewlett-Packard Co.) []
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [44544 2008-12-03] (Hewlett-Packard) []
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [53760 2008-12-03] (Hewlett-Packard) []
R2 UPDATESRV; C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe [54424 2014-11-20] (Bitdefender)
R2 VSSERV; C:\Program Files\Bitdefender\Bitdefender\vsserv.exe [1302784 2015-02-06] (Bitdefender)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 avc3; C:\Windows\System32\DRIVERS\avc3.sys [1073160 2015-02-06] (BitDefender)
R3 avchv; C:\Windows\System32\DRIVERS\avchv.sys [242504 2012-11-02] (BitDefender)
R3 avckf; C:\Windows\System32\DRIVERS\avckf.sys [528248 2014-11-20] (BitDefender)
R1 bdfwfpf; C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys [90704 2011-11-14] (BitDefender LLC)
S3 BDSandBox; C:\Windows\system32\drivers\bdsandbox.sys [66832 2013-11-04] (BitDefender SRL)
R1 bdselfpr; C:\Program Files\Bitdefender\Bitdefender\bdselfpr.sys [135600 2013-07-26] (BitDefender LLC)
R3 cmudax; C:\Windows\System32\drivers\cmudax.sys [1287296 2005-05-12] (C-Media Inc.)
S3 ctxS51; C:\Windows\System32\DRIVERS\ctxS51.sys [1903646 2006-05-01] (Intel Corporation)
R3 FETNDIS; C:\Windows\System32\DRIVERS\fetnd6.sys [44032 2009-07-14] (VIA Technologies, Inc. )
R0 gzflt; C:\Windows\System32\DRIVERS\gzflt.sys [165744 2013-08-23] (BitDefender LLC)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2015-05-26] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-04-14] (Malwarebytes Corporation)
R0 oem-drv86; C:\Windows\System32\DRIVERS\oem-drv86.sys [28160 2015-05-26] (secr9tos) []
R3 Ph3xIB32; C:\Windows\System32\DRIVERS\Ph3xIB32.sys [1311232 2009-07-14] (NXP Semiconductors)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
R3 rt70x86; C:\Windows\System32\DRIVERS\netr70.sys [306016 2010-04-27] (Ralink Technology Corp.)
R0 trufos; C:\Windows\System32\DRIVERS\trufos.sys [408280 2015-02-06] (BitDefender S.R.L.)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [27416 2006-11-30] (X10 Wireless Technology, Inc.)
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-26 18:56 - 2015-05-26 18:56 - 00041686 _____ () C:\Users\PRIVAT\Desktop\AntiMal.txt
2015-05-26 18:20 - 2015-05-26 18:52 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-05-26 18:19 - 2015-05-26 18:19 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-26 18:19 - 2015-05-26 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-26 18:19 - 2015-05-26 18:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-26 18:19 - 2015-05-26 18:19 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-05-26 18:19 - 2015-04-14 09:37 - 00092888 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-05-26 18:19 - 2015-04-14 09:37 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-05-26 18:19 - 2015-04-14 09:37 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-05-26 18:18 - 2015-05-26 18:18 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\PRIVAT\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-26 18:12 - 2015-05-26 18:12 - 00002154 _____ () C:\Users\PRIVAT\Desktop\JRT.txt
2015-05-26 18:01 - 2015-05-26 18:01 - 00000207 _____ () C:\Windows\tweaking.com-regbackup-PRIVAT-PC-Windows-7-Ultimate-(32-bit).dat
2015-05-26 18:01 - 2015-05-26 18:01 - 00000000 ____D () C:\RegBackup
2015-05-26 18:00 - 2015-05-26 18:00 - 02946703 _____ (Thisisu) C:\Users\PRIVAT\Downloads\JRT.exe
2015-05-26 17:48 - 2015-05-26 18:49 - 00028026 _____ () C:\Windows\PFRO.log
2015-05-26 17:44 - 2015-05-26 17:46 - 00000000 ____D () C:\AdwCleaner
2015-05-26 17:43 - 2015-05-26 17:44 - 02222592 _____ () C:\Users\PRIVAT\Downloads\AdwCleaner_4.205.exe
2015-05-26 17:19 - 2015-05-26 17:20 - 10801480 _____ (VS Revo Group ) C:\Users\PRIVAT\Downloads\RevoUninProSetup.exe
2015-05-26 17:18 - 2015-05-26 17:18 - 00001226 _____ () C:\Users\PRIVAT\Desktop\Revo Uninstaller.lnk
2015-05-26 17:18 - 2015-05-26 17:18 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-05-26 17:17 - 2015-05-26 17:18 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\PRIVAT\Downloads\revosetup95.exe
2015-05-26 13:36 - 2015-05-26 13:48 - 00040336 _____ () C:\Users\PRIVAT\Downloads\Addition.txt
2015-05-26 13:34 - 2015-05-26 19:09 - 00012845 _____ () C:\Users\PRIVAT\Downloads\FRST.txt
2015-05-26 13:34 - 2015-05-26 19:08 - 00000000 ____D () C:\FRST
2015-05-26 13:33 - 2015-05-26 13:33 - 01147392 _____ (Farbar) C:\Users\PRIVAT\Downloads\FRST.exe
2015-05-18 20:06 - 2015-05-05 03:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-18 20:06 - 2015-04-22 03:48 - 00342736 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-05-18 20:06 - 2015-04-21 18:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-18 20:06 - 2015-04-21 18:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-05-18 20:06 - 2015-04-21 18:24 - 19691008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-18 20:06 - 2015-04-21 18:11 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-18 20:06 - 2015-04-21 18:11 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-05-18 20:06 - 2015-04-21 18:10 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-05-18 20:06 - 2015-04-21 18:09 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-18 20:06 - 2015-04-21 18:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-05-18 20:06 - 2015-04-21 18:04 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-18 20:06 - 2015-04-21 18:03 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-18 20:06 - 2015-04-21 18:02 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-05-18 20:06 - 2015-04-21 18:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-18 20:06 - 2015-04-21 17:58 - 00664576 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-18 20:06 - 2015-04-21 17:58 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-18 20:06 - 2015-04-21 17:58 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-05-18 20:06 - 2015-04-21 17:57 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-05-18 20:06 - 2015-04-21 17:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-05-18 20:06 - 2015-04-21 17:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-18 20:06 - 2015-04-21 17:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-05-18 20:06 - 2015-04-21 17:39 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-05-18 20:06 - 2015-04-21 17:38 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-18 20:06 - 2015-04-21 17:36 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-18 20:06 - 2015-04-21 17:31 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-18 20:06 - 2015-04-21 17:26 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-18 20:06 - 2015-04-21 17:26 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-05-18 20:06 - 2015-04-21 17:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-18 20:06 - 2015-04-21 17:24 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-05-18 20:06 - 2015-04-21 17:17 - 12828672 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-18 20:06 - 2015-04-21 17:02 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-18 20:06 - 2015-04-21 16:58 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-18 20:06 - 2015-04-21 16:56 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-05-18 20:06 - 2015-04-18 04:56 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2015-05-17 20:14 - 2015-04-27 21:11 - 03989440 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-05-17 20:14 - 2015-04-27 21:11 - 03934144 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-05-17 20:14 - 2015-04-27 21:11 - 00137664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-05-17 20:14 - 2015-04-27 21:11 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-05-17 20:14 - 2015-04-27 21:08 - 01307648 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00851456 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00635392 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-05-17 20:14 - 2015-04-27 21:05 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-05-17 20:14 - 2015-04-27 21:04 - 01061376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-05-17 20:14 - 2015-04-27 21:04 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-05-17 20:14 - 2015-04-27 21:04 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-05-17 20:14 - 2015-04-27 21:04 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-05-17 20:14 - 2015-04-27 21:04 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-05-17 20:14 - 2015-04-27 21:04 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-05-17 20:14 - 2015-04-27 21:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-05-17 20:14 - 2015-04-27 21:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-05-17 20:14 - 2015-04-27 21:04 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-05-17 20:14 - 2015-04-27 21:04 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-05-17 20:14 - 2015-04-27 21:04 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-05-17 20:14 - 2015-04-27 21:04 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-05-17 20:14 - 2015-04-27 21:03 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-05-17 20:14 - 2015-04-27 21:03 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-05-17 20:14 - 2015-04-27 21:01 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-05-17 20:14 - 2015-04-27 21:01 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-05-17 20:14 - 2015-04-27 20:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-05-17 20:14 - 2015-04-27 20:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-05-17 20:14 - 2015-04-27 20:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-05-17 20:04 - 2015-05-26 18:50 - 00000336 _____ () C:\Windows\setupact.log
2015-05-17 20:04 - 2015-05-17 20:04 - 00000000 _____ () C:\Windows\setuperr.log
2015-05-17 20:03 - 2015-05-17 20:03 - 289940173 _____ () C:\Windows\MEMORY.DMP
2015-05-17 20:03 - 2015-05-17 20:03 - 00144976 _____ () C:\Windows\Minidump\051715-35984-01.dmp
2015-05-17 20:01 - 2015-05-17 20:01 - 00016636 _____ () C:\Users\PRIVAT\Documents\cc_20150517_200113.reg
2015-05-17 19:39 - 2015-02-03 05:12 - 01230848 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-05-17 19:38 - 2015-02-20 06:13 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2015-05-17 19:38 - 2015-02-20 06:13 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-05-17 19:38 - 2015-02-20 06:13 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2015-05-17 19:38 - 2015-02-20 06:13 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2015-05-17 19:38 - 2015-02-20 05:09 - 00299008 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-05-17 19:38 - 2015-02-13 07:26 - 12875264 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-05-17 19:38 - 2015-02-04 04:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2015-05-17 19:38 - 2015-02-03 05:16 - 00078784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-05-17 19:38 - 2015-02-03 05:12 - 11411968 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 03209728 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 01329664 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 01174528 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 01005056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 00744960 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 00617984 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 00406016 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 00354816 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\ubpm.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2015-05-17 19:38 - 2015-02-03 05:12 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2015-05-17 19:38 - 2015-02-03 05:00 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2015-05-17 19:38 - 2015-01-31 05:32 - 00919552 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2015-05-17 19:38 - 2015-01-31 04:52 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2015-05-17 19:38 - 2015-01-31 04:51 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2015-05-17 19:38 - 2015-01-31 01:56 - 00370488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-05-17 19:38 - 2015-01-17 04:30 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2015-05-17 19:38 - 2014-06-28 02:21 - 00455752 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-05-17 19:37 - 2015-02-03 05:12 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00103424 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-05-17 19:37 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-05-17 19:37 - 2015-02-03 05:12 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-05-17 19:37 - 2015-02-03 05:11 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-05-17 19:37 - 2015-02-03 05:11 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-05-17 19:37 - 2015-02-03 05:11 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2015-05-17 19:37 - 2015-02-03 05:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2015-05-17 19:37 - 2015-02-03 05:11 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2015-05-17 19:37 - 2015-02-03 05:11 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2015-05-17 19:37 - 2015-02-03 05:11 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2015-05-17 19:37 - 2015-02-03 05:11 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2015-05-17 19:37 - 2015-02-03 05:10 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2015-05-17 19:37 - 2015-02-03 05:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2015-05-17 19:37 - 2015-02-03 04:26 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2015-05-17 19:37 - 2014-11-01 00:22 - 00521384 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-05-17 19:37 - 2014-06-28 02:21 - 00409272 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-05-17 19:17 - 2015-05-26 14:21 - 00000000 ___SD () C:\Windows\system32\GWX
2015-05-15 18:43 - 2015-03-23 05:06 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-05-15 18:43 - 2015-03-23 05:06 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-05-15 18:43 - 2015-03-23 05:06 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-05-15 18:43 - 2015-03-23 05:06 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-05-15 18:43 - 2015-03-23 05:06 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-05-15 18:43 - 2015-03-23 05:06 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-05-15 18:43 - 2015-03-23 05:06 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-05-15 18:43 - 2015-03-23 04:59 - 00896000 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-05-15 18:43 - 2015-03-04 06:16 - 00249784 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2015-05-15 18:43 - 2015-03-04 06:10 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll
2015-05-15 18:43 - 2015-01-29 05:02 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2015-05-15 18:30 - 2015-03-05 06:06 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-05-15 18:29 - 2015-04-13 05:19 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-15 18:24 - 2015-05-15 18:24 - 00000000 ____D () C:\Users\PRIVAT\AppData\Local\VirtualStore
2015-05-15 18:21 - 2015-03-04 06:11 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\shimeng.dll
2015-05-15 18:21 - 2015-03-04 06:10 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2015-05-15 18:21 - 2015-03-04 06:10 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\aelupsvc.dll
2015-05-15 18:21 - 2015-03-04 06:10 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\sdbinst.exe
2015-05-15 18:20 - 2015-05-01 15:16 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-15 18:20 - 2015-04-08 05:14 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-05-15 18:20 - 2015-04-08 05:14 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll
2015-05-15 18:20 - 2015-03-25 05:00 - 03088384 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-05-15 18:20 - 2015-03-25 05:00 - 02020864 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-05-15 18:20 - 2015-03-25 05:00 - 00566784 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-05-15 18:20 - 2015-03-25 05:00 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-05-15 18:20 - 2015-03-25 05:00 - 00131584 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-05-15 18:20 - 2015-03-25 05:00 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-05-15 18:20 - 2015-03-25 05:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2015-05-15 18:20 - 2015-03-25 05:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2015-05-15 18:20 - 2015-03-25 05:00 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-05-15 18:20 - 2015-03-25 05:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2015-05-15 18:20 - 2015-03-25 05:00 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2015-05-15 18:19 - 2015-03-10 05:08 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-05-15 18:19 - 2015-03-10 05:05 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2015-05-15 18:19 - 2015-02-25 05:03 - 00514560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2015-05-15 18:19 - 2015-02-18 09:06 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2015-05-15 16:44 - 2015-05-15 16:44 - 00000000 ____D () C:\Users\PRIVAT\AppData\Local\LogMeIn Rescue Applet
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-26 19:02 - 2013-09-18 18:30 - 01200523 _____ () C:\Windows\WindowsUpdate.log
2015-05-26 18:59 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-26 18:59 - 2009-07-14 06:34 - 00026352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-26 18:51 - 2015-04-03 10:18 - 00001012 _____ () C:\Windows\Tasks\mDJGaRmub6Rk138fNU.job
2015-05-26 18:50 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-26 18:49 - 2013-09-18 19:25 - 00028160 _____ (secr9tos) C:\Windows\system32\Drivers\oem-drv86.sys
2015-05-26 18:49 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system
2015-05-26 18:38 - 2014-05-30 17:40 - 00000000 ____D () C:\Users\PRIVAT\AppData\Local\com
2015-05-26 17:46 - 2014-02-19 19:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-05-26 17:26 - 2014-05-30 18:00 - 00000000 ____D () C:\Users\PRIVAT\AppData\Roaming\0C1I1L1R1J0M1P0I1G
2015-05-26 13:56 - 2013-12-14 13:46 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-05-26 13:38 - 2013-12-14 13:45 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-26 13:38 - 2013-12-14 13:45 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-26 13:07 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\AppCompat
2015-05-26 13:02 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\ru-RU
2015-05-26 13:02 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2015-05-18 19:47 - 2013-09-18 18:43 - 00715878 _____ () C:\Windows\system32\perfh019.dat
2015-05-18 19:47 - 2013-09-18 18:43 - 00150184 _____ () C:\Windows\system32\perfc019.dat
2015-05-18 19:47 - 2010-11-20 23:01 - 02484460 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-18 19:41 - 2009-07-14 06:33 - 00387368 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-17 20:03 - 2013-10-10 09:33 - 00000000 ____D () C:\Windows\Minidump
2015-05-17 19:42 - 2013-10-27 20:49 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-05-17 19:17 - 2014-12-15 09:29 - 00000000 ____D () C:\Windows\system32\appraiser
2015-05-17 19:17 - 2014-05-11 14:26 - 00000000 ___SD () C:\Windows\system32\CompatTel
2015-05-17 19:17 - 2010-11-21 02:54 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-17 19:17 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2015-05-15 18:59 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-05-15 18:37 - 2013-09-18 18:10 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-15 18:27 - 2014-08-06 18:05 - 00000000 ____D () C:\Program Files\Ravensburger tiptoi
2015-05-15 18:27 - 2014-08-01 10:25 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2015-05-15 18:27 - 2014-06-12 15:47 - 00000000 ____D () C:\Users\PRIVAT\AppData\Roaming\Angry Birds Breakfast 2
2015-05-15 18:27 - 2014-05-30 10:44 - 00000000 ____D () C:\Program Files\MiniTool Partition Wizard Home Edition 8.1.1
2015-05-15 18:27 - 2014-05-15 13:17 - 00000000 ____D () C:\Program Files\AngryBirds
2015-05-15 18:27 - 2014-01-25 14:23 - 00000000 ____D () C:\Program Files\IrfanView
2015-05-15 18:27 - 2013-12-14 13:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-15 18:27 - 2013-11-23 13:14 - 00000000 ____D () C:\Program Files\CCleaner
2015-05-15 18:27 - 2013-11-16 21:03 - 00000000 ____D () C:\UBCD4Win
2015-05-15 18:27 - 2013-10-30 14:57 - 00000000 ____D () C:\Program Files\CDBurnerXP
2015-05-15 18:27 - 2013-10-17 13:57 - 00000000 ____D () C:\Program Files\Common Files\Designer
2015-05-15 18:27 - 2013-10-17 13:55 - 00000000 ____D () C:\Windows\Msagent
2015-05-15 18:27 - 2013-09-18 19:48 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-05-15 18:27 - 2013-09-18 17:38 - 00000000 ____D () C:\Users\PRIVAT
2015-05-15 18:27 - 2010-11-21 02:54 - 00000000 ___RD () C:\Users\Public\Recorded TV
2015-05-15 18:27 - 2010-11-21 02:54 - 00000000 ____D () C:\Windows\ShellNew
2015-05-15 18:27 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Sidebar
2015-05-15 18:27 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-05-15 18:27 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\Windows Defender
2015-05-15 18:27 - 2009-07-14 06:52 - 00000000 ____D () C:\Program Files\DVD Maker
2015-05-15 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2015-05-15 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\com
2015-05-15 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\System
2015-05-15 18:27 - 2009-07-14 04:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-05-15 18:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2015-04-30 10:07 - 2013-09-18 18:10 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Files in the root of some directories =======
2015-03-31 10:14 - 2015-03-31 10:14 - 0004387 _____ () C:\Users\PRIVAT\AppData\Roaming\mDJGaRmub6Rk138fNU
2015-03-31 10:14 - 2015-03-31 10:14 - 0005655 _____ () C:\Users\PRIVAT\AppData\Roaming\zNSAhTob
2014-08-01 12:39 - 2014-08-01 12:39 - 0003584 _____ () C:\Users\PRIVAT\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-02-07 18:36 - 2014-02-07 18:36 - 0535967 _____ () C:\ProgramData\1391790565.bdinstall.bin
2013-12-06 11:36 - 2013-12-06 11:40 - 0000375 _____ () C:\ProgramData\hpzinstall.log
Some files in TEMP:
====================
C:\Users\PRIVAT\AppData\Local\Temp\Quarantine.exe
C:\Users\PRIVAT\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-06 15:34
==================== End of log ============================ |