![]() |
VirTool:Win32/Obfuscator.ALA Hallo zusammen, ich benutze Windows 7, 64Bit Version. ich habe seit ein paar Tagen das Problem daß mir von Microsoft Essential das VirTool:Win32/Obfuscator.ALA angezeigt wird. Habe als Virusprogramm Avira von Antivir drauf der auch ständig anschlägt. Ich würd mich freuen wenn mir da jemand helfen könnte, da ich das Tool nicht herunter bekomme. Im voraus schonmal ganz lieben Dank. liebe Grüße Marion |
:hallo: Mein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...:abklatsch:
Hinweis:Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co. können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean :daumenhoc bekommst. Los geht's: Bitte auch das Log der AVPs oder einen Screenshot vom Fund posten. Danke! ;) Schritt 1 http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() Lesestoff Posten in CODE-Tags: So gehts... Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert uns massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
|
FRST.txt FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2014Additon.TXTFRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2014 |
Hi, Code: AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}![]() Info Mehrere Antivirusprogramme: Ich habe in den Logs festgestellt, dass auf diesem Rechner mehr als ein Antivirusprogramm mit Echtzeitschutz installiert ist. Das erzeugt antagonistische Effekte und vermindert dadurch die Schutzleistung. Die Sicherheit wird damit nicht erhöht. Bitte deinstalliere einen der beiden Scanner. Bitte poste mir vorher auch noch ein Log mit der Fundmeldung oder ein Screenshot davon. |
Kannst du mir bitte mal sagen wie ich hier einen Screenshot posten kann :)? http://www.directupload.net/file/d/3...644oxr_gif.htm |
Hi, mit dem SnippingTool von Windows ein Bild machen und anhängen. http://www.trojaner-board.de/attachm...eroklammer.png |
Scan von Microsoft Essential hxxp://www.directupload.net/file/d/3764/uj644oxr_gif.htm Habe Microsoft Essential deinstalliert |
OK... :) Schritt 1 Downloade Dir bitte
Schritt 2 http://filepony.de/icon/malwarebytes_anti_malware.png Malwarebytes Antimalware
Schritt 3 http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png Bitte starte FRST erneut, und drücke auf Scan. Bitte poste mir den Inhalt des Logs. |
Den Adw-Cleaner hab ich durchsuchen und löschen lassen. Danach ist der Rechner neu gestartet, das problem ist nur daß sich nach dem Neustart keine Text-Datei geöffnet hat |
Code: C:\AdwCleaner\AdwCleaner[Sx].txt |
Das habe ich schon versucht, nur finde ich die angegebene Datei nicht |
Weiter mit Schritt 2... ;) |
Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Suchlauf Datum: 03.10.2014 Suchlauf-Zeit: 14:15:09 Logdatei: Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.10.03.03 Rootkit Datenbank: v2014.09.19.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Marion Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 342403 Verstrichene Zeit: 11 Min, 13 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\Service\ttsvc.exe, 2368, Löschen bei Neustart, [dfa67d7296e5c96d26f88789e81bce32] Module: 0 (No malicious items detected) Registrierungsschlüssel: 48 PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D}\INPROCSERVER32, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{733413F4-5FB9-4EE9-8536-BF7AB1731A19}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3DD26F46-6B41-49B2-878E-1883411BBB59}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3DD26F46-6B41-49B2-878E-1883411BBB59}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{733413F4-5FB9-4EE9-8536-BF7AB1731A19}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6CB99040-7828-4C37-AC01-F15758F43E4D}, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [3055f7f8e3984cea5e68b61741c1de22], PUP.Optional.Outbrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6D4506CE-F855-4657-AA38-DB6B1F733982}, In Quarantäne, [98eda04f5a212f073de5ddf4ab57f20e], PUP.Optional.Snapdo.T, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Löschen bei Neustart, [fa8bd6197209d066fd22d100c1417090], PUP.Optional.Snapdo.T, HKU\S-1-5-21-3133097954-3543690179-3637798621-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, Löschen bei Neustart, [fa8bd6197209d066fd22d100c1417090], PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [fa8bd6197209d066fd22d100c1417090], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [b6cfe40b9fdca88ec923e3eae919857b], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [384dca25077487af509db01d679be51b], PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [483de807e09bfa3cbffca9ef3dc52cd4], PUP.Optional.WindowsProtectManger.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsMangerProtect, In Quarantäne, [a0e528c77b00d0664745e8ccf50ca45c], PUP.Optional.TermTutor.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\TermTutor, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ttsvc, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ttnfd, In Quarantäne, [374e42adc9b249eda77ad33d6f9417e9], PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{6ccfd995-07be-49cf-8ad6-1422dc08761a}Gw64, In Quarantäne, [9fe6a748cdae3ff701b9799f52b12bd5], PUP.Optional.AdvancedSystemProtector.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~4A5BE654_is1, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\UNINS000.EXE, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\UNINS000.EXE, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\IEXPLORE.EXE, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\IEXPLORE.EXE, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RegClean Pro_is1, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RegClean-Pro_is1, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [760f737cc8b372c4d781e45f27dc7090], PUP.Optional.SnipSmart.A, HKLM\SOFTWARE\WOW6432NODE\snipsmart, In Quarantäne, [ed9816d9c5b6ae882b54e9274eb5867a], PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [b1d411dee09bb4829730d0a87e862bd5], PUP.Optional.AdvancedSystemProtector.A, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\Advanced-System Protector, In Quarantäne, [6e17ad425c1f75c1d084d33f808327d9], PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\RegClean Pro, In Quarantäne, [7411ec03dc9f2b0bbf0e3ede5fa41fe1], PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [c0c5628d3c3f7eb83aeba27b0ef5e818], PUP.Optional.SnipSmart.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\snipsmart, Löschen bei Neustart, [f095f4fbe3987fb70d732de36c973dc3], PUP.Optional.WebSearches.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\SupHpUISoft, Löschen bei Neustart, [7d0849a68af1340250160e0650b3cb35], PUP.Optional.AlexaTB.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\DISTROMATIC\Toolbars, Löschen bei Neustart, [3c49c728cead50e61128aab5e91b2cd4], PUP.Optional.InstallCore.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [91f4f6f9e398cf67bba970d2e91a2ed2], PUP.Optional.InstallCore.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [bacb04ebd5a68caa912f094fba4a32ce], PUP.Optional.Qone8, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [1174826df48796a066f2e3814db71ee2], PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\SMARTBAR, Löschen bei Neustart, [374ec32c4437aa8c2014b8c2a85cd22e], PUP.Optional.Softonic.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\SOFTONIC\Universal Downloader, Löschen bei Neustart, [51345a9577042f07f6a9d1605ca7af51], PUP.Optional.AdvancedSystemProtector.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\SYSTWEAK\Advanced-System Protector, Löschen bei Neustart, [7b0aa54a522942f45104f022ec1707f9], PUP.Optional.RegCleanerPro.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\SYSTWEAK\RegClean Pro, Löschen bei Neustart, [196c07e890ebb482a8bb68f661a30bf5], PUP.Optional.SystemSpeedup, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\SYSTWEAK\ssd, Löschen bei Neustart, [a5e0935c057667cf2103a57834cf26da], Registrierungswerte: 7 PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [e89df9f6512a1125391539d810f3a15f] PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [a3e24ca3c8b30f27b79747caec176a96] PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD|ImagePath, system32\drivers\ttnfd.sys, In Quarantäne, [d4b159965c1fe650f72ba16f53b0f20e] PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTSVC|ImagePath, "C:\Program Files (x86)\TermTutor\Service\ttsvc.exe", In Quarantäne, [abda608fb6c548ee88971ff1da2956aa] PUP.Optional.InstallCore.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\INSTALLCORE|tb, 0R2Y1I1P1N0J1U1C, Löschen bei Neustart, [bacb04ebd5a68caa912f094fba4a32ce] PUP.Optional.ShoppingHelper.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\SMARTBAR|publisher, ShoppingHelper, Löschen bei Neustart, [374ec32c4437aa8c2014b8c2a85cd22e] PUP.Optional.Snapdo.T, HKU\S-1-5-21-3133097954-3543690179-3637798621-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, Löschen bei Neustart, [7114c62985f6cb6b49bc9f7cae5534cc] Registrierungsdaten: 18 PUP.Optional.SweetPage.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe sweet-page, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe sweet-page,[c8bd628dabd0280e71f4ee24a36257a9] PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[4f366c835427bf77c43c40d228dd28d8] PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe sweet-page, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe sweet-page,[394c3cb3f784241267fe1bf78580916f] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[e79e935cc0bb2214ab5555bd18ed956b] PUP.Optional.SnapDo.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}),Ersetzt,[8500d31c4b305ed836dafe0a8f76ea16] PUP.Optional.Snapdo, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}),Löschen bei Neustart,[4d38fcf39ae1b77fb9b9c34e2fd632ce] PUP.Optional.SweetPage.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, sweet-page, Gut: (Google), Schlecht: (sweet-page bei Neustart,[0382eb043249b97d74ef9f73759022de] PUP.Optional.SweetPage.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, sweet-page, Gut: (Google), Schlecht: (sweet-page bei Neustart,[1273ec03bcbf181eee74e52dca3ba858] PUP.Optional.Snapdo, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}),Löschen bei Neustart,[7015856a6318ce6889e8a36ef0157090] PUP.Optional.Snapdo, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}),Löschen bei Neustart,[3550da15502b93a3e58fa26f729351af] PUP.Optional.Snapdo, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}),Löschen bei Neustart,[7c0930bf3e3d979f91e4a071986d46ba] PUP.Optional.SnapDo.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8E&q={searchTerms}),Löschen bei Neustart,[c2c34ba4166563d3c24ffb0d01045ea2] PUP.Optional.Snapdo, HKU\S-1-5-21-3133097954-3543690179-3637798621-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, Search, Gut: (Google), Schlecht: (Search bei Neustart,[c0c5707fb8c34de9294aaf62c63f22de] PUP.Optional.Snapdo, HKU\S-1-5-21-3133097954-3543690179-3637798621-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}),Löschen bei Neustart,[1f66cb2432496dc9b7ba5db4fd08f20e] PUP.Optional.Snapdo, HKU\S-1-5-21-3133097954-3543690179-3637798621-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}),Löschen bei Neustart,[b1d45b942457af87ed8526ebd23347b9] PUP.Optional.Snapdo, HKU\S-1-5-21-3133097954-3543690179-3637798621-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}),Löschen bei Neustart,[1f662ac5f3888ea81a5ada3726df39c7] PUP.Optional.Snapdo, HKU\S-1-5-21-3133097954-3543690179-3637798621-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}),Löschen bei Neustart,[64213db2710a89add3a278990ef77c84] PUP.Optional.SnapDo.A, HKU\S-1-5-21-3133097954-3543690179-3637798621-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-2\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}, Gut: (Google), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3ZQQWmwISFOaNT7hqnI92GefcaOiGqj7qMARHotF8wUN9R0pSfDkxYBWbZcpKyBApVw66E0Q3PMXqFzbCsF1GTh29itQutrYWtInEi3pLzRXC9Fd5B3XMdscL-Q1q1CG2Nls4zTLtlhNIwuSF6kmrs9zaRUtZIv8D&q={searchTerms}),Löschen bei Neustart,[c3c233bc3a413ef8fa173cccee1718e8] Ordner: 26 PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor, Löschen bei Neustart, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\IE, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\Service, Löschen bei Neustart, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.RegCleanPro.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro, In Quarantäne, [7f066b841e5d0a2c552a2efc3ac9fc04], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\clamunpack, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], Rogue.Multiple, C:\ProgramData\374311380, In Quarantäne, [dfa60be4e19af0469fdadcf5659df60a], PUP.Optional.Iminent.A, C:\Program Files (x86)\IminentToolbar, In Quarantäne, [e0a5d11e86f595a1cb43548d47bb37c9], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\voice, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\voice\de, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, In Quarantäne, [d6af5996a3d883b307208e6b976b7c84], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [d6af5996a3d883b307208e6b976b7c84], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn\3.0.0.10_0, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\Resources, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector, In Quarantäne, [6e175d924e2dc274e1ab9f656b98ac54], PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\signatures, In Quarantäne, [6e175d924e2dc274e1ab9f656b98ac54], PUP.Optional.AdvancedSystemProtector.A, C:\Users\Marion\AppData\Roaming\Systweak\Advanced-System Protector, In Quarantäne, [fd88c629d0abcb6bf29abb4906fdf709], PUP.Optional.AdvancedSystemProtector.A, C:\Users\Marion\AppData\Roaming\Systweak\Advanced-System Protector\2.1.1000.13727, In Quarantäne, [fd88c629d0abcb6bf29abb4906fdf709], Dateien: 188 PUP.Optional.TermTutor.A, C:\Windows\System32\drivers\ttnfd.sys, Löschen bei Neustart, [4501e093b242532c5b677dc52614d6eb], PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{6ccfd995-07be-49cf-8ad6-1422dc08761a}Gw64.sys, Löschen bei Neustart, [f3f99a5881b34d8f15235dead22528c6], PUP.Optional.TermTutor.A, C:\Program Files\TermTutor\IE\TermTutorClientIE.dll, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\IE\TermTutorClientIE.dll, In Quarantäne, [8104905f7209a1959560533f47bbba46], PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, In Quarantäne, [a0e528c77b00d0664745e8ccf50ca45c], PUP.Optional.AdvancedSystemProtector, C:\Windows\System32\sasnative64.exe, In Quarantäne, [2c5914db463547efd5a1a10eb54cdb25], PUP.Optional.InstalLCore, C:\Users\Marion\AppData\Local\Temp\is1242154493\16755580_stp.EXE, In Quarantäne, [aadb6986f586a78fbdcb4ba9d62ec937], PUP.Optional.InstalLCore, C:\Users\Marion\AppData\Local\Temp\is1242154493\423211_stp.EXE, In Quarantäne, [e1a415da631872c40b7d2dc7d92bd030], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\terms-of-service.rtf, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\Uninstall.exe, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses\buildcrx-license.txt, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses\Info-ZIP-license.txt, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses\nsJSON-license.txt, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\3rd Party Licenses\UAC-license.txt, In Quarantäne, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.TermTutor.A, C:\Program Files (x86)\TermTutor\Service\ttsvc.exe, Löschen bei Neustart, [dfa67d7296e5c96d26f88789e81bce32], PUP.Optional.AdvancedSystemProtector, C:\Windows\System32\Tasks\Advanced-System Protector_startup, In Quarantäne, [0283b6393645c17576509a781ce72ed2], PUP.Optional.AdvancedSystemProtector, C:\Users\Public\Desktop\Advanced-System Protector.lnk, In Quarantäne, [1e67cc2389f2c076064af61df70cfe02], PUP.Optional.RegCleanerPro, C:\Users\Public\Desktop\RegClean Pro.lnk, In Quarantäne, [5431fcf31a6145f13939d73e0af94bb5], PUP.Optional.RegCleanerPro, C:\Windows\System32\Tasks\RegClean Pro, In Quarantäne, [582d7877b8c3a78fcba9b85d4ab958a8], PUP.Optional.RegCleanPro.A, C:\Windows\System32\Tasks\RegClean Pro_DEFAULT, In Quarantäne, [0d78d916bfbc74c2b209bb64b152ca36], PUP.Optional.RegCleanPro.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro\Register RegClean Pro.lnk, In Quarantäne, [7f066b841e5d0a2c552a2efc3ac9fc04], PUP.Optional.RegCleanPro.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro\RegClean Pro entfernen.lnk, In Quarantäne, [7f066b841e5d0a2c552a2efc3ac9fc04], PUP.Optional.RegCleanPro.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegClean Pro\RegClean Pro.lnk, In Quarantäne, [7f066b841e5d0a2c552a2efc3ac9fc04], PUP.Optional.RegCleanerPro.J, C:\Windows\Tasks\RegClean Pro_UPDATES.job, In Quarantäne, [2d58905f6e0de94dc0f7fd475da660a0], PUP.Optional.RegCleanPro.A, C:\Windows\Tasks\RegClean Pro_DEFAULT.job, In Quarantäne, [e4a16b842f4ceb4b8ad6fe5923e1f20e], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe.config, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\norwegian_asp_NO.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\AdvancedSystemProtector.exe, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\AppResource.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\asp.ico, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\AspManager.exe, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\aspsys.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\ASPUninstall.exe, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\categories.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Chinese_asp_ZH-CN.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Chinese_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\danish_asp_DA.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Danish_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\dutch_asp_NL.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Dutch_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\eng_asp_en.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\eng_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\filetypehelper.exe, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Finnish_asp_FI.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Finnish_uninst_fi.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\french_asp_FR.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\French_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\german_asp_DE.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\German_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Norwegian_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\polish_uninst_pl.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\portugese_uninst_pt.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\portuguese_asp_PT-BR.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Portuguese_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\russian_asp_ru.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\russian_uninst_ru.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\scandll.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\spanish_asp_ES.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\spanish_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\swedish_asp_SV.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\swedish_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\greek_uninst_el.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Interop.IWshRuntimeLibrary.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\italian_asp_IT.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Italian_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\japanese_asp_JA.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Japanese_uninst.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\korean_uninst_ko.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\loading_withWhiteBG.avi, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Microsoft.Win32.TaskScheduler.DLL, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\System.Core.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\System.Data.SQLite.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\TPS.ico, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\traditionalcn_uninst_zh-tw.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Turkish_uninst_tr.ini, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\unins000.dat, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\unins000.exe, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\unins000.msg, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\unrar.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.Compression.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.Compression.Formats.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.FileSystem.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Xceed.Zip.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\clamunpack\clamscan.exe, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\clamunpack\libclamav.dll, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\clamunpack\readme.txt, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\asp-fixer.com, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\asp-fixer.exe, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\asp-fixer.pif, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\asp-fixer.scr, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\ASP-Troubleshooter.chm, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\firefox.com, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\iexplore.exe, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.AdvancedSystemProtector.A, C:\Program Files (x86)\ASP\Troubleshooter\iexplore.lnk, In Quarantäne, [c4c1ac437506d95d45bd67142ada02fe], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Chinese_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\FileList.rcp, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Chinese_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\CleanSchedule.exe, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Danish_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Danish_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Dutch_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Dutch_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\eng_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\eng_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Japanese_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Japanese_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\korean_rcp_ko.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\korean_uninst_ko.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\LicMgr.dll, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Norwegian_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Norwegian_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\polish_rcp_pl.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\polish_uninst_pl.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\portugese_rcp_pt.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\portugese_uninst_pt.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Portuguese_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Portuguese_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\RCPUninstall.exe, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Finnish_rcp_fi.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Finnish_uninst_fi.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\French_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\French_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\German_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\German_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\greek_rcp_el.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\greek_uninst_el.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\install_left_image.bmp, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\isxdl.dll, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Italian_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Italian_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\RegCleanPro.exe, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\RegList.rcp, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\russian_rcp_ru.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\russian_uninst_ru.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Spanish_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\spanish_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Swedish_rcp.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\swedish_uninst.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\systweakasp.exe, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\TPS.ico, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\TraditionalCn_rcp_zh-tw.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\traditionalcn_uninst_zh-tw.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\turkish_rcp_tr.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\Turkish_uninst_tr.ini, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\unins000.dat, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\unins000.exe, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\unins000.msg, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanPro.A, C:\Program Files (x86)\RCP\xmllite.dll, In Quarantäne, [285de10ea3d8d36355af7dfe2dd7d42c], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\backup0.bin, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\backup3.bin, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\backup4.bin, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\backup6.bin, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\ExcludeList.rcp, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\German_rcp.dat, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\log_10-03-2014.log, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\rcpupdate.ini, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\results.rcp, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\TempHLList.rcp, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000001.rmx, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\Partial Backups\00000001.rxb, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.RegCleanerPro.A, C:\Users\Marion\AppData\Roaming\Systweak\RegClean Pro\Version 6.1\voice\de\voice.wav, In Quarantäne, [463f1fd05328ac8a167d12cfac56b54b], PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [d6af5996a3d883b307208e6b976b7c84], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn\3.0.0.10_0\background.html, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn\3.0.0.10_0\background.js, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn\3.0.0.10_0\icon128.png, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn\3.0.0.10_0\icon16.png, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn\3.0.0.10_0\icon48.png, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn\3.0.0.10_0\jigsaw.js, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn\3.0.0.10_0\jquery.js, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.Boost.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Extensions\igckfjdcbkimejmjmpmebffdjjjgncfn\3.0.0.10_0\manifest.json, In Quarantäne, [3f46d21db2c90f271d0511e9c33fc23e], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\BrowserSafeguard.exe, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\makecert.exe, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\TrustedRoot.cer, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\uninstall.BrowserSafeguard.exe, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\Resources\certutil.exe, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\Resources\libnspr4.dll, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\Resources\libplc4.dll, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\Resources\libplds4.dll, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\Resources\nss3.dll, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\Resources\smime3.dll, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.BrowserSafeGuard, C:\Users\Marion\AppData\Local\BrowserSafeguard\Resources\softokn3.dll, In Quarantäne, [dda80ce388f3ba7c6f4018ea61a27f81], PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\AddonSafelist, In Quarantäne, [6e175d924e2dc274e1ab9f656b98ac54], PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System Protector\log.xslt, In Quarantäne, [6e175d924e2dc274e1ab9f656b98ac54], PUP.Optional.AdvancedSystemProtector.A, C:\Users\Marion\AppData\Roaming\Systweak\Advanced-System Protector\Settings.db, In Quarantäne, [fd88c629d0abcb6bf29abb4906fdf709], PUP.Optional.AdvancedSystemProtector.A, C:\Users\Marion\AppData\Roaming\Systweak\Advanced-System Protector\2.1.1000.13727\ASPLog.txt, In Quarantäne, [fd88c629d0abcb6bf29abb4906fdf709], PUP.Optional.SweetPage.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://www.sweet-page.com/?type=hp&ts=1412337400&from=cor&uid=WDCXWD10EZEX-00KUWA0_WD-WCC1S725322953229",), Ersetzt,[7b0a7b746c0f2b0bd4005de9b25355ab] PUP.Optional.SweetPage.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "search_url": "hxxp://www.sweet-page.com/web/?type=ds&ts=1412337400&from=cor&uid=WDCXWD10EZEX-00KUWA0_WD-WCC1S725322953229&q={searchTerms}"), Ersetzt,[8ef70ae5b2c959dd24b249fd13f2847c] PUP.Optional.SweetPage.A, C:\Users\Marion\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://www.sweet-page.com/?type=hp&ts=1412337400&from=cor&uid=WDCXWD10EZEX-00KUWA0_WD-WCC1S725322953229" ],), Ersetzt,[3a4ba44b3a410d295e7953f3bd487789] Physische Sektoren: 0 (No malicious items detected) (end) FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2014--- --- --- |
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2014--- --- --- FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2014--- --- --- |
Wenn Du mit diesem PC sensible Logins machst, also Online-Banking, paypal etc. dann bitte von einem sauberen PC aus (oder mit Handy, Tablet) die Passwörter ändern und diesen bis zum clean nicht mehr dafür verwenden. Schritt 1 Downloade Dir HitmanProhttp://deeprybka.trojaner-board.de/b.../hitmanpro.pngauf Deinen Desktop: HitmanPro-32 Bit Version HitmanPro-64 Bit Version
|
Code: HitmanPro 3.7.9.225 |
:wtf: komisches Log irgendwie... Code: 2014-10-03 13:44 - 2014-10-03 13:44 - 00716656 _____ ( ) C:\Users\Marion\Desktop\FileOpenerSetup.exeSchritt 1 http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...st/frstfix.png Drücke bitte die http://deeprybka.trojaner-board.de/b...ne/revo/w7.png + R Taste und schreibe notepad in das Ausführen Fenster. Klicke auf OK und kopiere nun den Text aus der Codebox in das leere Textdokument: Code: CloseProcesses:
Nach dem Reboot bitte das Log posten und dann: Dateien hochladen:
Bitte um Rückmeldung ob es geklappt hat! ;) Danke für Deine Hilfe! Diesmal den richtigen Adwcleaner laden...:) http://www.trojaner-board.de/157635-...s-richtig.html Schritt 2 Downloade Dir bitte
Schritt 3 http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png Bitte starte FRST erneut, und drücke auf Scan. Bitte poste mir den Inhalt des Logs. |
Du das tu ich nicht, das war die Datei die ich vorhin herunterladen sollte, deswegen hatte ich mich auch gewundert warum die Text-Datei nicht auf ging als der Computer neu gestartet war |
Kein Problem! :abklatsch: Hab den Baustein auf dem Handy noch nicht aktualisiert. :stirn: Sonst wäre das beim 1. Post dabei gewesen. http://www.trojaner-board.de/157635-...s-richtig.html |
Ich habe nun die Datei abgespeichert unter FRST. Wenn ich dann auf Fix gehe, steht NO FIXLIST.TXT FOUND, the fixlist.txt should be in the same folder/directory the tool is located |
Du musst sie auf den Desktop abspeichern. ;) Code: Running from C:\Users\Marion\Desktop |
lach, du machst mich fertig ;) Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2014 Ran by Marion at 2014-10-03 16:31:57 Run:1 Running from C:\Users\Marion\Desktop Loaded Profiles: Marion & Acronis Agent User (Available profiles: Marion & Acronis Agent User) Boot Mode: Normal ============================================== Content of fixlist: ***************** 2014-10-03 13:44 - 2014-10-03 13:44 - 00716656 _____ ( ) C:\Users\Marion\Desktop\FileOpenerSetup.exe ***************** C:\Users\Marion\Desktop\FileOpenerSetup.exe => Moved successfully. ==== End of Fixlog ==== |
Und Du mich erst...:D Bitte die Datei auf den Desktop laden und Schritt 1 wiederholen. :) |
Das mit der Zip-Datei hat geklappt ;) |
Ja, aber bitte das machen was ich oben geschrieben habe. Du hast die falsche fixlist gemacht. Meine bitte runterladen und Fix wiederholen, zip- bitte wieder hochladen. |
Tut mir leid daß ich dich so stresse, das ist keine Absicht :) Sorry jetzt komm ich nicht mehr mit, ich hatte doch die kopiert die du mir geschickt hast |
Liste der Anhänge anzeigen (Anzahl: 1) Diese Datei bitte auf den Desktop ablegen (also runterladen und vom Download-Verzeichnis auf den Desktop kopieren) dann FRST-Fix wiederholen. Nach dem Reboot zip hochladen und weiter mit den nächsten Schritten. |
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 02-10-2014 Ran by Marion at 2014-10-03 17:00:04 Run:4 Running from C:\Users\Marion\Desktop Loaded Profiles: Marion & Acronis Agent User (Available profiles: Marion & Acronis Agent User) Boot Mode: Normal ============================================== Content of fixlist: ***************** CloseProcesses: HKLM\...\Run: [accessibility_api] => C:\ProgramData\Acronis\Acep\windows_sound_recorder\movie_maker\speed_dial\missed_call.exe [175616 2013-03-07] (American Megatrends, Inc) C:\ProgramData\Acronis\Acep\windows_sound_recorder\movie_maker\speed_dial\missed_call.exe HKU\S-1-5-21-3133097954-3543690179-3637798621-1000\...\Run: [accessibility_api] => C:\ProgramData\Acronis\Acep\windows_sound_recorder\movie_maker\speed_dial\missed_call.exe [175616 2013-03-07] (American Megatrends, Inc) C:\ProgramData\Acronis\Acep\windows_sound_recorder\movie_maker\speed_dial\missed_call.exe HKU\S-1-5-21-3133097954-3543690179-3637798621-1000\...\RunOnce: [queue] => C:\ProgramData\Acronis\AgentService\movie_moments\toolbar\recover\e_mail.exe [171520 2013-06-10] (Faronics Corporation) C:\ProgramData\Acronis\AgentService\movie_moments\toolbar\recover\e_mail.exe HKU\S-1-5-21-3133097954-3543690179-3637798621-1000\...\Winlogon: [Shell] C:\Program Files\Canon\MyPrinter\PL\32bit\app_bar\configuration.exe,explorer.exe <==== ATTENTION C:\Program Files\Canon\MyPrinter\PL\32bit\app_bar\configuration.exe SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = Task: {85F3EB34-4F79-4AD8-BFB5-B1650AD0535E} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION C:\Program Files (x86)\MyPC Backup S1 ddoiigbx; \??\C:\Windows\system32\drivers\ddoiigbx.sys [X] S3 DIRECTIO; \??\UNC\srv1c027-b.wds8-b.intern\reminst\Test\BitPro64\DirectIo.sys [X] S1 fsmsnfwt; \??\C:\Windows\system32\drivers\fsmsnfwt.sys [X] S1 ihnucalu; \??\C:\Windows\system32\drivers\ihnucalu.sys [X] S1 itcwrofb; \??\C:\Windows\system32\drivers\itcwrofb.sys [X] S1 jmkcmoxh; \??\C:\Windows\system32\drivers\jmkcmoxh.sys [X] S1 lacwkzcs; \??\C:\Windows\system32\drivers\lacwkzcs.sys [X] S1 lfjdnuqm; \??\C:\Windows\system32\drivers\lfjdnuqm.sys [X] S1 nesesnma; \??\C:\Windows\system32\drivers\nesesnma.sys [X] S1 nmwtxjbn; \??\C:\Windows\system32\drivers\nmwtxjbn.sys [X] S1 nqhqxrbj; \??\C:\Windows\system32\drivers\nqhqxrbj.sys [X] S1 ohryqmkp; \??\C:\Windows\system32\drivers\ohryqmkp.sys [X] S1 pqtxhguf; \??\C:\Windows\system32\drivers\pqtxhguf.sys [X] S1 rciklfqv; \??\C:\Windows\system32\drivers\rciklfqv.sys [X] S1 rhjxtslu; \??\C:\Windows\system32\drivers\rhjxtslu.sys [X] S1 tvmeatie; \??\C:\Windows\system32\drivers\tvmeatie.sys [X] 2014-09-29 11:20 - 2014-10-01 11:40 - 00000000 ___HD () C:\Users\Marion\AppData\Local\Dfsntdevjq 2014-09-27 15:20 - 2014-09-29 11:20 - 00000000 ___HD () C:\Users\Marion\AppData\Roaming\Owuu 2014-09-27 09:19 - 2014-09-27 15:20 - 00000000 ___HD () C:\Users\Marion\AppData\Local\Mdffocmx 2014-09-27 09:09 - 2014-09-29 11:34 - 00000000 ___HD () C:\Users\Marion\AppData\Roaming\Rtpzgejllg 2014-09-26 17:49 - 2014-09-27 09:19 - 00000000 ___HD () C:\Users\Marion\AppData\Roaming\Psny 2014-09-26 08:43 - 2014-09-26 23:15 - 00000000 ___HD () C:\Users\Marion\AppData\Roaming\Ydllnepc 2014-09-26 08:29 - 2014-09-26 17:49 - 00000000 ___HD () C:\Users\Marion\AppData\Local\Rqhcinlpl 2014-09-25 10:41 - 2014-10-03 14:27 - 00000000 ____D () C:\Users\Marion\AppData\Roaming\Systweak 2014-09-25 09:43 - 2014-09-25 11:13 - 00000000 ___HD () C:\Users\Marion\AppData\Roaming\Obfii 2014-09-25 09:32 - 2014-10-03 14:31 - 00000000 ____D () C:\ProgramData\evg 2014-09-25 09:31 - 2014-09-25 09:31 - 00000000 ___HD () C:\Users\Marion\AppData\Roaming\Xggt 2014-09-25 10:42 - 2014-09-25 10:42 - 00004030 _____ () C:\Windows\System32\Tasks\LaunchSignup Folder: C:\Users\Marion\AppData\Roaming\10tons 2014-10-03 13:46 - 2014-10-03 13:46 - 00000000 ____D () C:\Users\Marion\AppData\Roaming\1H1Q 2014-10-03 13:45 - 2014-10-03 14:27 - 00000000 ____D () C:\ProgramData\Systweak 2014-10-03 13:45 - 2014-10-03 13:56 - 00001157 _____ () C:\Users\Public\Desktop\FileOpener.lnk 2014-10-03 13:45 - 2014-10-03 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener 2014-10-03 13:45 - 2014-10-03 13:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced-System Protector 2014-10-03 13:45 - 2014-10-03 13:45 - 00000000 ____D () C:\Program Files\TermTutor 2014-10-03 13:45 - 2014-10-03 13:45 - 00000000 ____D () C:\Program Files (x86)\Tweaks 2014-10-03 13:44 - 2014-10-03 13:44 - 00716656 _____ ( ) C:\Users\Marion\Desktop\FileOpenerSetup.exe EmptyTemp: ***************** Processes closed successfully. HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\accessibility_api => Value not found. "C:\ProgramData\Acronis\Acep\windows_sound_recorder\movie_maker\speed_dial\missed_call.exe" => File/Directory not found. HKU\S-1-5-21-3133097954-3543690179-3637798621-1000\Software\Microsoft\Windows\CurrentVersion\Run\\accessibility_api => Value not found. "C:\ProgramData\Acronis\Acep\windows_sound_recorder\movie_maker\speed_dial\missed_call.exe" => File/Directory not found. HKU\S-1-5-21-3133097954-3543690179-3637798621-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\queue => value deleted successfully. "C:\ProgramData\Acronis\AgentService\movie_moments\toolbar\recover\e_mail.exe" => File/Directory not found. HKU\S-1-5-21-3133097954-3543690179-3637798621-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => value deleted successfully. "C:\Program Files\Canon\MyPrinter\PL\32bit\app_bar\configuration.exe" => File/Directory not found. HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully. "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => Key not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{85F3EB34-4F79-4AD8-BFB5-B1650AD0535E}" => Key not found. C:\Windows\System32\Tasks\LaunchSignup not found. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchSignup" => Key not found. "C:\Program Files (x86)\MyPC Backup" => File/Directory not found. ddoiigbx => Service not found. DIRECTIO => Service not found. fsmsnfwt => Service not found. ihnucalu => Service not found. itcwrofb => Service not found. jmkcmoxh => Service not found. lacwkzcs => Service not found. lfjdnuqm => Service not found. nesesnma => Service not found. nmwtxjbn => Service not found. nqhqxrbj => Service not found. ohryqmkp => Service not found. pqtxhguf => Service not found. rciklfqv => Service not found. rhjxtslu => Service not found. tvmeatie => Service not found. "C:\Users\Marion\AppData\Local\Dfsntdevjq" => File/Directory not found. "C:\Users\Marion\AppData\Roaming\Owuu" => File/Directory not found. "C:\Users\Marion\AppData\Local\Mdffocmx" => File/Directory not found. "C:\Users\Marion\AppData\Roaming\Rtpzgejllg" => File/Directory not found. "C:\Users\Marion\AppData\Roaming\Psny" => File/Directory not found. "C:\Users\Marion\AppData\Roaming\Ydllnepc" => File/Directory not found. "C:\Users\Marion\AppData\Local\Rqhcinlpl" => File/Directory not found. "C:\Users\Marion\AppData\Roaming\Systweak" => File/Directory not found. "C:\Users\Marion\AppData\Roaming\Obfii" => File/Directory not found. C:\ProgramData\evg => Moved successfully. "C:\Users\Marion\AppData\Roaming\Xggt" => File/Directory not found. "C:\Windows\System32\Tasks\LaunchSignup" => File/Directory not found. ========================= Folder: C:\Users\Marion\AppData\Roaming\10tons ======================== 2014-09-30 17:45 - 2014-09-30 17:45 - 0000000 ____D () C:\Users\Marion\AppData\Roaming\10tons\Sparkle_Unleashed 2014-09-30 17:45 - 2014-09-30 17:45 - 0000000 ____D () C:\Users\Marion\AppData\Roaming\10tons\Sparkle_Unleashed\profiles 2014-09-30 17:45 - 2014-10-01 09:46 - 0007827 _____ () C:\Users\Marion\AppData\Roaming\10tons\Sparkle_Unleashed\profiles\1.xml 2014-09-30 17:45 - 2014-09-30 17:46 - 0000463 _____ () C:\Users\Marion\AppData\Roaming\10tons\Sparkle_Unleashed\profiles\index.xml ====== End of Folder: ====== "C:\Users\Marion\AppData\Roaming\1H1Q" => File/Directory not found. "C:\ProgramData\Systweak" => File/Directory not found. "C:\Users\Public\Desktop\FileOpener.lnk" => File/Directory not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileOpener" => File/Directory not found. "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced-System Protector" => File/Directory not found. "C:\Program Files\TermTutor" => File/Directory not found. "C:\Program Files (x86)\Tweaks" => File/Directory not found. "C:\Users\Marion\Desktop\FileOpenerSetup.exe" => File/Directory not found. EmptyTemp: => Removed 93 KB temporary data. The system needed a reboot. ==== End of Fixlog ==== |
Naja, dreifach hält besser. ;) Jetzt bitte die zip hochladen... |
AdwCleaner Logfile: Code: # AdwCleaner v3.311 - Bericht erstellt am 03/10/2014 um 17:08:25die zip hab ich hochgeladen FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2014--- --- --- |
Gut gemacht soweit! :daumenhoc Bitte lasse die Datei aus der Code-Box bei http://deeprybka.trojaner-board.de/b...virustotal.png überprüfen.
|
da wird mir dann angezeigt daß Email.exe nicht zu finden ist |
Du hast doch die Probleme seit der Installation von Acronis oder? |
eher weniger, das lag an einer email die ich geöffnet habe, was ich nicht hätte machen sollen |
Haben die Scanner erst seit dem Öffnen der Mail gemotzt? Hast die Mail noch? OK, macht man eigentlich nicht wenn man schon gefixt hat, dennoch möchte ich wissen was CF dazu meint: Echtzeitscanner abschalten und Anweisungen genau befolgen bitte: http://www.trojaner-board.de/attachm...ackt-avira.png Scan mit Combofix
|
Code: ComboFix 14-10-02.01 - Marion 03.10.2014 18:00:37.1.4 - x64 |
OK bitte mal PC neu starten: Schritt 1 http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png Bitte starte FRST erneut, markiere auch die checkbox http://deeprybka.trojaner-board.de/b...t/addition.pngund drücke auf Scan. Bitte poste mir den Inhalt der beiden Logs die erstellt werden. |
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2014--- --- --- Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2014 |
Ok. Für heute machen wir erstmal Schluss an dieser Stelle. Melde mich dann so schnell wie möglich wieder. Den PC bitte solange nicht mehr mit dem Internet verbinden. Zitat:
|
Die Mail hab ich leider nicht mehr, hab sie gelöscht. Die Scanner haben erst angefangen als ich die Mail geöffnet hatte. |
Hi, Schritt 1 http://deeprybka.trojaner-board.de/b...isoft/emsi.png Download
|
Code: Emsisoft Emergency Kit - Version 9.0 |
Hi, gut gemacht. Bitte PC neustarten und frische FRST-Logs... Schritt 1 http://filepony.de/icon/frst.pnghttp://deeprybka.trojaner-board.de/b...t/frstscan.png Bitte starte FRST erneut, markiere auch die checkbox http://deeprybka.trojaner-board.de/b...t/addition.pngund drücke auf Scan. Bitte poste mir den Inhalt der beiden Logs die erstellt werden. |
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-10-2014--- --- --- Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-10-2014 |
Schau mal bitte in Dein Postfach hier beim Trojaner-Board. ;) |
| Alle Zeitangaben in WEZ +1. Es ist jetzt 16:18 Uhr. |
Copyright ©2000-2025, Trojaner-Board