Alles gemacht. (Beim ersten Start des PCs heute war übrigens wieder eine Warnung von "Advanced-System Protector" da...also war es noch da)
Beim Download von ADW-Cleaner hat avast! das zuerst blockiert, also hab ich ihn ausgeschaltet, dann ist es gegangen.
mbam log: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 13.10.2014
Suchlauf-Zeit: 18:49:01
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.10.13.05
Rootkit Datenbank: v2014.10.11.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: ****
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 361195
Verstrichene Zeit: 5 Min, 20 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\utilneurowise.exe, 3184, Löschen bei Neustart, [8dac40d44834ec4aa19e1796f50cf20e]
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe, 3284, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749]
Module: 7
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\aspsys.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Microsoft.Win32.TaskScheduler.DLL, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\System.Data.SQLite.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\unrar.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.Compression.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.FileSystem.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.Zip.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
Registrierungsschlüssel: 25
PUP.Optional.Neurowise.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util neurowise, In Quarantäne, [8dac40d44834ec4aa19e1796f50cf20e],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [8dac908490ece35386631abac04205fb],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [8dac908490ece35386631abac04205fb],
PUP.Optional.SaveSence.A, HKU\S-1-5-21-2175078040-2326866684-2893729699-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}, In Quarantäne, [3ffa789c205c999d905c5647fc0624dc],
PUP.Optional.SaveSence.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}, In Quarantäne, [3ffa789c205c999d905c5647fc0624dc],
PUP.Optional.SaveSence.A, HKU\S-1-5-21-2175078040-2326866684-2893729699-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}, In Quarantäne, [3ffa789c205c999d905c5647fc0624dc],
PUP.Optional.Neurowise.A, HKU\S-1-5-21-2175078040-2326866684-2893729699-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{D08AB008-0647-4784-8E2C-5769CD4A7C3A}, In Quarantäne, [3efbb1636d0f43f3cf573466ed15ba46],
PUP.Optional.Neurowise.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{D08AB008-0647-4784-8E2C-5769CD4A7C3A}, In Quarantäne, [3efbb1636d0f43f3cf573466ed15ba46],
PUP.Optional.Neurowise.A, HKU\S-1-5-21-2175078040-2326866684-2893729699-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{D08AB008-0647-4784-8E2C-5769CD4A7C3A}, In Quarantäne, [3efbb1636d0f43f3cf573466ed15ba46],
PUP.Optional.Neurowise.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{724DD777-5654-4D06-B3BC-C2FF56615998}, In Quarantäne, [56e3c351cbb1a294cc726449b44d43bd],
PUP.Optional.Neurowise.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E693A372-A8D4-4CBD-B011-66358BEA2F48}, In Quarantäne, [56e3c351cbb1a294cc726449b44d43bd],
PUP.Optional.Neurowise.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{E693A372-A8D4-4CBD-B011-66358BEA2F48}, In Quarantäne, [56e3c351cbb1a294cc726449b44d43bd],
PUP.Optional.Neurowise.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{724DD777-5654-4D06-B3BC-C2FF56615998}, In Quarantäne, [56e3c351cbb1a294cc726449b44d43bd],
PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RegClean Pro_is1, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.Neurowise.A, HKLM\SOFTWARE\WOW6432NODE\neurowise, In Quarantäne, [9b9e9c78e9933600b86f68b9df247888],
PUP.Optional.SaveSense.A, HKLM\SOFTWARE\WOW6432NODE\SaveSense, In Quarantäne, [74c51004215b73c3fc5b541dd430817f],
PUP.Optional.AdvancedSystemProtector.A, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\Advanced-System Protector, In Quarantäne, [0e2b120294e8280e9abc2eee28db59a7],
PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\RegClean Pro, In Quarantäne, [60d95fb56c100b2b27a0988e33d08c74],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [28116ba9601cdd5951ccc95e63a0827e],
PUP.Optional.Neurowise.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update neurowise, In Quarantäne, [2b0ef420ff7db48209200a17c93ada26],
PUP.Optional.Neurowise.A, HKU\S-1-5-21-2175078040-2326866684-2893729699-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\neurowise, In Quarantäne, [6ccdfe1699e382b4bf695bc6da294fb1],
PUP.Optional.SaveSense.A, HKU\S-1-5-21-2175078040-2326866684-2893729699-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SaveSense, In Quarantäne, [bc7d8e86adcf1d193d17ec850df7c33d],
PUP.Optional.AdvancedSystemProtector.A, HKU\S-1-5-21-2175078040-2326866684-2893729699-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\Advanced-System Protector, In Quarantäne, [f5445eb67804f343fe595bc1887bc23e],
PUP.Optional.RegCleanerPro.A, HKU\S-1-5-21-2175078040-2326866684-2893729699-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\RegClean Pro, In Quarantäne, [1128ff154a32cf6783bacb9dc73dcb35],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-2175078040-2326866684-2893729699-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [d16851c34f2d2e08d14b62c5897a4bb5],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 23
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise, Löschen bei Neustart, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin, Löschen bei Neustart, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\plugins, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\clamunpack, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\voice, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\voice\de, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}\content, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}\content\images, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}\defaults, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}\defaults\preferences, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\updates, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\2.1.1000.13722, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\2.1.1000.13827, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\Logs, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
Dateien: 181
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\utilneurowise.exe, Löschen bei Neustart, [8dac40d44834ec4aa19e1796f50cf20e],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\neurowisebho.dll, In Quarantäne, [56e3c351cbb1a294cc726449b44d43bd],
PUP.Optional.RegCleanPro, C:\Windows\System32\roboot64.exe, In Quarantäne, [cd6c878d2f4d0b2b8c5efeb2679a2ad6],
PUP.Optional.AdvancedSystemProtector, C:\Windows\System32\sasnative64.exe, In Quarantäne, [0b2e0c087dff989eebfe38780ff226da],
PUP.Optional.AdvancedSystemProtector, C:\Windows\System32\Tasks\Advanced-System Protector_startup, In Quarantäne, [77c215ff136970c63b8bb963ea19e61a],
PUP.Optional.Neurowise.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{fe651286-52a1-461b-a17a-f258b4b81968}.xpi, In Quarantäne, [1524b85c91eb65d1da512cf1e221827e],
PUP.Optional.RegCleanerPro, C:\Windows\System32\Tasks\RegClean Pro, In Quarantäne, [47f20e06374563d36905fb242cd741bf],
PUP.Optional.RegCleanerPro, C:\Windows\System32\Tasks\ASP, In Quarantäne, [db5ecf45fb811d199bd4120d5ba80ef2],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\neurowise.ico, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\0, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\updateneurowise.InstallState, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\sqlite3.dll, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\utilneurowise.InstallState, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\plugins\neurowise.BOAS.dll, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\plugins\neurowise.Bromon.dll, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\plugins\neurowise.BroStats.dll, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\plugins\neurowise.CompatibilityChecker.dll, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\plugins\neurowise.FFUpdate.dll, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.Neurowise.A, C:\Program Files (x86)\neurowise\bin\plugins\neurowise.IEUpdate.dll, In Quarantäne, [bc7de33195e7bf77e73fec3558ab10f0],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe.config, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\norwegian_asp_NO.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\AppResource.dll, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\asp.ico, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\AspManager.exe, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\aspsys.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\ASPUninstall.exe, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\categories.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Chinese_asp_ZH-CN.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Chinese_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\danish_asp_DA.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Danish_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\dutch_asp_NL.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Dutch_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\eng_asp_en.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\eng_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\filetypehelper.exe, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Finnish_asp_FI.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Finnish_uninst_fi.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\french_asp_FR.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\French_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\german_asp_DE.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\German_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Norwegian_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\polish_uninst_pl.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\portugese_uninst_pt.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\portuguese_asp_PT-BR.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Portuguese_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\russian_asp_ru.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\russian_uninst_ru.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\scandll.dll, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\spanish_asp_ES.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\spanish_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\swedish_asp_SV.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\swedish_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\greek_uninst_el.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Interop.IWshRuntimeLibrary.dll, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\italian_asp_IT.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Italian_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\japanese_asp_JA.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Japanese_uninst.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\korean_uninst_ko.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\loading_withWhiteBG.avi, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Microsoft.Win32.TaskScheduler.DLL, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\System.Core.dll, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\System.Data.SQLite.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\TPS.ico, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\traditionalcn_uninst_zh-tw.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Turkish_uninst_tr.ini, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\unins000.dat, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\unins000.exe, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\unins000.msg, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\unrar.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.Compression.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.Compression.Formats.dll, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.FileSystem.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.Zip.dll, Löschen bei Neustart, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\clamunpack\clamscan.exe, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\clamunpack\libclamav.dll, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\clamunpack\readme.txt, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\asp-fixer.com, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\asp-fixer.exe, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\asp-fixer.pif, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\asp-fixer.scr, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\ASP-Troubleshooter.chm, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\firefox.com, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\iexplore.exe, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\iexplore.lnk, In Quarantäne, [75c4ef25ef8db2848e42cbb9857fb749],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Chinese_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\FileList.rcp, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Chinese_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\CleanSchedule.exe, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Danish_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Danish_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Dutch_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Dutch_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\eng_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\eng_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Japanese_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Japanese_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\korean_rcp_ko.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\korean_uninst_ko.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\LicMgr.dll, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Norwegian_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Norwegian_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\polish_rcp_pl.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\polish_uninst_pl.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\portugese_rcp_pt.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\portugese_uninst_pt.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Portuguese_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Portuguese_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\RCPUninstall.exe, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Finnish_rcp_fi.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Finnish_uninst_fi.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\French_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\French_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\German_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\German_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\greek_rcp_el.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\greek_uninst_el.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\install_left_image.bmp, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\isxdl.dll, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Italian_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Italian_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\RegCleanPro.exe, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\RegList.rcp, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\russian_rcp_ru.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\russian_uninst_ru.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Spanish_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\spanish_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Swedish_rcp.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\swedish_uninst.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\systweakasp.exe, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\TPS.ico, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\TraditionalCn_rcp_zh-tw.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\traditionalcn_uninst_zh-tw.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\turkish_rcp_tr.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Turkish_uninst_tr.ini, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\unins000.dat, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\unins000.exe, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\unins000.msg, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\xmllite.dll, In Quarantäne, [81b8fd172f4df2444191a5dfd430a65a],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\backup3.bin, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\backup4.bin, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\backup6.bin, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\ExcludeList.rcp, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\German_rcp.dat, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\log_10-09-2014.log, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\results.rcp, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\TempHLList.rcp, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.RegCleanerPro.A, C:\Users\****\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\voice\de\voice.wav, In Quarantäne, [ca6f5cb8116ba69099251fc9659d8779],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}\chrome.manifest, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}\install.rdf, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}\content\savesense.xul, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}\content\images\icon32.png, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.SaveSense.A, C:\Users\****\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\extensions\{2fab2e94-d6f9-42de-8839-3510cef6424b}\defaults\preferences\defaults.js, In Quarantäne, [7ebb9a7ad4a8e155ac489b52ef137d83],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\AddonSafelist, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\log.xslt, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\completedatabase.db, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\Cookies.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\DigSign.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\FilePathFIX.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\FilePaths.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\FileSignature.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\Folders.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\Md5.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\Registry.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\SetupSign.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures\StrSetupSign.bin, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\updates\100oupdate.zip, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\updates\1971completedatabase.zip, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\updates\1985mupdate.zip, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\updates\1986update.zip, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\updates\1987update.zip, In Quarantäne, [3cfd48cc92ea61d5118e60ab63a0c937],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\ASPStartupManagerErrorLog.txt, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\QDetail.db, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\Settings.db, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\Update.ini, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\2.1.1000.13827\ASPLog.txt, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\Logs\log_12-10-14_07-24-37.xml, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\****\AppData\Roaming\Systweak\Advanced-System Protector\Logs\SMLog.xml, In Quarantäne, [a4957e9656266fc72e7154b7956eba46],
Physische Sektoren: 0
(No malicious items detected)
(end) ADW-Cleaner log: Code:
# AdwCleaner v4.000 - Bericht erstellt am 13/10/2014 um 19:05:11
# DB v2014-10-13.4
# Aktualisiert 12/10/2014 von Xplode
# Betriebssystem : Windows 7 Enterprise Service Pack 1 (64 bits)
# Benutzername : *** - ***-PC
# Gestartet von : C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UWXRS5OL\AdwCleaner_4.000 (1).exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\***\AppData\Roaming\ASP
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro
Ordner Gelöscht : C:\ProgramData\Systweak
Ordner Gelöscht : C:\Users\***\AppData\Roaming\Systweak
Datei Gelöscht : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default\user.js
***** [ Tasks ] *****
Task Gelöscht : advanced-System Protector_startup
Task Gelöscht : ASP
Task Gelöscht : RegClean Pro
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Myfree Codec
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17280
-\\ Mozilla Firefox v31.0 (x86 de)
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [2587 octets] - [13/10/2014 19:03:31]
AdwCleaner[S0].txt - [2386 octets] - [13/10/2014 19:05:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2446 octets] ########## JRT log: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.2 (10.09.2014:1)
OS: Windows 7 Enterprise x64
Ran by smayer on 13.10.2014 at 19:09:19,49
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.10.2014 at 19:14:14,59
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Neues FRST log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-10-2014 02
Ran by *** (administrator) on ***-PC on 13-10-2014 19:30:51
Running from C:\Users\***\Desktop
Loaded Profiles: *** & UpdatusUser (Available profiles: *** & UpdatusUser)
Platform: Windows 7 Enterprise Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Dropbox, Inc.) C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11786344 2014-08-17] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2207848 2014-08-17] (Realtek Semiconductor)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-08-17] (AVAST Software)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2014-02-07] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2175078040-2326866684-2893729699-1000\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1564992 2014-02-07] (Samsung)
HKU\S-1-5-21-2175078040-2326866684-2893729699-1001\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [241984 2011-11-27] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [203072 2011-11-27] (NVIDIA Corporation)
Startup: C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\***\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://ecosia.org/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x3E01AA8233BACF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - {10144D35-573A-49C8-9C44-8414ADC861FA} URL = hxxp://ecosia.org/search?q={searchTerms}&addon=opsensearch-ie
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Tcpip\Parameters: [DhcpNameServer] 82.209.169.71 82.209.169.72
FireFox:
========
FF ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\vi2usry4.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: google.com/WidevineMediaOptimizer -> C:\Users\***\AppData\Roaming\IDM\bin\npwidevinemediaoptimizer.dll (Google Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-08-17]
Chrome:
=======
CHR Profile: C:\Users\***\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-08-17]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-08-17] (AVAST Software)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-08-17] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-08-17] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-08-17] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-08-17] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-08-17] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-08-17] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-08-17] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-08-17] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-10-13] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-13 19:30 - 2014-10-13 19:30 - 02110464 _____ (Farbar) C:\Users\***\Desktop\FRST64.exe
2014-10-13 19:14 - 2014-10-13 19:14 - 00000696 _____ () C:\Users\***\Desktop\JRT.txt
2014-10-13 19:09 - 2014-10-13 19:09 - 00000000 ____D () C:\Windows\ERUNT
2014-10-13 19:06 - 2014-10-13 19:06 - 00002516 _____ () C:\Users\***\Desktop\AdwCleaner[S0].txt
2014-10-13 19:03 - 2014-10-13 19:05 - 00000000 ____D () C:\AdwCleaner
2014-10-13 18:58 - 2014-10-13 19:07 - 00036674 _____ () C:\Users\***\Desktop\mbam.txt
2014-10-13 18:48 - 2014-10-13 19:07 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-13 18:48 - 2014-10-13 18:48 - 00001112 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-13 18:48 - 2014-10-13 18:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-13 18:48 - 2014-10-13 18:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-13 18:48 - 2014-10-13 18:48 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-13 18:48 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-13 18:48 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-13 18:48 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-12 22:14 - 2014-10-12 22:14 - 00029029 _____ () C:\Users\***\Desktop\combofix.txt
2014-10-12 22:06 - 2014-10-12 22:06 - 00029101 _____ () C:\ComboFix.txt
2014-10-12 21:59 - 2014-10-12 22:06 - 00000000 ____D () C:\Qoobox
2014-10-12 21:59 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-12 21:59 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-12 21:59 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-12 21:59 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-12 21:59 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-12 21:59 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-12 21:59 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-12 21:59 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-12 21:58 - 2014-10-12 22:05 - 00000000 ____D () C:\Windows\erdnt
2014-10-12 21:56 - 2014-10-12 21:56 - 05582915 _____ (Swearware) C:\Users\***\Desktop\ComboFix.exe
2014-10-12 21:48 - 2014-10-13 18:39 - 00000000 ____D () C:\Program Files\Google
2014-10-12 21:48 - 2014-10-13 18:39 - 00000000 ____D () C:\Program Files (x86)\Google
2014-10-12 21:48 - 2014-10-12 21:51 - 00000000 ____D () C:\Users\***\AppData\Local\Google
2014-10-12 21:48 - 2014-10-12 21:51 - 00000000 ____D () C:\ProgramData\Google
2014-10-12 20:30 - 2014-10-12 20:30 - 00000474 _____ () C:\Users\***\Desktop\defogger_disable.txt
2014-10-12 20:28 - 2014-10-12 20:33 - 00015562 _____ () C:\Users\***\Desktop\GMER.txt
2014-10-12 20:12 - 2014-10-12 20:33 - 00020187 _____ () C:\Users\***\Desktop\Addition.txt
2014-10-12 20:11 - 2014-10-13 19:30 - 00011398 _____ () C:\Users\***\Desktop\FRST.txt
2014-10-12 20:07 - 2014-10-13 19:30 - 00000000 ____D () C:\FRST
2014-10-12 20:03 - 2014-10-12 20:03 - 00000474 _____ () C:\Users\***\Desktop\defogger_disable.log
2014-10-12 20:03 - 2014-10-12 20:03 - 00000000 _____ () C:\Users\***\defogger_reenable
2014-10-10 10:45 - 2014-10-13 19:05 - 00059914 _____ () C:\Windows\PFRO.log
2014-10-10 10:45 - 2014-10-13 19:05 - 00000392 _____ () C:\Windows\setupact.log
2014-10-10 10:45 - 2014-10-10 10:45 - 00409832 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-10 10:45 - 2014-10-10 10:45 - 00109296 _____ () C:\Users\***\AppData\Local\GDIPFONTCACHEV1.DAT
2014-10-10 10:45 - 2014-10-10 10:45 - 00000000 _____ () C:\Windows\setuperr.log
2014-10-10 00:34 - 2014-10-10 00:34 - 00000000 ____D () C:\Users\***\AppData\Roaming\TeamViewer
2014-10-10 00:09 - 2014-10-10 00:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced-System Protector
2014-10-10 00:07 - 2014-10-10 00:07 - 00000000 ____D () C:\Users\***\AppData\Local\MediaMonkey
2014-10-10 00:06 - 2014-10-10 00:09 - 00000000 ____D () C:\Users\***\AppData\Roaming\MediaMonkey
2014-10-09 23:55 - 2014-10-09 23:55 - 00000000 ____D () C:\Users\***\AppData\Local\Macroplant,_LLC
2014-10-09 23:54 - 2014-10-10 00:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-10-09 23:54 - 2014-10-10 00:45 - 00000000 ____D () C:\Program Files (x86)\Sharepod
2014-10-09 23:27 - 2014-10-09 23:27 - 00001789 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-09 23:27 - 2014-10-09 23:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-09 23:27 - 2014-10-09 23:27 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-09 23:27 - 2014-10-09 23:27 - 00000000 ____D () C:\Program Files\iTunes
2014-10-09 23:27 - 2014-10-09 23:27 - 00000000 ____D () C:\Program Files\iPod
2014-10-09 23:27 - 2014-10-09 23:27 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-10-01 10:01 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-01 10:01 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-28 13:08 - 2014-09-28 13:08 - 00000000 ____D () C:\Users\***\Documents\Advanced Macro
2014-09-24 14:27 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-24 14:27 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-21 19:18 - 2014-10-10 00:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-09-21 19:18 - 2014-09-21 19:18 - 00000000 ___RD () C:\Program Files (x86)\Skype
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-13 19:12 - 2009-07-14 07:13 - 01400806 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-13 19:12 - 2009-07-14 06:45 - 00026512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-13 19:12 - 2009-07-14 06:45 - 00026512 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-13 19:07 - 2014-08-18 10:54 - 00000000 ___RD () C:\Users\***\Dropbox
2014-10-13 19:07 - 2014-08-17 18:08 - 00000000 ____D () C:\Users\***\AppData\Roaming\Dropbox
2014-10-13 19:05 - 2014-08-17 18:41 - 01133075 _____ () C:\Windows\WindowsUpdate.log
2014-10-13 19:05 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-13 18:55 - 2009-07-14 06:45 - 00000000 ____D () C:\Windows\Setup
2014-10-12 23:37 - 2014-08-17 18:09 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-12 22:11 - 2014-08-17 18:15 - 00002016 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-10-12 22:11 - 2014-08-17 17:57 - 00000872 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-10-12 22:06 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-10-12 22:05 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-12 21:49 - 2014-08-17 18:24 - 00000000 ____D () C:\Users\***\AppData\Local\Adobe
2014-10-12 21:48 - 2014-08-17 18:09 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-12 21:48 - 2014-08-17 18:09 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-12 21:48 - 2014-08-17 18:09 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-12 20:03 - 2014-08-17 17:40 - 00000000 ____D () C:\Users\***
2014-10-10 11:27 - 2014-08-17 18:01 - 00000000 ____D () C:\Users\***\AppData\Roaming\vlc
2014-10-10 01:06 - 2014-08-17 18:10 - 00000000 ____D () C:\Users\***\AppData\Roaming\Skype
2014-10-10 01:02 - 2014-08-17 18:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-10-10 01:02 - 2014-08-17 18:05 - 00000000 ____D () C:\Windows\Panther
2014-10-10 00:51 - 2014-08-17 18:10 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-10-10 00:51 - 2014-08-17 18:10 - 00000000 ____D () C:\ProgramData\Skype
2014-10-10 00:13 - 2014-08-17 18:05 - 00000000 ____D () C:\Program Files (x86)\Notepad++
2014-10-09 23:45 - 2014-08-17 18:17 - 00000000 ____D () C:\Users\***\AppData\Roaming\Apple Computer
2014-10-09 11:23 - 2014-08-30 19:43 - 00000000 ____D () C:\Users\***\Documents\Lund University
2014-10-06 16:21 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-10-03 13:51 - 2014-08-17 18:15 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-09-26 19:53 - 2014-08-17 18:20 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-20 15:44 - 2014-08-17 18:22 - 00000000 ____D () C:\Users\***\AppData\Local\Microsoft Help
2014-09-19 12:41 - 2014-08-17 18:15 - 00001029 _____ () C:\Users\***\Desktop\Dropbox.lnk
2014-09-19 12:41 - 2014-08-17 18:13 - 00000000 ____D () C:\Users\***\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-09-16 20:42 - 2014-08-30 23:12 - 00000000 ____D () C:\Windows\rescache
2014-09-15 09:06 - 2010-11-21 05:27 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-14 23:32 - 2014-08-19 21:08 - 00000000 ____D () C:\Users\***\AppData\Local\Viber
2014-09-14 23:15 - 2014-08-19 21:08 - 00000000 ____D () C:\Users\***\AppData\Roaming\ViberPC
Some content of TEMP:
====================
C:\Users\***\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpfj8kqa.dll
C:\Users\***\AppData\Local\Temp\Quarantine.exe
C:\Users\***\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-08 10:35
==================== End Of Log ============================ --- --- --- |