Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 01.03.2016
Suchlaufzeit: 02:29:16
Protokolldatei:
Administrator: Ja
Version: 2.2.0.1024
Malware-Datenbank: v2016.02.29.05
Rootkit-Datenbank: v2016.02.27.01
Lizenz: Premium-Version
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows Vista Service Pack 2
CPU: x86
Dateisystem: NTFS
Benutzer: +++++++
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 372918
Abgelaufene Zeit: 30 Min., 0 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 1
PUP.Optional.MultiIE, C:\Users\+++++++\AppData\LocalLow\Browser-Security\safe_url.dll, , [61188bdb41588bab4686d4deae5446ba],
Registrierungsschlüssel: 12
PUP.Optional.MultiIE, HKLM\SOFTWARE\CLASSES\CLSID\{E6D66045-F951-4DBF-962E-993B4FB6A9E0}, , [61188bdb41588bab4686d4deae5446ba],
PUP.Optional.MultiIE, HKLM\SOFTWARE\CLASSES\CLSID\{E6D66045-F951-4DBF-962E-993B4FB6A9E0}\INPROCSERVER32, , [61188bdb41588bab4686d4deae5446ba],
PUP.Optional.MultiIE, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E6D66045-F951-4DBF-962E-993B4FB6A9E0}, , [61188bdb41588bab4686d4deae5446ba],
PUP.Optional.MultiIE, HKU\S-1-5-21-3867315891-1915105375-3091467415-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{E6D66045-F951-4DBF-962E-993B4FB6A9E0}, , [61188bdb41588bab4686d4deae5446ba],
PUP.Optional.MultiIE, HKU\S-1-5-21-3867315891-1915105375-3091467415-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E6D66045-F951-4DBF-962E-993B4FB6A9E0}, , [61188bdb41588bab4686d4deae5446ba],
PUP.Optional.MultiIE, HKU\S-1-5-21-3867315891-1915105375-3091467415-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{E6D66045-F951-4DBF-962E-993B4FB6A9E0}, , [61188bdb41588bab4686d4deae5446ba],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [3346b4b21089b284868a9d907c88df21],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{8CDE19E6-71C2-4B46-89B7-35F6A18C571A}, , [13667bebd5c4df574cc481acb351b050],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Bidaily Synchronize Task[973b], , [eb8eb8aecacfd660d9b9f6108084b34d],
PUP.Optional.WinYahoo, HKU\S-1-5-21-3867315891-1915105375-3091467415-1000\SOFTWARE\wincy, , [82f7ef77b3e644f2ad5731dd52b131cf],
PUP.Optional.WinYahoo, HKU\S-1-5-21-3867315891-1915105375-3091467415-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [a3d6ec7aabee2214739b84a935cf0af6],
PUP.Optional.ProductSetup, HKU\S-1-5-21-3867315891-1915105375-3091467415-1000\SOFTWARE\PRODUCTSETUP, , [e891a3c31a7f49edd07b37d61be95da3],
Registrierungswerte: 7
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL,
Yahoo Suche ? Websuche & Suchmaschine Vista (TM) Home Premium&p={searchTerms}, [3346b4b21089b284868a9d907c88df21], %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback,
Yahoo Suche ? Websuche & Suchmaschine Vista (TM) Home Premium&p={searchTerms}, [1d5c3333d7c2fb3b5db39e8f9e6646ba], %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{8CDE19E6-71C2-4B46-89B7-35F6A18C571A}|URL,
Yahoo Suche ? Websuche & Suchmaschine Vista (TM) Home Premium&p={searchTerms}, [13667bebd5c4df574cc481acb351b050], %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{8CDE19E6-71C2-4B46-89B7-35F6A18C571A}|TopResultURLFallback,
Yahoo Suche ? Websuche & Suchmaschine Vista (TM) Home Premium&p={searchTerms}, [0c6de77f3a5fa78f809071bc12f2cf31], %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-3867315891-1915105375-3091467415-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback,
Yahoo Suche ? Websuche & Suchmaschine Vista (TM) Home Premium&p={searchTerms}, [a3d6ec7aabee2214739b84a935cf0af6], %5
PUP.Optional.Conduit, HKU\S-1-5-21-3867315891-1915105375-3091467415-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURL, http://www.bing.com/search?pc=COSP&ptag=D022416-A6B219395BABB4E59ADF&form=CONBDF&conlogo=CT3332005&q={searchTerms}, , [a1d8e77f8a0f0f2760425992867d41bf]
PUP.Optional.ProductSetup, HKU\S-1-5-21-3867315891-1915105375-3091467415-1000\SOFTWARE\PRODUCTSETUP|tb, 0X1F1T1V1G1G, , [e891a3c31a7f49edd07b37d61be95da3]
Registrierungsdaten: 1
PUP.Optional.Conduit, HKU\S-1-5-21-3867315891-1915105375-3091467415-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page,
Bing, Gut: (
Google), Schlecht: (
Bing),,[ea8f98ce5049d95d1a8f1de0897b5ca4]
Ordner: 20
PUP.Optional.MultiPlug.Gen, C:\ProgramData\7346885875457339532, , [e9909ccac8d1da5cfc9a00dcb94abc44],
PUP.Optional.CrossRider, C:\Program Files\CinemaP-1.9cV28.09, , [00795115564321155d856e802ad92dd3],
PUP.Optional.BrowserSecurity, C:\Users\+++++++\AppData\LocalLow\Browser-Security, , [8fea6ef8d8c137ffe67634f9e51f827e],
PUP.Optional.Acengine.WnskRST, C:\Windows\System32\config\systemprofile\AppData\Local\acengine, , [e8917de900992b0bfe72a8ba4db74bb5],
PUP.Optional.OurSurfing.ShrtCln, C:\Users\+++++++\AppData\Roaming\oursurfing, , [0475d6909cfd79bdfd4e0dc330d2639d],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Cache, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension Rules, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension State, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Session Storage, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.BrowserSecurity, C:\Users\+++++++\AppData\Roaming\Browser-Security, , [e495075f1287c2741167718ade2440c0],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\actions, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.SetSearchSetting, C:\Users\hajori\AppData\Roaming\Mozilla\Firefox\Profiles\2lok3ej7.default\extensions\{23BA1545-A651-4EDB-9568-45BE0CBAE475}, , [6f0a36308e0bdf5711b73aee7a8b6e92],
Dateien: 89
PUP.Optional.MultiIE, C:\Users\+++++++\AppData\LocalLow\Browser-Security\safe_url.dll, , [61188bdb41588bab4686d4deae5446ba],
PUP.Optional.InstallCore, C:\Users\+++++++\AppData\Roaming\0U1E1Q1T2Z1P0S2Z1T1C\Adobe Reader Packages\uninstaller.exe, , [82f73531bfdac4729357b28b2fd2ad53],
PUP.Optional.InstallCore, C:\Users\+++++++\AppData\Roaming\0U1E1Q1T2Z1P0S2Z1T1C\ASUS Data Security Manager Packages\uninstaller.exe, , [98e1471fd1c8ce680cdea895c23f20e0],
PUP.Optional.InstallCore, C:\Users\+++++++\AppData\Roaming\0U1E1Q1T2Z1P0S2Z1T1C\Java Update Packages\uninstaller.exe, , [3544f2749603e254a149f04d45bca060],
PUP.Optional.InstallCore, C:\Users\Harald\Downloads\UpdateStar_10-1265GER_installer.exe, , [6a0f283e8316c86e069b5209f908da26],
Trojan.Agent, C:\Users\+++++++\AppData\Roaming\svchost.exe.tmp, , [d8a189ddbbde67cfef515579c53e13ed],
PUP.Optional.OurSurfing.ShrtCln, C:\Program Files\Mozilla Firefox\browser\searchplugins\oursurfing.xml, , [4c2d36303d5c79bd538d01d7d72c06fa],
PUP.Optional.WinYahoo, C:\Users\+++++++\AppData\LocalLow\Microsoft\Internet Explorer\Services\WinYahoo.ico, , [b7c22a3ccfca2412f18d74658380649c],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\7346885875457339532\0761db6a09db839a66ffa2b60655e352.ini, , [e9909ccac8d1da5cfc9a00dcb94abc44],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\7346885875457339532\0912c0dc1e513b1266ffa2b60655e352.ini, , [e9909ccac8d1da5cfc9a00dcb94abc44],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\7346885875457339532\29ed52a6943da83dad190132a9a9e00d.ini, , [e9909ccac8d1da5cfc9a00dcb94abc44],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\7346885875457339532\4717f374fb4a996aad190132a9a9e00d.ini, , [e9909ccac8d1da5cfc9a00dcb94abc44],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\7346885875457339532\7581323da2aedcc9ad190132a9a9e00d.ini, , [e9909ccac8d1da5cfc9a00dcb94abc44],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\7346885875457339532\a8aa984433799aa966ffa2b60655e352.ini, , [e9909ccac8d1da5cfc9a00dcb94abc44],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\7346885875457339532\aaee60a831c4568966ffa2b60655e352.ini, , [e9909ccac8d1da5cfc9a00dcb94abc44],
PUP.Optional.MultiPlug.Gen, C:\ProgramData\7346885875457339532\b4f73acb236bcd2ead190132a9a9e00d.ini, , [e9909ccac8d1da5cfc9a00dcb94abc44],
PUP.Optional.CrossRider, C:\Program Files\CinemaP-1.9cV28.09\bgNova.html, , [00795115564321155d856e802ad92dd3],
PUP.Optional.CrossRider, C:\Program Files\CinemaP-1.9cV28.09\c7f87861-80f9-43ed-982c-8f3f48e72905.crx, , [00795115564321155d856e802ad92dd3],
PUP.Optional.CrossRider, C:\Program Files\CinemaP-1.9cV28.09\c7f87861-80f9-43ed-982c-8f3f48e72905.xpi, , [00795115564321155d856e802ad92dd3],
PUP.Optional.WinYahoo, C:\Users\+++++++\AppData\LocalLow\Microsoft\Internet Explorer\Services\Wincy.ico, , [4138095d29707abc8bc8e547c63e768a],
PUP.Optional.BrowserSecurity, C:\Users\+++++++\AppData\LocalLow\Browser-Security\safe_url.dat, , [8fea6ef8d8c137ffe67634f9e51f827e],
PUP.Optional.BrowserSecurity, C:\Users\+++++++\AppData\LocalLow\Browser-Security\session.dat, , [8fea6ef8d8c137ffe67634f9e51f827e],
PUP.Optional.Acengine.WnskRST, C:\Windows\System32\config\systemprofile\AppData\Local\acengine\acengine.ini, , [e8917de900992b0bfe72a8ba4db74bb5],
PUP.Optional.OurSurfing.ShrtCln, C:\Users\+++++++\AppData\Roaming\oursurfing\inst1.dat, , [0475d6909cfd79bdfd4e0dc330d2639d],
PUP.Optional.OurSurfing.ShrtCln, C:\Users\+++++++\AppData\Roaming\oursurfing\unipc.dat, , [0475d6909cfd79bdfd4e0dc330d2639d],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\chrome.dat, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\First Run, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Local State, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Cookies, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Cookies-journal, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Current Session, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Current Tabs, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Favicons, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Favicons-journal, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\History, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\History-journal, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Login Data, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Login Data-journal, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Network Action Predictor, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Network Action Predictor-journal, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Preferences, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\README, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Secure Preferences, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Shortcuts, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Shortcuts-journal, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Top Sites, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Top Sites-journal, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Visited Links, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Web Data, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Web Data-journal, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Cache\data_0, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Cache\data_1, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Cache\data_2, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Cache\data_3, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Cache\index, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension Rules\000003.log, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension Rules\CURRENT, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension Rules\LOCK, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension Rules\LOG, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension Rules\MANIFEST-000002, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension State\000003.log, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension State\CURRENT, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension State\LOCK, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension State\LOG, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Extension State\MANIFEST-000002, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Session Storage\000003.log, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Session Storage\CURRENT, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Session Storage\LOCK, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Session Storage\LOG, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.CrossBrowse, C:\Users\+++++++\AppData\Local\Crossbrowse\Crossbrowse\User Data\Default\Session Storage\MANIFEST-000002, , [c0b90c5a495044f2eb7510c932d020e0],
PUP.Optional.BrowserSecurity, C:\Users\+++++++\AppData\Roaming\Browser-Security\license.rtf, , [e495075f1287c2741167718ade2440c0],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\background.html, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\chromeCoreFilesIndex.txt, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\manifest.json, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\popup.html, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\Settings.json, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\manifest.xml, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\extensionData\plugins.json, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\icon128.png, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\icon16.png, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\icon48.png, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.CrossRider, C:\Users\+++++++\AppData\Roaming\Opera Software\Opera Stable\Extensions\lkadffjmnaiokkdncgdlecdegajoiemi\1.26.99_0\icons\actions\1.png, , [c7b2ee785d3c13234542a4594eb4ce32],
PUP.Optional.SetSearchSetting, C:\Users\++++++i\AppData\Roaming\Mozilla\Firefox\Profiles\2lok3ej7.default\extensions\{23BA1545-A651-4EDB-9568-45BE0CBAE475}\install.rdf, , [6f0a36308e0bdf5711b73aee7a8b6e92],
PUP.Optional.SetSearchSetting, C:\Users\++++++i\AppData\Roaming\Mozilla\Firefox\Profiles\2lok3ej7.default\extensions\{23BA1545-A651-4EDB-9568-45BE0CBAE475}\bootstrap.js, , [6f0a36308e0bdf5711b73aee7a8b6e92],
PUP.Optional.SetSearchSetting, C:\Users\++++++i\AppData\Roaming\Mozilla\Firefox\Profiles\2lok3ej7.default\extensions\{23BA1545-A651-4EDB-9568-45BE0CBAE475}\search.json, , [6f0a36308e0bdf5711b73aee7a8b6e92],
PUP.Optional.WinYahoo, C:\Users\++++++i\AppData\Roaming\Mozilla\Firefox\Profiles\2lok3ej7.default\prefs.js, Gut: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Schlecht: (user_pref("browser.startup.homepage", "http://at.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_), ,[f782c1a55049fe381b77f5380302d729]
PUP.Optional.WinYahoo, C:\Users\++++++i\AppData\Roaming\Mozilla\Firefox\Profiles\2lok3ej7.default\prefs.js, Gut: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Schlecht: (user_pref("browser.startup.homepage", "http://at.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_ir_15_40¶m1=1¶m2=f,[c9b030366b2e270f850e4de0f0153dc3]D1%26b,[c9b030366b2e270f850e4de0f0153dc3]DFirefox%26cc,[c9b030366b2e270f850e4de0f0153dc3]Dat%26pa,[c9b030366b2e270f850e4de0f0153dc3]DWinYahoo), %5
PUP.Optional.Conduit, C:\Users\+++++++\AppData\Roaming\Mozilla\Firefox\Profiles\lyea7h4g.default-1451307230502\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "http://www.bing.com/?pc=COSP&ptag=D022416-A6B219395BABB4E59ADF&form=CONMHP&conlogo=CT3332005")
, ,[abce7aec3267072fe0a6949037ce41bf]
PUP.Optional.Conduit, C:\Users\+++++++\AppData\Roaming\Mozilla\Firefox\Profiles\lyea7h4g.default-1451307230502\prefs.js, Gut: (user_pref("browser.startup.homepage", "https://www.malwarebytes.org/restorebrowser/), Schlecht: (user_pref("browser.startup.homepage", "http://www.bing.com/?pc=COSP&ptag=D022416-A6B219395BABB4E59ADF&form=CONMHP&conlogo=CT3332005), ,[295080e647523bfb447d909cd82dde22]
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end)