![]() |
Windows 8.1 64 Bit Internettabs öffnen sich automatisch Hallo Mein PC ist extrem langsam geworden. Ausserdem öffnen sich, wenn ich einen beliebiegen Browser starte, automatisch andere Internetseiten mit Werbung. Weiter schalten sich auf einigen Internetseiten die ich besuche, Werbebanner auf. Habe ein Lied heruntergeladen, das wohl nicht nur ein Lied war :( Besten Dank für die Hilfe! Freundliche Grüsse Baillan |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-02-2015 --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-02-2015 |
Lade Dir bitte von hier ![]()
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Suchlauf Datum: 13.02.2015 Suchlauf-Zeit: 11:15:52 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.02.13.03 Rootkit Datenbank: v2015.02.03.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Baillan Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 349058 Verstrichene Zeit: 13 Min, 35 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 3 Trojan.FakeMS, C:\Windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe, 2020, Löschen bei Neustart, [6f88fe1f88023105d6ac0508cb3751af] PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy.exe, 2868, Löschen bei Neustart, [50a752cbcdbd61d583b26afbb053d22e] PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe, 2020, Löschen bei Neustart, [956248d58efc6bcb862a225ecf347987] Module: 3 PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\mgwz.dll, Löschen bei Neustart, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\Installer.dll, Löschen bei Neustart, [956248d58efc6bcb862a225ecf347987], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\InstallerLibrary.dll, Löschen bei Neustart, [956248d58efc6bcb862a225ecf347987], Registrierungsschlüssel: 59 Trojan.FakeMS, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SystemUpdatekb70007, In Quarantäne, [6f88fe1f88023105d6ac0508cb3751af], PUP.Optional.SearchProtect.A, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [0bec09143753e94d8393af57f310db25], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{fc6837c6-c38c-4b28-8fdf-882c27696402}, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\Pfc6837c6_c38c_4b28_8fdf_882c27696402_.Pfc6837c6_c38c_4b28_8fdf_882c27696402_, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\Pfc6837c6_c38c_4b28_8fdf_882c27696402_.Pfc6837c6_c38c_4b28_8fdf_882c27696402_.9, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Pfc6837c6_c38c_4b28_8fdf_882c27696402_.Pfc6837c6_c38c_4b28_8fdf_882c27696402_, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Pfc6837c6_c38c_4b28_8fdf_882c27696402_.Pfc6837c6_c38c_4b28_8fdf_882c27696402_.9, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{FC6837C6-C38C-4B28-8FDF-882C27696402}, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FC6837C6-C38C-4B28-8FDF-882C27696402}, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FC6837C6-C38C-4B28-8FDF-882C27696402}, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FC6837C6-C38C-4B28-8FDF-882C27696402}, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FC6837C6-C38C-4B28-8FDF-882C27696402}, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1e96740b-33ca-4c20-94c7-24cab81638df}, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P1e96740b_33ca_4c20_94c7_24cab81638df_.P1e96740b_33ca_4c20_94c7_24cab81638df_, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P1e96740b_33ca_4c20_94c7_24cab81638df_.P1e96740b_33ca_4c20_94c7_24cab81638df_.9, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P1e96740b_33ca_4c20_94c7_24cab81638df_.P1e96740b_33ca_4c20_94c7_24cab81638df_, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P1e96740b_33ca_4c20_94c7_24cab81638df_.P1e96740b_33ca_4c20_94c7_24cab81638df_.9, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{1E96740B-33CA-4C20-94C7-24CAB81638DF}, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{1E96740B-33CA-4C20-94C7-24CAB81638DF}, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{1E96740B-33CA-4C20-94C7-24CAB81638DF}, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{1E96740B-33CA-4C20-94C7-24CAB81638DF}, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{1E96740B-33CA-4C20-94C7-24CAB81638DF}, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{142cf675-f4ff-4aed-890e-3bae7f87f6cc}, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P142cf675_f4ff_4aed_890e_3bae7f87f6cc_.P142cf675_f4ff_4aed_890e_3bae7f87f6cc_, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P142cf675_f4ff_4aed_890e_3bae7f87f6cc_.P142cf675_f4ff_4aed_890e_3bae7f87f6cc_.9, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P142cf675_f4ff_4aed_890e_3bae7f87f6cc_.P142cf675_f4ff_4aed_890e_3bae7f87f6cc_, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P142cf675_f4ff_4aed_890e_3bae7f87f6cc_.P142cf675_f4ff_4aed_890e_3bae7f87f6cc_.9, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{142CF675-F4FF-4AED-890E-3BAE7F87F6CC}, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{142CF675-F4FF-4AED-890E-3BAE7F87F6CC}, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{142CF675-F4FF-4AED-890E-3BAE7F87F6CC}, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{142CF675-F4FF-4AED-890E-3BAE7F87F6CC}, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{142CF675-F4FF-4AED-890E-3BAE7F87F6CC}, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [4fa829f4e9a145f184adb2465fa55ea2], PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, In Quarantäne, [e5127da0216955e105108f0bbe45ca36], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, In Quarantäne, [39be23facbbff244f215fdabbc47fc04], PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [a552839a2f5b9c9af041dd1be81c6e92], PUP.Optional.Booster.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}{774350ce}, In Quarantäne, [8e6970ad1e6ce551906bd1e1b1524ab6], PUP.Optional.Amonetize, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{AEB719FD-EDB0-43E9-B524-90F97C1E6499}, In Quarantäne, [40b79a836822a195698a6645dd26d828], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP, In Quarantäne, [e017b6678604f541686d3a6d838019e7], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [ed0ab865ed9d082e1de90f99748fea16], PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [2ccb44d9aedce45296a5e7b6aa590df3], PUP.Optional.Qone8, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [33c495881d6d0b2b54dc8573cf35b848], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{9B41579A-1996-42F9-8F84-7B7786818CEF}, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{7041156A-0D2B-4DCD-A8EE-D0608BFCB2D0}, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9B41579A-1996-42F9-8F84-7B7786818CEF}, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E2343056-CC08-46AC-B898-BFC7ACF4E755}, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{0F19EF48-CB8C-416A-B84C-C33B02970632}, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{382F6195-1B46-40D5-B9FD-0493263E6132}, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{DFF50D27-9859-4F50-9BE1-A4CBFA102B9D}, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{0F19EF48-CB8C-416A-B84C-C33B02970632}, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{382F6195-1B46-40D5-B9FD-0493263E6132}, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{DFF50D27-9859-4F50-9BE1-A4CBFA102B9D}, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{E0D6077D-7186-48B2-A6C6-2F7C533E8CFF}, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.SystemUpdate.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SystemUpdatekb70007, In Quarantäne, [956248d58efc6bcb862a225ecf347987], Registrierungswerte: 7 PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPDP|dir, C:\Program Files (x86)\SupTab, In Quarantäne, [e017b6678604f541686d3a6d838019e7] PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, amt, In Quarantäne, [ed0ab865ed9d082e1de90f99748fea16] PUM.Bad.Proxy, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:8118;https=127.0.0.1:8118, In Quarantäne, [fcfbad704545c67019db812a72912cd4] PUM.Bad.Proxy, HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:8118;https=127.0.0.1:8118, In Quarantäne, [a354011cd1b9d561777d58539271ea16] PUM.Bad.Proxy, HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:8118;https=127.0.0.1:8118, In Quarantäne, [da1dbd60137788aef004466535ceaf51] PUM.Bad.Proxy, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:8118;https=127.0.0.1:8118, In Quarantäne, [54a3f02d5f2bc6703abab1fa748f8d73] PUP.Optional.QuickStart.A, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, quick_start@gmail.com, In Quarantäne, [45b2c855602af046109f3184996a847c] Registrierungsdaten: 7 PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1417790499&from=wpc&uid=ST1000DM003-1CH162_Z1D810TL&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1417790499&from=wpc&uid=ST1000DM003-1CH162_Z1D810TL&q={searchTerms}),Ersetzt,[d91e74a95832f343d6a3644ea26303fd] PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, mystartsearch, Gut: (Google), Schlecht: (mystartsearch,[06f108158a00cc6a88f0a70bd92c748c] PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1417790499&from=wpc&uid=ST1000DM003-1CH162_Z1D810TL&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1417790499&from=wpc&uid=ST1000DM003-1CH162_Z1D810TL&q={searchTerms}),Ersetzt,[e7109b82d9b13afc83f74072a164d12f] PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1417790499&from=wpc&uid=ST1000DM003-1CH162_Z1D810TL&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1417790499&from=wpc&uid=ST1000DM003-1CH162_Z1D810TL&q={searchTerms}),Ersetzt,[7087c459c1c9e254e099e1d19a6b956b] PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, mystartsearch, Gut: (Google), Schlecht: (mystartsearch,[01f6e23b8efcc571ff79e0d2da2beb15] PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1417790499&from=wpc&uid=ST1000DM003-1CH162_Z1D810TL&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1417790499&from=wpc&uid=ST1000DM003-1CH162_Z1D810TL&q={searchTerms}),Ersetzt,[07f0b26b4b3ff3432d4d4d653bca8878] PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-590913564-4252522651-4106047901-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, mystartsearch, Gut: (Google), Schlecht: (mystartsearch,[50a7b76676148bab0774a60c947156aa] Ordner: 19 Rogue.Multiple, C:\ProgramData\3872871776, In Quarantäne, [9760ed302a603ff70dd16ed5f40fa45c], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\backup, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy, Löschen bei Neustart, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\images, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [a354bc61cbbfe05683f3df89758e8d73], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [a354bc61cbbfe05683f3df89758e8d73], PUP.Optional.MultiPlug.A, C:\ProgramData\50Coupons, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, C:\ProgramData\MInimumPricce, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.SupTab.A, C:\Users\Baillan\AppData\Roaming\SupTab, In Quarantäne, [3cbbd34a93f7d75f27d6264949ba49b7], PUP.Optional.MultiPlug.A, C:\ProgramData\BlockIt Ad remover, In Quarantäne, [86710716c3c775c170860671cb38ef11], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007, Löschen bei Neustart, [956248d58efc6bcb862a225ecf347987], PUP.Optional.FunDeals.A, C:\ProgramData\FunDeals, In Quarantäne, [f8ffa974f79351e565943a4c699a738d], Dateien: 122 Trojan.FakeMS, C:\Windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe, Löschen bei Neustart, [6f88fe1f88023105d6ac0508cb3751af], PUP.Optional.MultiPlug.A, C:\ProgramData\50CCoupponnS\Cc4SzTULDfiO2P.dll, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], PUP.Optional.MultiPlug.A, C:\ProgramData\50CCoupponnS\Cc4SzTULDfiO2P.x64.dll, In Quarantäne, [6b8c8994becc94a2029db0fc5baa3bc5], Trojan.Agent, C:\ProgramData\50Coupons\WS8mcI1ZtenrIp.exe, In Quarantäne, [d81f58c595f5f73fc612798c4db54ab6], PUP.Optional.MultiPlug.A, C:\ProgramData\JoniCoUponn\XxfS7S7rHKL4Xm.dll, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, C:\ProgramData\JoniCoUponn\XxfS7S7rHKL4Xm.x64.dll, In Quarantäne, [b146d14c9feb80b64a551b91986da45c], PUP.Optional.MultiPlug.A, C:\ProgramData\MInimumPricce\1aVBYdNOLOPQYO.dll, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], PUP.Optional.MultiPlug.A, C:\ProgramData\MInimumPricce\1aVBYdNOLOPQYO.x64.dll, In Quarantäne, [f7004ecfd1b936009a05a10b0df8946c], Trojan.Agent, C:\ProgramData\FunDeals\MgOOqZcLFB4GU1.exe, In Quarantäne, [5f983fde98f24ee88e4ad035a65c916f], PUP.Optional.Unizeto, C:\Users\Baillan\AppData\Local\Temp\180209.exe, In Quarantäne, [1bdcb6679af01d191373e419d22f8779], PUP.Optional.Conduit.A, C:\Users\Baillan\AppData\Local\Temp\nsm2AF0.exe, In Quarantäne, [599e5bc2dfab60d6f5d400a9bf425ca4], PUP.Optional.Unizeto, C:\Users\Baillan\AppData\Local\Temp\b98a07E37Fdb.exe, In Quarantäne, [a05708155f2bd462bec8629bdf22fd03], PUP.Optional.Unizeto, C:\Users\Baillan\AppData\Local\Temp\CFC92.exe, In Quarantäne, [fff8cf4e355551e5d1b556a726db59a7], PUP.Optional.SearchProtect.A, C:\Users\Baillan\AppData\Local\Temp\SPSetup.exe, In Quarantäne, [995e28f502880c2aba2c347f0df44cb4], PUP.Optional.Unizeto, C:\Users\Baillan\AppData\Local\Temp\375afac87.exe, In Quarantäne, [857249d44b3f56e0cbbb6796af529967], PUP.Optional.Unizeto, C:\Users\Baillan\AppData\Local\Temp\405D7932381d0.exe, In Quarantäne, [688fd14c8bff8fa7ff879a6315ec7c84], Trojan.FakeMS, C:\Users\Baillan\AppData\Local\Temp\MsiToExe.SetupExtension.msi, In Quarantäne, [39be2eef5238ed49a8da58b5de24669a], PUP.Optional.Unizeto, C:\Users\Baillan\AppData\Local\Temp\76F13f3201.exe, In Quarantäne, [d91e5cc1d4b60333b0d6feffce332dd3], PUP.Optional.V9.A, C:\Users\Baillan\AppData\Local\Temp\442764078\442764078.zipDir\qSE.exe, In Quarantäne, [32c589941f6b58de18121138cc346c94], PUP.Optional.Skytech.A, C:\Users\Baillan\AppData\Local\Temp\442764078\442764078.zipDir\UninstallManager.exe, In Quarantäne, [6a8d0617781271c5a298bbf247ba10f0], PUP.Optional.Bundle, C:\Users\Baillan\AppData\Local\Temp\64f81b15e9a78\temp\wpc_mystartsearch.exe, In Quarantäne, [cc2b27f62a605bdb6c4a965df40d19e7], PUP.Optional.Conduit.A, C:\Windows\Temp\nsdE7EE.exe, In Quarantäne, [01f678a517739a9c06c3c5e48e7343bd], PUP.Optional.Conduit.A, C:\Windows\Temp\nszCABC.exe, In Quarantäne, [f8ff110c7c0efe38d0f9a60360a1f709], PUP.Optional.Conduit.A, C:\Windows\Temp\nsrD88B.exe, In Quarantäne, [dc1b4bd2e3a7d56105c4614860a10bf5], PUP.Optional.Conduit.A, C:\Windows\Temp\nsnBABD.exe, In Quarantäne, [61967aa32f5b0f27b9102f7a13eed828], Trojan.FakeMS, C:\Windows\Installer\1a64af90.msi, In Quarantäne, [35c262bb0f7be353dda5000d7a88e917], PUP.Optional.MyStartSearch.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\mystartsearch.xml, In Quarantäne, [4ea924f9f496a49226ed1b7f0af91ae6], PUP.Optional.InetStat.A, C:\Users\Baillan\AppData\Roaming\InetStat\inetstat.exe, In Quarantäne, [fdfa8f8ec6c480b60d46c1db5da6ef11], Rogue.Multiple, C:\ProgramData\3872871776\BITECC4.tmp, In Quarantäne, [9760ed302a603ff70dd16ed5f40fa45c], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\Installer.dll, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\InstallerLibrary.dll, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\InstallFirefoxExtension.dll, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\InstallFirefoxExtension.InstallState, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\Newtonsoft.Json.dll, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\NewVersionUploader.exe, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\NewVersionUploader.exe.config, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\SQLite.Interop.dll, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\System.Data.SQLite.dll, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\win32.reg, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\WindowsUpdater.exe, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\WindowsUpdater.exe.config, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\backup\InstallerLibrary.dll, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\backup\System Update kb70007\backup\uninstall.exe, In Quarantäne, [0fe8db426d1df73f5cd89cc9cc37b24e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\AUTHORS.txt, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\config.txt, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\default.action, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\default.filter, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\LICENSE.txt, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\match-all.action, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\mgwz.dll, Löschen bei Neustart, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy.exe, Löschen bei Neustart, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy.log, Löschen bei Neustart, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\privoxy_uninstall.exe, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\README.txt, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\trust.txt, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.action, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.action_empty, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.filter, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\user.filter_old, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\p_doc.css, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\coding.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\cvs.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\documentation.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\index.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\introduction.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\newrelease.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\testing.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\developer-manual\webserver-update.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\configuration.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\contact.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\copyright.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\general.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\index.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\installation.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\misc.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\faq\trouble.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\images\files-in-use.jpg, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\images\proxy_setup.jpg, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\actions-file.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\appendix.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\config.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\configuration.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\contact.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\copyright.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\files-in-use.jpg, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\filter-file.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\index.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\installation.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\introduction.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\proxy2.jpg, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\proxy_setup.jpg, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\p_doc.css, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\quickstart.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\seealso.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\startup.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\templates.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\doc\user-manual\whatsnew.html, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\cgi-style.css, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\connect-failed, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-local-help, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-support-and-service, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-title, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\mod-unstable-warning, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\no-such-domain, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.Privoxy.A, C:\Program Files (x86)\MSR\Privoxy\templates\url-info-osd.xml, In Quarantäne, [50a752cbcdbd61d583b26afbb053d22e], PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [a354bc61cbbfe05683f3df89758e8d73], PUP.Optional.MultiPlug.A, C:\ProgramData\50Coupons\WS8mcI1ZtenrIp.dat, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, C:\ProgramData\50Coupons\WS8mcI1ZtenrIp.exe, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, C:\ProgramData\50Coupons\WS8mcI1ZtenrIp.tlb, In Quarantäne, [04f38499d9b14de920671f4cd330659b], PUP.Optional.MultiPlug.A, C:\ProgramData\MInimumPricce\1aVBYdNOLOPQYO.dat, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.MultiPlug.A, C:\ProgramData\MInimumPricce\1aVBYdNOLOPQYO.tlb, In Quarantäne, [2bcc50cd5436b87ea32d4d21c93a9c64], PUP.Optional.MultiPlug.A, C:\ProgramData\BlockIt Ad remover\BlockIt Ad remover.exe, In Quarantäne, [86710716c3c775c170860671cb38ef11], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\Installer.dll, Löschen bei Neustart, [956248d58efc6bcb862a225ecf347987], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\InstallerLibrary.dll, Löschen bei Neustart, [956248d58efc6bcb862a225ecf347987], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\Newtonsoft.Json.dll, In Quarantäne, [956248d58efc6bcb862a225ecf347987], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\SQLite.Interop.dll, In Quarantäne, [956248d58efc6bcb862a225ecf347987], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\System.Data.SQLite.dll, In Quarantäne, [956248d58efc6bcb862a225ecf347987], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\win32.reg, In Quarantäne, [956248d58efc6bcb862a225ecf347987], PUP.Optional.SystemUpdate.A, C:\Windows\Microsoft\SystemUpdatekb70007\WindowsUpdater.exe, Löschen bei Neustart, [956248d58efc6bcb862a225ecf347987], PUP.Optional.FunDeals.A, C:\ProgramData\FunDeals\MgOOqZcLFB4GU1.dat, In Quarantäne, [f8ffa974f79351e565943a4c699a738d], PUP.Optional.FunDeals.A, C:\ProgramData\FunDeals\MgOOqZcLFB4GU1.exe, In Quarantäne, [f8ffa974f79351e565943a4c699a738d], PUP.Optional.FunDeals.A, C:\ProgramData\FunDeals\MgOOqZcLFB4GU1.tlb, In Quarantäne, [f8ffa974f79351e565943a4c699a738d], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) AdwCleaner Logfile: Code: # AdwCleaner v4.110 - Bericht erstellt 13/02/2015 um 11:51:48 Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-02-2015 --- --- --- |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=636751be54b0be42865c5ad9cdaef462 # engine=22476 # end=stopped # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-14 11:20:23 # local_time=2015-02-15 12:20:23 (+0100, Mitteleuropäische Zeit) # country="Switzerland" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 131338 14260342 0 0 # scanned=191981 # found=30 # cleaned=0 # scan_time=9385 sh=8E93740966BA73F797D44E06261D90B433A2ACBD ft=1 fh=c71c0011e74117ce vn="Variante von Win32/Adware.MultiPlug.EG Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\AllCCheapiPricee\Zi7e9JawKNfkw7.dll.vir" sh=B5C30C332F71692D05F5A163332028E9E3B59176 ft=1 fh=e5f2212712c4a9c8 vn="Variante von Win64/Adware.MultiPlug.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\AllCCheapiPricee\Zi7e9JawKNfkw7.x64.dll.vir" sh=6B621B4CA688AFA20EAAAA9AF0DDC313B2362FB0 ft=1 fh=c71c00111f879ee5 vn="Variante von Win32/Adware.MultiPlug.EG Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\RegullarDeallS\mTj1RFhjJfaNDy.dll.vir" sh=6846423A48F90C458C16DEFE7E9D92EC51D49B46 ft=1 fh=8ed56cb48584d8c3 vn="Variante von Win64/Adware.MultiPlug.F Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\RegullarDeallS\mTj1RFhjJfaNDy.x64.dll.vir" sh=E791C9164A4F17FDA4F55442945346462FA1CA23 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\0f@OGVH2HmiT.net\content\bg.js.vir" sh=8014612FE4E86AFDA37999954AC8207AFE6BF807 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\9@jbiIchieA.org\content\bg.js.vir" sh=2B089A469713E65BB5B1E8601734669BE0667166 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\aSJ@BrfjyrQ.org\content\bg.js.vir" sh=1DCE1163222BB4CFDE41C543011F9D56338009D4 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\bFCn@5.com\content\bg.js.vir" sh=93D10F53BA2E23A2E681A417D2AB4E56F26A61E7 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\fd@5qV0HBr9.edu\content\bg.js.vir" sh=BAB2943DD7FA41813A7C844026DF3B05D38CF1DF ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\ifKlf@b1NI.com\content\bg.js.vir" sh=AED27064B2B28568C80025400C92ADB068FC279B ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\sF@OLBQQl1B.edu\content\bg.js.vir" sh=61A3881BFDFB5175F2A6E6FD537E5A5B3A1CCC3B ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\Zvk@kfMSKN.com\content\bg.js.vir" sh=EE2D8A0C16CB4F60E07AD30BC8F4AF2D25E4FF62 ft=1 fh=c2a60ef126908cf5 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSS.exe" sh=24A108C48173FDD9962F7CC3D4DB4B852D864838 ft=1 fh=0501d0dc4c9a869f vn="Variante von Win32/Systweak.N evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll" sh=915239C2678EFCE5C2E45012595BEA0C050864B4 ft=1 fh=9ca6c4d86ffea4d8 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe" sh=67A75BAA7A5BBB2EEEBB99D490F00F82D0BB1E09 ft=1 fh=5d5a0ac2ab2c0a85 vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe" sh=2C09414F7BCF16F3C9A358B5CCD4492EF7EEF08E ft=1 fh=5545a1a02bc092d6 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe" sh=322DCE4CCA5EB266FFEDD900C6D628769AD18300 ft=1 fh=b3d66e50f9e4f6b1 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe" sh=B8ED6D5A4537284C2C2F35C7236E57C50866592F ft=1 fh=c71c001130b855cf vn="Variante von Win32/SProtector.O evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\UpgraderLite\UpgraderLite.dll" sh=C2DAA9DDB3B35DD8DABBACE53020A1A4A785E1D5 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\ProgramData\dmphgiejllnfdeppeeplfjeekghmonbp\DApwbyD.js" sh=C70EB0EAC781E2374971AEA93EB27899D173D016 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\ProgramData\pjigibplibdclndolkajhcookogbpjgh\apgk.js" sh=C2DAA9DDB3B35DD8DABBACE53020A1A4A785E1D5 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Users\All Users\dmphgiejllnfdeppeeplfjeekghmonbp\DApwbyD.js" sh=C70EB0EAC781E2374971AEA93EB27899D173D016 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Users\All Users\pjigibplibdclndolkajhcookogbpjgh\apgk.js" sh=1BFA179C7DBDA181CE8ED124BEB4091574B7C9B3 ft=1 fh=c71c00111fb72831 vn="Variante von Win32/Adware.MultiPlug.DX Anwendung" ac=I fn="C:\Users\Baillan\AppData\Local\Temp\64f81b15e9a78\temp\putfu.exe" sh=FB3F7E2BF56F5EA06763303CDAA0E962E975E063 ft=1 fh=c0dea5299389dc4e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Baillan\AppData\Local\Temp\DMR\dmr_72.exe" sh=FB3F2E77CEBDC706721E75B695039B232B19A48E ft=1 fh=2d5664f1815eeba5 vn="Variante von Win32/SProtector.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Baillan\AppData\Local\Temp\is-0QCB8.tmp\OptProCrash.dll" sh=137A70A2E9217F23D70CF25D956D6D2F1C70ADCC ft=1 fh=a349b983a7c2545e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Baillan\Downloads\Calibre 32 Bit - CHIP-Installer.exe" sh=49ACAFACAAC62A745E69D71A58CC9453C41B15D0 ft=1 fh=b98f31ba52914450 vn="Variante von Win32/Toolbar.Conduit.I evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Baillan\Downloads\UBCD4WinV360.exe" sh=F661D5984279F8E188AFCBF3A07938F4B0305622 ft=1 fh=7d031498b8c1af67 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Baillan\Downloads\Windows Defender - CHIP-Installer.exe" sh=759443A17F389C99E242C3D223C5673099E6ECC7 ft=1 fh=acbe0709ebfea47e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Baillan\Downloads\Windows_KB890830_x86_V5.19 - CHIP-Installer.exe" ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=636751be54b0be42865c5ad9cdaef462 # engine=22479 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-15 11:51:11 # local_time=2015-02-15 12:51:11 (+0100, Mitteleuropäische Zeit) # country="Switzerland" # lang=1031 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 172786 14305390 0 0 # scanned=250731 # found=30 # cleaned=28 # scan_time=10555 sh=C2DAA9DDB3B35DD8DABBACE53020A1A4A785E1D5 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Users\All Users\dmphgiejllnfdeppeeplfjeekghmonbp\DApwbyD.js" sh=C70EB0EAC781E2374971AEA93EB27899D173D016 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Users\All Users\pjigibplibdclndolkajhcookogbpjgh\apgk.js" sh=8E93740966BA73F797D44E06261D90B433A2ACBD ft=1 fh=c71c0011e74117ce vn="Variante von Win32/Adware.MultiPlug.EG Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\AllCCheapiPricee\Zi7e9JawKNfkw7.dll.vir" sh=B5C30C332F71692D05F5A163332028E9E3B59176 ft=1 fh=e5f2212712c4a9c8 vn="Variante von Win64/Adware.MultiPlug.F Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\AllCCheapiPricee\Zi7e9JawKNfkw7.x64.dll.vir" sh=6B621B4CA688AFA20EAAAA9AF0DDC313B2362FB0 ft=1 fh=c71c00111f879ee5 vn="Variante von Win32/Adware.MultiPlug.EG Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\RegullarDeallS\mTj1RFhjJfaNDy.dll.vir" sh=6846423A48F90C458C16DEFE7E9D92EC51D49B46 ft=1 fh=8ed56cb48584d8c3 vn="Variante von Win64/Adware.MultiPlug.F Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\RegullarDeallS\mTj1RFhjJfaNDy.x64.dll.vir" sh=E791C9164A4F17FDA4F55442945346462FA1CA23 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\0f@OGVH2HmiT.net\content\bg.js.vir" sh=8014612FE4E86AFDA37999954AC8207AFE6BF807 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\9@jbiIchieA.org\content\bg.js.vir" sh=2B089A469713E65BB5B1E8601734669BE0667166 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\aSJ@BrfjyrQ.org\content\bg.js.vir" sh=1DCE1163222BB4CFDE41C543011F9D56338009D4 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\bFCn@5.com\content\bg.js.vir" sh=93D10F53BA2E23A2E681A417D2AB4E56F26A61E7 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\fd@5qV0HBr9.edu\content\bg.js.vir" sh=BAB2943DD7FA41813A7C844026DF3B05D38CF1DF ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\ifKlf@b1NI.com\content\bg.js.vir" sh=AED27064B2B28568C80025400C92ADB068FC279B ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\sF@OLBQQl1B.edu\content\bg.js.vir" sh=61A3881BFDFB5175F2A6E6FD537E5A5B3A1CCC3B ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Baillan\AppData\Roaming\Mozilla\Firefox\Profiles\wpouqvv8.default\Extensions\Zvk@kfMSKN.com\content\bg.js.vir" sh=EE2D8A0C16CB4F60E07AD30BC8F4AF2D25E4FF62 ft=1 fh=c2a60ef126908cf5 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSS.exe" sh=24A108C48173FDD9962F7CC3D4DB4B852D864838 ft=1 fh=0501d0dc4c9a869f vn="Variante von Win32/Systweak.N evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll" sh=915239C2678EFCE5C2E45012595BEA0C050864B4 ft=1 fh=9ca6c4d86ffea4d8 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe" sh=67A75BAA7A5BBB2EEEBB99D490F00F82D0BB1E09 ft=1 fh=5d5a0ac2ab2c0a85 vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe" sh=2C09414F7BCF16F3C9A358B5CCD4492EF7EEF08E ft=1 fh=5545a1a02bc092d6 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe" sh=322DCE4CCA5EB266FFEDD900C6D628769AD18300 ft=1 fh=b3d66e50f9e4f6b1 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe" sh=B8ED6D5A4537284C2C2F35C7236E57C50866592F ft=1 fh=c71c001130b855cf vn="Variante von Win32/SProtector.O evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Program Files (x86)\UpgraderLite\UpgraderLite.dll" sh=C2DAA9DDB3B35DD8DABBACE53020A1A4A785E1D5 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\ProgramData\dmphgiejllnfdeppeeplfjeekghmonbp\DApwbyD.js" sh=C70EB0EAC781E2374971AEA93EB27899D173D016 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\ProgramData\pjigibplibdclndolkajhcookogbpjgh\apgk.js" sh=1BFA179C7DBDA181CE8ED124BEB4091574B7C9B3 ft=1 fh=c71c00111fb72831 vn="Variante von Win32/Adware.MultiPlug.DX Anwendung (Gesäubert durch Löschen - in Quarantäne kopiert)" ac=C fn="C:\Users\Baillan\AppData\Local\Temp\64f81b15e9a78\temp\putfu.exe" sh=FB3F7E2BF56F5EA06763303CDAA0E962E975E063 ft=1 fh=c0dea5299389dc4e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Baillan\AppData\Local\Temp\DMR\dmr_72.exe" sh=FB3F2E77CEBDC706721E75B695039B232B19A48E ft=1 fh=2d5664f1815eeba5 vn="Variante von Win32/SProtector.E evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Baillan\AppData\Local\Temp\is-0QCB8.tmp\OptProCrash.dll" sh=137A70A2E9217F23D70CF25D956D6D2F1C70ADCC ft=1 fh=a349b983a7c2545e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Baillan\Downloads\Calibre 32 Bit - CHIP-Installer.exe" sh=49ACAFACAAC62A745E69D71A58CC9453C41B15D0 ft=1 fh=b98f31ba52914450 vn="Variante von Win32/Toolbar.Conduit.I evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Baillan\Downloads\UBCD4WinV360.exe" sh=F661D5984279F8E188AFCBF3A07938F4B0305622 ft=1 fh=7d031498b8c1af67 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Baillan\Downloads\Windows Defender - CHIP-Installer.exe" sh=759443A17F389C99E242C3D223C5673099E6ECC7 ft=1 fh=acbe0709ebfea47e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung (gelöscht - in Quarantäne kopiert)" ac=C fn="C:\Users\Baillan\Downloads\Windows_KB890830_x86_V5.19 - CHIP-Installer.exe" Results of screen317's Security Check version 0.99.96 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java 64-bit 8 Update 31 Adobe Flash Player 16.0.0.305 Adobe Reader XI Mozilla Firefox (35.0.1) ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Results of screen317's Security Check version 0.99.96 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java 64-bit 8 Update 31 Adobe Flash Player 16.0.0.305 Adobe Reader XI Mozilla Firefox (35.0.1) ````````Process Check: objlist.exe by Laurent```````` `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-02-2015 --- --- --- |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte. |
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-02-2015 Ran by Baillan at 2015-02-15 22:20:42 Run:1 Running from C:\Users\Baillan\Downloads Loaded Profiles: Baillan (Available profiles: Baillan) Boot Mode: Normal ============================================== Content of fixlist: ***************** ProxyEnable: [.DEFAULT] => Internet Explorer proxy is enabled. ProxyEnable: [S-1-5-19] => Internet Explorer proxy is enabled. ProxyEnable: [S-1-5-20] => Internet Explorer proxy is enabled. ProxyEnable: [S-1-5-21-590913564-4252522651-4106047901-1001] => Internet Explorer proxy is enabled. FF NetworkProxy: "http", "127.0.0.1" FF NetworkProxy: "http_port", 8118 FF NetworkProxy: "ssl", "127.0.0.1" FF NetworkProxy: "ssl_port", 8118 S2 774350ce; "C:\windows\system32\rundll32.exe" "c:\Program Files (x86)\UpgraderLite\UpgraderLite.dll",serv c:\Program Files (x86)\UpgraderLite Emptytemp: ***************** HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\S-1-5-21-590913564-4252522651-4106047901-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. Firefox Proxy settings were reset. 774350ce => Service deleted successfully. c:\Program Files (x86)\UpgraderLite => Moved successfully. EmptyTemp: => Removed 721 MB temporary data. The system needed a reboot. ==== End of Fixlog 22:20:59 ==== FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-02-2015 --- --- --- --- --- --- Vielen herzlichen Dank für die Hilfe! Weiss deine Mühe sehr zu schätzen Schrauber :) Darf ich fragen aus welcher Motivation ihr das macht? |
Das frag ich mich auch immer wieder :D Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Alles gut . Nochmals Besten Dank! |
Gern Geschehen :) |
Alle Zeitangaben in WEZ +1. Es ist jetzt 21:59 Uhr. |
Copyright ©2000-2025, Trojaner-Board