fixlog: Code:
Entferungsergebnis von Farbar Recovery Scan Tool (x64) Version: 07-06-2017 01
durchgeführt von **** (07-06-2017 23:01:53) Run:3
Gestartet von C:\Users\****\Desktop
Geladene Profile: **** (Verfügbare Profile: ****)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
CloseProcesses:
2017-05-30 09:56 - 2017-05-30 09:56 - 0000017 _____ () C:\Users\****\AppData\Local\resmon.resmoncfg
EmptyTemp:
*****************
Prozesse erfolgreich geschlossen.
C:\Users\****\AppData\Local\resmon.resmoncfg => erfolgreich verschoben
=========== EmptyTemp: ==========
BITS transfer queue => 8675328 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9543911 B
Java, Flash, Steam htmlcache => 14649353 B
Windows/system/drivers => 93712 B
Edge => 0 B
Chrome => 0 B
Firefox => 48742487 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 2450 B
NetworkService => 0 B
**** => 7702541 B
RecycleBin => 0 B
EmptyTemp: => 85.3 MB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 23:01:55 ==== hitman: Code:
Code:
HitmanPro 3.7.20.286
www.hitmanpro.com
Computer name . . . . : WHOPPER
Windows . . . . . . . : 10.0.0.15063.X64/8
User name . . . . . . : WHOPPER\****
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2017-06-07 23:04:14
Scan mode . . . . . . : Normal
Scan duration . . . . : 1m 34s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 0
Traces . . . . . . . : 2
Objects scanned . . . : 1.731.855
Files scanned . . . . : 25.081
Remnants scanned . . : 369.347 files / 1.337.427 keys
Suspicious files ____________________________________________________________
C:\Users\****\Desktop\FRST-OlderVersion\FRST64.exe
Size . . . . . . . : 2.433.536 bytes
Age . . . . . . . : 5.2 days (2017-06-02 17:42:19)
Entropy . . . . . : 7.6
SHA-256 . . . . . : FE14D9CE6A7E6B6027AE58EDFA4AD710E822249417D951CFBE17EABEBABD9C85
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
C:\Users\****\Desktop\FRST64.exe
Size . . . . . . . : 2.435.072 bytes
Age . . . . . . . : 0.0 days (2017-06-07 23:01:08)
Entropy . . . . . : 7.6
SHA-256 . . . . . : 421AA5868869489A2DAE21E1FCD4D13791D3142A0A88D057ECEA602A0C3BB8C3
Needs elevation . : Yes
Fuzzy . . . . . . : 24.0
Program has no publisher information but prompts the user for permission elevation.
Entropy (or randomness) indicates the program is encrypted, compressed or obfuscated. This is not typical for most programs.
Authors name is missing in version info. This is not common to most programs.
Version control is missing. This file is probably created by an individual. This is not typical for most programs.
Time indicates that the file appeared recently on this computer.
ESET: Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=172004e16b0edb46904b707f6825dc1d
# end=init
# utc_time=2017-06-07 09:07:40
# local_time=2017-06-07 11:07:40 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 33649
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=172004e16b0edb46904b707f6825dc1d
# end=updated
# utc_time=2017-06-07 09:09:39
# local_time=2017-06-07 11:09:39 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=172004e16b0edb46904b707f6825dc1d
# engine=33649
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2017-06-07 09:51:20
# local_time=2017-06-07 11:51:20 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 96419 7005276 0 0
# scanned=313318
# found=24
# cleaned=0
# scan_time=2501
sh=B16B1DE7FFAFA5BD4D7ADB767B40516698F72C9B ft=1 fh=491523b26eeaee2a vn="Variante von Win64/Riskware.NetFilter.R Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\axhzlojlfwmllcgnwoloaxwjadiicood.back"
sh=AFFDAF63A959DCBE30EC8F6A5E567E30F30C3A20 ft=1 fh=a7244ce0ca5ee523 vn="Variante von Win32/Adware.Agent.NPN Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\phwstfciyqwkaseupooynqpxuwyzjnwj.back"
sh=BDFE1051D3ABBC4EF23FF00E51E3C9B76290DD31 ft=1 fh=9f4b1fe7e6383fea vn="Variante von Win32/Jawego.D eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\acvaqzajvzubcurffirvdwufeilgthfg\emsetup.exe"
sh=C6585F5B15F2AC23A9112451DD4C5C0268B1C457 ft=1 fh=5feca4a79c2dd30b vn="Variante von Win32/SuperTuneup.B eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\acvaqzajvzubcurffirvdwufeilgthfg\PCCleanPlus.exe"
sh=CF3192F6AAF3EE95437EDD5E16F6FABE627454D4 ft=1 fh=9693ea7b617f4684 vn="Variante von Win32/Taobao.F eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\cwynwdxopchlwuncwipuoyyxhzcbrznq\Bin\ChannelU.dll"
sh=ECC4BBED22FD5F57C4B3EB1BF927D966754DF864 ft=1 fh=9c73494d6bbf3c4e vn="Variante von Win32/Adware.Agent.NPN Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\epfamfldedxlxvnvpvkktmkpzgqqbhap\HelpTool.dll"
sh=B0D9531D85CB5C63B46400ED9BB8199922B4E54E ft=1 fh=6eea51b3ec706d37 vn="Variante von Win32/Adware.Eszjuxuan.A Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\epfamfldedxlxvnvpvkktmkpzgqqbhap\YeaDesktop.exe"
sh=6F86B0C40819785B3F42F4E5DCF8513BA2DFF3F8 ft=1 fh=e3f410659c8acd62 vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\gayxchxnzlhhwwyfxayknabryfwajxjy\MainService.exe"
sh=0C0C68AF84FC2970F8494E0B781812981F36F77E ft=1 fh=31dde2c0b3b8597c vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\gayxchxnzlhhwwyfxayknabryfwajxjy\PGChk.exe"
sh=F3B9857A368514A6BF35626F6769E4387EDE8DA3 ft=1 fh=efdd74c811ae89b7 vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\gayxchxnzlhhwwyfxayknabryfwajxjy\ProxyGate.exe"
sh=EE05E27A26C3852A835A007ADD1B89AFE5DD9B88 ft=1 fh=389f12129e92bc03 vn="Variante von Win32/ProxyGate.A eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\gayxchxnzlhhwwyfxayknabryfwajxjy\TrafficMonitor.exe"
sh=0A954DE1AD57FAC14B8E1093BC51829E1CD8AA1A ft=1 fh=ad2a9341c985c0b9 vn="Variante von Win32/Deceptor.SystemHealer.A Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\jlhmrrlrlmcfvqbocaftxtdvsqmskzcm\HealerConsole.exe"
sh=1FA2A9C019D321067CE9AE322A5C05F096C5F061 ft=1 fh=4121f3e18e6b36a1 vn="Variante von Win32/Adware.Adposhel.X Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\jlhmrrlrlmcfvqbocaftxtdvsqmskzcm\RescueMonitor.exe"
sh=F146DACC80FEFA06BD81AA2928C0C590AD2A5086 ft=1 fh=1b315b6eb78dffc9 vn="Variante von Win32/Deceptor.SystemHealer.A Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\jlhmrrlrlmcfvqbocaftxtdvsqmskzcm\SystemHealer.exe"
sh=A373EBC770CCE177E51695479309C1AF55974805 ft=1 fh=8daaad833d42c20e vn="Variante von Win32/Deceptor.SystemHealer.A Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\jlhmrrlrlmcfvqbocaftxtdvsqmskzcm\Uninstaller.exe"
sh=EEE6A904175D4F85C6C2B09DEE04ABFD39EEBA89 ft=1 fh=7fe1730ae29aaf68 vn="Variante von Win32/Jawego.D eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\vfbdqreoumaibaidroxjkhsjxamtgktv\em.exe"
sh=EA8F2CEC078F5369CE877C81D3F709D6FCF5DDE1 ft=1 fh=307c47462dcd751b vn="Variante von Win32/Jawego.C eventuell unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\vgiwgcowpncqiemriqhtqenbwnfpushu\pccleanplus.exe"
sh=CC9F655417921264A1673F5473FD0247DA81C301 ft=1 fh=bcaf1607da3b1e37 vn="Variante von Generik.CJUCHKW Trojaner" ac=I fn="C:\AdwCleaner\quarantine\files\vgiwgcowpncqiemriqhtqenbwnfpushu\uninstaller.exe"
sh=240B1FFE7220FF853DEC1F3139AE926AECC55890 ft=1 fh=5e35ff16c4e406cb vn="Variante von MSIL/Adware.OxyPumper.AA Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\xoxmbrxdxhtaetchhyqepaqwbffaifns\vmdiag.exe"
sh=17823A75CF929590D73405EE46EFA4364BEAE31E ft=1 fh=2f1fbb77134fc05c vn="Variante von MSIL/Adware.CsdiMonetize.K Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\INTERNET EXPLORER\056X34297Y\Y'JkDl1g3a.exe"
sh=D22E10F458A9597EE7BE791B76A98F442D7AE312 ft=1 fh=6a1495e05d5fb66a vn="Variante von Win32/Adware.ELEX.QL Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Ferbis\fastfind.dll"
sh=67D021F426C7469ADDCD79E376749334ADF393B1 ft=1 fh=8144cece57c50e5a vn="Variante von Win32/Adware.ELEX.QG Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files (x86)\Ferbis\goopdate.dll"
sh=2787380B27185780CF3CD28CC0CC7604A73ABB42 ft=1 fh=8ccf816383022d33 vn="Variante von Win32/Adware.Zdengo.V Anwendung" ac=I fn="C:\FRST\Quarantine\C\windows\eb40a68307d6d6774101e0cc417db863.exe.xBAD"
sh=27949493702C6C02FC7BDA802E258B09F3679076 ft=1 fh=b360d79adb21dd62 vn="Variante von MSIL/Adware.CsdiMonetize.O Anwendung" ac=I fn="C:\Program Files\Windows Photo Viewer\PF9EN7MZPG8PJRT7XQ49IUO12\Uvc8ar6pQv.exe" Mein Laptop läuft jetzt seit einigen Tagen flüssig, ich habe keine Adware, ungewünschte Werbung oder Verlangsamung mehr.
Das einzige, was noch auffällt ist, dass Malwarebytes die Meldung ,,initalpage123.com wurde blockiert'' gibt, sobald ich den Browser öffne. Google ich etwas, erhalte ich kein Suchergebniss, sondern nur eine Seite von Malwarebytes: ,,has blocked a potentially malicious website.'' |