PeterPan | 01.09.2016 00:00 | mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 31.08.2016
Suchlaufzeit: 11:25
Protokolldatei: mbam.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2016.08.31.02
Rootkit-Datenbank: v2016.08.15.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: olgam
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 290378
Abgelaufene Zeit: 5 Min., 19 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 2
PUP.Optional.Wajam, HKLM\SOFTWARE\WajInterEn, In Quarantäne, [108e6de4801ad363210c7d3e0cf77789],
PUP.Optional.Wajam, HKLM\SOFTWARE\WOW6432NODE\WajInterEn, In Quarantäne, [930bff52a9f192a4ab82a9125ba836ca],
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 5
PUP.Optional.WebBar, C:\Windows\System32\config\systemprofile\AppData\Local\WebBar, In Quarantäne, [a7f7b9988f0b70c63838f8c3ae5516ea],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
Dateien: 56
PUP.Optional.WebBar, C:\Windows\System32\config\systemprofile\AppData\Local\WebBar\wb.log, In Quarantäne, [a7f7b9988f0b70c63838f8c3ae5516ea],
PUP.Optional.Revizer.PrxySvrRST, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage, In Quarantäne, [9fff55fc415950e69c5828b6ae557888],
PUP.Optional.Revizer.PrxySvrRST, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_static.re-markit00.re-markit.co_0.localstorage-journal, In Quarantäne, [148aea677a204beba54fc41a976cce32],
PUP.Optional.BestPriceNinja, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage, In Quarantäne, [96088bc67c1e60d6fe025c86a95a15eb],
PUP.Optional.BestPriceNinja, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage-journal, In Quarantäne, [504e470a8812181e39c7b42e679cae52],
PUP.Optional.BestPriceNinja, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage, In Quarantäne, [6539163bc8d2d264ed13806223e0e31d],
PUP.Optional.BestPriceNinja, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage-journal, In Quarantäne, [940a450c4456e84e8a76e6fc8c7751af],
PUP.Optional.eShopComp, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_pstatic.eshopcomp.com_0.localstorage, In Quarantäne, [d8c6252c29711026fa56796ec83b6f91],
PUP.Optional.eShopComp, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_pstatic.eshopcomp.com_0.localstorage-journal, In Quarantäne, [019d470a3664a0960a46f3f4dc2758a8],
PUP.Optional.eShopComp, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\http_pstatic.eshopcomp.com_0.localstorage, In Quarantäne, [4c522c25b8e238fec68a07e0bd46ad53],
PUP.Optional.eShopComp, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\http_pstatic.eshopcomp.com_0.localstorage-journal, In Quarantäne, [4f4f91c0eab0c2749bb50bdcd62d966a],
PUP.Optional.UTop, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_utop.it_0.localstorage, In Quarantäne, [693586cbaeeccb6bb79e9552b94a7f81],
PUP.Optional.UTop, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_utop.it_0.localstorage-journal, In Quarantäne, [0b935df4237740f6391cd512ad56f40c],
PUP.Optional.UTop, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\http_utop.it_0.localstorage, In Quarantäne, [f5a95001aded3006ce872dba867d53ad],
PUP.Optional.UTop, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\http_utop.it_0.localstorage-journal, In Quarantäne, [b3ebe56c6c2e65d1d4810ddacc376f91],
PUP.Optional.CrossRider, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, In Quarantäne, [6737f75aedad40f6fbbf50995da6d030],
PUP.Optional.CrossRider, C:\Users\olgam\AppData\Local\Chromium\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, In Quarantäne, [5a44232e7327c86e972335b417ec11ef],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\07da62a4b5091495bc214deea7eb8a88.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\3838f871cf7252b24211e3b02be042ef.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\1538af1b1e673ff19770e018be25caf1.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\1b63f008770206e732c06bc3f2c4d768.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\1f6b24aaeabaee9cfc5f5c418103a8f0.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\203bcdb69a5aba69f3ae0b988f90088a.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\2dc08b2a0c42589f102623e694ab8504.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\365c2c8c63ec84e369c3f1c09576041e.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\38ab55e8496585648db48e5735eca948.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\45418e1f6fb2554c4fb2c47dc500e7b7.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\4a5fc2fb2a2ecd5acbe7102040dfcf50.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\5843a9c7060b1c93d1c7bbeb848fca54.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\5a578dbed6821e10eac045a2489347f5.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\648975b8c978033d0beef53f89e27eb6.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\71009cc0a6ba38f3d1768226739ebca6.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\90f3b2fbef5fe0d6db09364c231d347d.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\9c5d0c9590589e602418a06fa974d76c.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\a683c61f61450481656553a2af387cf6.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\b39a3ffae555c2a35b20cbf24e4ffacb.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\c4b92228bc4c16428c0b36321d8f8fda.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\cf3b43769aa85eb53b63b8d7ad29b986.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\dae188dead76ee3794d1703d47b00700.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\dbf514ebff5e241671c8e2e7ca4a5eaf.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\e7ce84a0f171406cbc8a64e33c7b3819.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.Wajam.Gen, C:\Program Files\1affcf7fb076855377858474a13789ea\d9c3a7900d0e3b00328caabe675b659d\f7808e30b311e6f1937bc951d5d4b806.ico, In Quarantäne, [732bb998afeb65d18e386d87669d1ce4],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\HowToRemove.html, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\chromium-min.jpg, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\control panel-min-min.JPG, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\down.png, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\ff menu.JPG, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\ff search engine-min.png, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\hp-min ff.png, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\hp-min ie.png, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\search engine.gif, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\setup pages.gif, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\sp-min.png, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\start-min.jpg, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\HowToRemove\up.png, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
PUP.Optional.WinYahoo, C:\Users\olgam\AppData\Local\{F3FCC5A0-D754-A918-BACC-8CF09EA47068}\coti, In Quarantäne, [bae4f75a9208cf679ae06c3105ff27d9],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) Eset Online Scan Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=init
# utc_time=2016-08-29 09:38:50
# local_time=2016-08-29 11:38:50 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 30578
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=updated
# utc_time=2016-08-29 09:42:57
# local_time=2016-08-29 11:42:57 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# engine=30578
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2016-08-29 09:46:15
# local_time=2016-08-29 11:46:15 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode=freeze
# scanned=14828
# found=23
# cleaned=0
# scan_time=198
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\xbtmeeehrceiqdhbatvuxrdgcnyleode.back"
sh=2483A3CFD78B8430725D6428EA1D93B4213CE02A ft=1 fh=de3a60083678fff8 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\RescueMonitor.exe"
sh=319775C62B595BFAB5AF994180F144881524E110 ft=1 fh=e3ab7ddb7e055b12 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\SystemHealer.exe"
sh=352D94006557FFE56D0B3D4A3D53A33E1EDAA13B ft=1 fh=9c2deb251acdf724 vn="Variante von Win32/Systweak.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\bwfojvdjqgzukyjanilqdjbghocnlrre\winzipdu.exe"
sh=523DED566E785E6CE03F9A0F1E9387CE22220A7C ft=1 fh=c71c0011c52e71be vn="Variante von Win32/Adware.CloudGuard.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\ddnuuhidyqaezutghzytdnhbekpaizuq\ConsoleApplication1.dll"
sh=1F8B6EB234CEFA2929576F6BF03006071371B866 ft=1 fh=7453b3f73a41e764 vn="Win32/InstallCore.ACZ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\dlskainzuvztxqsemqngxasxkdumjbpf\Ravensburger tiptoi Packages\uninstaller.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\fakuntggvakyzaphldxxububpcslbwrf\19b689b7-7481-0.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kzwdqvqwzmbkyrxfnxihrlrkjcbwhrul\19b689b7-0815-1.d"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\isa.dll"
sh=13E74D6DA81122396FF0AEA4526D0F97792FEEB2 ft=1 fh=252fcb3fe8fcc619 vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\wbsvc.exe"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa.dll"
sh=1B0FAFADB96A3204ADE84E0CA75B08A3D1F6227C ft=1 fh=17a875c148afbb71 vn="Variante von Win64/WebBar.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa_x64.dll"
sh=64BF3D74D378137DCFD029C0B9E68ABD5771601F ft=1 fh=b19376104f5cd5ec vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\wb.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\okrqyhbhvayzsbcbjhaafmevkmavhryf\19b689b7-6815-1.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\uemkwzlvdknrcsbaqhbuyudkumcsrqoe\19b689b7-51c5-0.d"
sh=88C3275D35429BF52CFA571CDEF2EDF77475BC72 ft=1 fh=89941ec6341689f3 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\OneSystemCare.exe"
sh=79C5273491CE942B3A83F3DA30DE626DD889D8F6 ft=1 fh=84dce0a161783d9a vn="Variante von Win32/Adware.SpeedingUpMyPC.AR Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemCash.exe"
sh=AD4361F47171799A5628A31F98C4BAABD344A16C ft=1 fh=43269c3001716996 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemConsole.exe"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\387834b3c358f300c01dcd3ccb2cf86b\2370bcddcd14e1925cb970e83536de2c.exe.patcher"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\a142944bde42b743d8dfdbbe69da33b9\2370bcddcd14e1925cb970e83536de2c.exe"
sh=3F1ACAD7FD0A63C353E55CA3B1C7C0C1FE87768B ft=1 fh=e325d99799c60866 vn="Variante von Win32/Wajam.AH evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\a142944bde42b743d8dfdbbe69da33b9\3b67fbd47fcce720631001f76c855698.exe"
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\a142944bde42b743d8dfdbbe69da33b9\c9ce7465f7fbe4dc60fd0ce498ac1253.sys"
sh=C45D975AA9D6ADFA3DDE7B4474E82DFB5DF5EB0C ft=1 fh=026d01d7e6a9c806 vn="Variante von Win32/Wajam.AN evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\a142944bde42b743d8dfdbbe69da33b9\c6dee1fcda18f91b4a144256241d1ee3\dggenk.dll"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=init
# utc_time=2016-08-30 11:33:25
# local_time=2016-08-30 01:33:25 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 30585
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=updated
# utc_time=2016-08-30 11:34:29
# local_time=2016-08-30 01:34:29 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# engine=30585
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-08-30 11:37:54
# local_time=2016-08-30 01:37:54 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode=freeze
# scanned=19920
# found=23
# cleaned=0
# scan_time=205
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\xbtmeeehrceiqdhbatvuxrdgcnyleode.back"
sh=2483A3CFD78B8430725D6428EA1D93B4213CE02A ft=1 fh=de3a60083678fff8 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\RescueMonitor.exe"
sh=319775C62B595BFAB5AF994180F144881524E110 ft=1 fh=e3ab7ddb7e055b12 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\SystemHealer.exe"
sh=352D94006557FFE56D0B3D4A3D53A33E1EDAA13B ft=1 fh=9c2deb251acdf724 vn="Variante von Win32/Systweak.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\bwfojvdjqgzukyjanilqdjbghocnlrre\winzipdu.exe"
sh=523DED566E785E6CE03F9A0F1E9387CE22220A7C ft=1 fh=c71c0011c52e71be vn="Variante von Win32/Adware.CloudGuard.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\ddnuuhidyqaezutghzytdnhbekpaizuq\ConsoleApplication1.dll"
sh=1F8B6EB234CEFA2929576F6BF03006071371B866 ft=1 fh=7453b3f73a41e764 vn="Win32/InstallCore.ACZ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\dlskainzuvztxqsemqngxasxkdumjbpf\Ravensburger tiptoi Packages\uninstaller.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\fakuntggvakyzaphldxxububpcslbwrf\19b689b7-7481-0.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kzwdqvqwzmbkyrxfnxihrlrkjcbwhrul\19b689b7-0815-1.d"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\isa.dll"
sh=13E74D6DA81122396FF0AEA4526D0F97792FEEB2 ft=1 fh=252fcb3fe8fcc619 vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\wbsvc.exe"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa.dll"
sh=1B0FAFADB96A3204ADE84E0CA75B08A3D1F6227C ft=1 fh=17a875c148afbb71 vn="Variante von Win64/WebBar.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa_x64.dll"
sh=64BF3D74D378137DCFD029C0B9E68ABD5771601F ft=1 fh=b19376104f5cd5ec vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\wb.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\okrqyhbhvayzsbcbjhaafmevkmavhryf\19b689b7-6815-1.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\uemkwzlvdknrcsbaqhbuyudkumcsrqoe\19b689b7-51c5-0.d"
sh=88C3275D35429BF52CFA571CDEF2EDF77475BC72 ft=1 fh=89941ec6341689f3 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\OneSystemCare.exe"
sh=79C5273491CE942B3A83F3DA30DE626DD889D8F6 ft=1 fh=84dce0a161783d9a vn="Variante von Win32/Adware.SpeedingUpMyPC.AR Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemCash.exe"
sh=AD4361F47171799A5628A31F98C4BAABD344A16C ft=1 fh=43269c3001716996 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemConsole.exe"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\387834b3c358f300c01dcd3ccb2cf86b\2370bcddcd14e1925cb970e83536de2c.exe.patcher"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\a142944bde42b743d8dfdbbe69da33b9\2370bcddcd14e1925cb970e83536de2c.exe"
sh=3F1ACAD7FD0A63C353E55CA3B1C7C0C1FE87768B ft=1 fh=e325d99799c60866 vn="Variante von Win32/Wajam.AH evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\a142944bde42b743d8dfdbbe69da33b9\3b67fbd47fcce720631001f76c855698.exe"
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\a142944bde42b743d8dfdbbe69da33b9\c9ce7465f7fbe4dc60fd0ce498ac1253.sys"
sh=C45D975AA9D6ADFA3DDE7B4474E82DFB5DF5EB0C ft=1 fh=026d01d7e6a9c806 vn="Variante von Win32/Wajam.AN evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files\a142944bde42b743d8dfdbbe69da33b9\c6dee1fcda18f91b4a144256241d1ee3\dggenk.dll"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=init
# utc_time=2016-08-30 10:19:01
# local_time=2016-08-31 12:19:01 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 30591
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=updated
# utc_time=2016-08-30 10:20:04
# local_time=2016-08-31 12:20:04 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# engine=30591
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2016-08-30 10:55:00
# local_time=2016-08-31 12:55:00 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode=freeze
# scanned=201548
# found=25
# cleaned=0
# scan_time=2095
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\xbtmeeehrceiqdhbatvuxrdgcnyleode.back"
sh=2483A3CFD78B8430725D6428EA1D93B4213CE02A ft=1 fh=de3a60083678fff8 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\RescueMonitor.exe"
sh=319775C62B595BFAB5AF994180F144881524E110 ft=1 fh=e3ab7ddb7e055b12 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\SystemHealer.exe"
sh=352D94006557FFE56D0B3D4A3D53A33E1EDAA13B ft=1 fh=9c2deb251acdf724 vn="Variante von Win32/Systweak.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\bwfojvdjqgzukyjanilqdjbghocnlrre\winzipdu.exe"
sh=523DED566E785E6CE03F9A0F1E9387CE22220A7C ft=1 fh=c71c0011c52e71be vn="Variante von Win32/Adware.CloudGuard.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\ddnuuhidyqaezutghzytdnhbekpaizuq\ConsoleApplication1.dll"
sh=1F8B6EB234CEFA2929576F6BF03006071371B866 ft=1 fh=7453b3f73a41e764 vn="Win32/InstallCore.ACZ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\dlskainzuvztxqsemqngxasxkdumjbpf\Ravensburger tiptoi Packages\uninstaller.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\fakuntggvakyzaphldxxububpcslbwrf\19b689b7-7481-0.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kzwdqvqwzmbkyrxfnxihrlrkjcbwhrul\19b689b7-0815-1.d"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\isa.dll"
sh=13E74D6DA81122396FF0AEA4526D0F97792FEEB2 ft=1 fh=252fcb3fe8fcc619 vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\wbsvc.exe"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa.dll"
sh=1B0FAFADB96A3204ADE84E0CA75B08A3D1F6227C ft=1 fh=17a875c148afbb71 vn="Variante von Win64/WebBar.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa_x64.dll"
sh=64BF3D74D378137DCFD029C0B9E68ABD5771601F ft=1 fh=b19376104f5cd5ec vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\wb.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\okrqyhbhvayzsbcbjhaafmevkmavhryf\19b689b7-6815-1.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\uemkwzlvdknrcsbaqhbuyudkumcsrqoe\19b689b7-51c5-0.d"
sh=88C3275D35429BF52CFA571CDEF2EDF77475BC72 ft=1 fh=89941ec6341689f3 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\OneSystemCare.exe"
sh=79C5273491CE942B3A83F3DA30DE626DD889D8F6 ft=1 fh=84dce0a161783d9a vn="Variante von Win32/Adware.SpeedingUpMyPC.AR Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemCash.exe"
sh=AD4361F47171799A5628A31F98C4BAABD344A16C ft=1 fh=43269c3001716996 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemConsole.exe"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\387834b3c358f300c01dcd3ccb2cf86b\2370bcddcd14e1925cb970e83536de2c.exe.patcher"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\2370bcddcd14e1925cb970e83536de2c.exe"
sh=3F1ACAD7FD0A63C353E55CA3B1C7C0C1FE87768B ft=1 fh=e325d99799c60866 vn="Variante von Win32/Wajam.AH evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\3b67fbd47fcce720631001f76c855698.exe"
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\c9ce7465f7fbe4dc60fd0ce498ac1253.sys"
sh=C45D975AA9D6ADFA3DDE7B4474E82DFB5DF5EB0C ft=1 fh=026d01d7e6a9c806 vn="Variante von Win32/Wajam.AN evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\c6dee1fcda18f91b4a144256241d1ee3\dggenk.dll"
sh=DE076B0EE8BB0DE8185B973EA89B66B0A36E5CC9 ft=1 fh=22323d23463ce066 vn="Variante von Win32/InstallCore.AFV evtl. unerwünschte Anwendung" ac=I fn="C:\Users\olgam\Downloads\HDVideoPlayer.exe"
sh=747405747B2889028EEACD480EC035A31A01892A ft=1 fh=8f870d62e28e1116 vn="Variante von Win32/DownloadGuide.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\olgam\Downloads\install-avast-free-antivirus.exe"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=init
# utc_time=2016-08-31 08:35:30
# local_time=2016-08-31 10:35:30 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 30595
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=updated
# utc_time=2016-08-31 08:36:28
# local_time=2016-08-31 10:36:28 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# engine=30595
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-08-31 09:11:30
# local_time=2016-08-31 11:11:30 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode=freeze
# scanned=199970
# found=23
# cleaned=0
# scan_time=2101
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\xbtmeeehrceiqdhbatvuxrdgcnyleode.back"
sh=2483A3CFD78B8430725D6428EA1D93B4213CE02A ft=1 fh=de3a60083678fff8 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\RescueMonitor.exe"
sh=319775C62B595BFAB5AF994180F144881524E110 ft=1 fh=e3ab7ddb7e055b12 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\SystemHealer.exe"
sh=352D94006557FFE56D0B3D4A3D53A33E1EDAA13B ft=1 fh=9c2deb251acdf724 vn="Variante von Win32/Systweak.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\bwfojvdjqgzukyjanilqdjbghocnlrre\winzipdu.exe"
sh=523DED566E785E6CE03F9A0F1E9387CE22220A7C ft=1 fh=c71c0011c52e71be vn="Variante von Win32/Adware.CloudGuard.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\ddnuuhidyqaezutghzytdnhbekpaizuq\ConsoleApplication1.dll"
sh=1F8B6EB234CEFA2929576F6BF03006071371B866 ft=1 fh=7453b3f73a41e764 vn="Win32/InstallCore.ACZ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\dlskainzuvztxqsemqngxasxkdumjbpf\Ravensburger tiptoi Packages\uninstaller.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\fakuntggvakyzaphldxxububpcslbwrf\19b689b7-7481-0.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kzwdqvqwzmbkyrxfnxihrlrkjcbwhrul\19b689b7-0815-1.d"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\isa.dll"
sh=13E74D6DA81122396FF0AEA4526D0F97792FEEB2 ft=1 fh=252fcb3fe8fcc619 vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\wbsvc.exe"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa.dll"
sh=1B0FAFADB96A3204ADE84E0CA75B08A3D1F6227C ft=1 fh=17a875c148afbb71 vn="Variante von Win64/WebBar.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa_x64.dll"
sh=64BF3D74D378137DCFD029C0B9E68ABD5771601F ft=1 fh=b19376104f5cd5ec vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\wb.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\okrqyhbhvayzsbcbjhaafmevkmavhryf\19b689b7-6815-1.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\uemkwzlvdknrcsbaqhbuyudkumcsrqoe\19b689b7-51c5-0.d"
sh=88C3275D35429BF52CFA571CDEF2EDF77475BC72 ft=1 fh=89941ec6341689f3 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\OneSystemCare.exe"
sh=79C5273491CE942B3A83F3DA30DE626DD889D8F6 ft=1 fh=84dce0a161783d9a vn="Variante von Win32/Adware.SpeedingUpMyPC.AR Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemCash.exe"
sh=AD4361F47171799A5628A31F98C4BAABD344A16C ft=1 fh=43269c3001716996 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemConsole.exe"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\387834b3c358f300c01dcd3ccb2cf86b\2370bcddcd14e1925cb970e83536de2c.exe.patcher"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\2370bcddcd14e1925cb970e83536de2c.exe"
sh=3F1ACAD7FD0A63C353E55CA3B1C7C0C1FE87768B ft=1 fh=e325d99799c60866 vn="Variante von Win32/Wajam.AH evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\3b67fbd47fcce720631001f76c855698.exe"
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\c9ce7465f7fbe4dc60fd0ce498ac1253.sys"
sh=C45D975AA9D6ADFA3DDE7B4474E82DFB5DF5EB0C ft=1 fh=026d01d7e6a9c806 vn="Variante von Win32/Wajam.AN evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\c6dee1fcda18f91b4a144256241d1ee3\dggenk.dll"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=init
# utc_time=2016-08-31 09:46:11
# local_time=2016-08-31 11:46:11 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 30605
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# end=updated
# utc_time=2016-08-31 09:48:12
# local_time=2016-08-31 11:48:12 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=4cb19936edcf8a478d436a31278e5560
# engine=30605
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-08-31 10:33:44
# local_time=2016-09-01 12:33:44 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode=freeze
# scanned=202069
# found=23
# cleaned=0
# scan_time=2732
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\xbtmeeehrceiqdhbatvuxrdgcnyleode.back"
sh=2483A3CFD78B8430725D6428EA1D93B4213CE02A ft=1 fh=de3a60083678fff8 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\RescueMonitor.exe"
sh=319775C62B595BFAB5AF994180F144881524E110 ft=1 fh=e3ab7ddb7e055b12 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\aiyblstijdmhlyepqimjhlhjhgfkuhxd\SystemHealer.exe"
sh=352D94006557FFE56D0B3D4A3D53A33E1EDAA13B ft=1 fh=9c2deb251acdf724 vn="Variante von Win32/Systweak.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\bwfojvdjqgzukyjanilqdjbghocnlrre\winzipdu.exe"
sh=523DED566E785E6CE03F9A0F1E9387CE22220A7C ft=1 fh=c71c0011c52e71be vn="Variante von Win32/Adware.CloudGuard.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\ddnuuhidyqaezutghzytdnhbekpaizuq\ConsoleApplication1.dll"
sh=1F8B6EB234CEFA2929576F6BF03006071371B866 ft=1 fh=7453b3f73a41e764 vn="Win32/InstallCore.ACZ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\dlskainzuvztxqsemqngxasxkdumjbpf\Ravensburger tiptoi Packages\uninstaller.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\fakuntggvakyzaphldxxububpcslbwrf\19b689b7-7481-0.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\kzwdqvqwzmbkyrxfnxihrlrkjcbwhrul\19b689b7-0815-1.d"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\isa.dll"
sh=13E74D6DA81122396FF0AEA4526D0F97792FEEB2 ft=1 fh=252fcb3fe8fcc619 vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\wbsvc.exe"
sh=63A30441B5CAA16E8FE841EFC9BD7776D04E48A0 ft=1 fh=723e89e62feaf1e4 vn="Variante von Win32/WebBar.D evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa.dll"
sh=1B0FAFADB96A3204ADE84E0CA75B08A3D1F6227C ft=1 fh=17a875c148afbb71 vn="Variante von Win64/WebBar.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\isa_x64.dll"
sh=64BF3D74D378137DCFD029C0B9E68ABD5771601F ft=1 fh=b19376104f5cd5ec vn="Variante von MSIL/WebBar.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\nzeywelgpfrsutuwszaepkrmdjglqfzl\2.0.5897.26129\wb.exe"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\okrqyhbhvayzsbcbjhaafmevkmavhryf\19b689b7-6815-1.d"
sh=165C427651F37C512A42C94B544FE61005E331EF ft=1 fh=c71c00113333a183 vn="Variante von Win32/Adware.Adposhel.E Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\uemkwzlvdknrcsbaqhbuyudkumcsrqoe\19b689b7-51c5-0.d"
sh=88C3275D35429BF52CFA571CDEF2EDF77475BC72 ft=1 fh=89941ec6341689f3 vn="Variante von Win32/OptimizerEliteMax.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\OneSystemCare.exe"
sh=79C5273491CE942B3A83F3DA30DE626DD889D8F6 ft=1 fh=84dce0a161783d9a vn="Variante von Win32/Adware.SpeedingUpMyPC.AR Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemCash.exe"
sh=AD4361F47171799A5628A31F98C4BAABD344A16C ft=1 fh=43269c3001716996 vn="Variante von Win32/Adware.Adposhel.B Anwendung" ac=I fn="C:\AdwCleaner\quarantine\files\yqdlpbtixostmqwdgbtnczhayvkimlcy\SystemConsole.exe"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\387834b3c358f300c01dcd3ccb2cf86b\2370bcddcd14e1925cb970e83536de2c.exe.patcher"
sh=D6573FEFE075DD75D5BBADDC95F2AB249181C7F0 ft=1 fh=4739b9d3e2734b96 vn="Variante von Win64/Wajam.D evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\2370bcddcd14e1925cb970e83536de2c.exe"
sh=3F1ACAD7FD0A63C353E55CA3B1C7C0C1FE87768B ft=1 fh=e325d99799c60866 vn="Variante von Win32/Wajam.AH evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\3b67fbd47fcce720631001f76c855698.exe"
sh=38CBF1010D8665FD18862981E70138EFD4D95D41 ft=1 fh=e26803a63e301762 vn="Variante von Win64/Wajam.E evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\c9ce7465f7fbe4dc60fd0ce498ac1253.sys"
sh=C45D975AA9D6ADFA3DDE7B4474E82DFB5DF5EB0C ft=1 fh=026d01d7e6a9c806 vn="Variante von Win32/Wajam.AN evtl. unerwünschte Anwendung" ac=I fn="C:\FRST\Quarantine\C\Program Files\a142944bde42b743d8dfdbbe69da33b9\c6dee1fcda18f91b4a144256241d1ee3\dggenk.dll" Security Check Code:
Results of screen317's Security Check version 1.009
x64 (UAC is enabled)
Internet Explorer 11 ``````````````Antivirus/Firewall Check:``````````````
Windows Defender
McAfee Anti-Virus und Anti-Spyware
WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:`````````
Mozilla Firefox (48.0.2) ````````Process Check: objlist.exe by Laurent````````
Windows Defender MSMpEng.exe
mcafee VIRUSS~1 mcvsshld.exe
Windows Defender MpCmdRun.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |