Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7: Webseiten werden auf Werbung umgeleitet.

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 13.01.2015, 07:49   #5
jaydee81
 
Windows 7: Webseiten werden auf Werbung umgeleitet. - Standard

Windows 7: Webseiten werden auf Werbung umgeleitet.



Ok sorry, hier als TXT.

Log 1
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Scan Date: 12.01.2015
Scan Time: 19:17:00
Logfile: Mal Log 1.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.12.07
Rootkit Database: v2015.01.07.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: JDR

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 312948
Time Elapsed: 8 min, 34 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 5
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1584, Delete-on-Reboot, [830426d0286149ed628b497ac1401ae6]
PUP.Optional.VeriStaff, C:\Program Files (x86)\LPT\srptsl.exe, 1372, Delete-on-Reboot, [fa8d44b2dfaa2511126a0b528779a45c]
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\Service\wpsvc.exe, 2332, Delete-on-Reboot, [a6e1c531ff8aca6c6949eef2a06142be]
PUP.Optional.Linkury.A, C:\Program Files (x86)\LPT\srpts.exe, 1928, Delete-on-Reboot, [fe898d6994f5b28440906148ee15a759]
PUP.Optional.Score.A, C:\Windows\rcore.exe, 2196, Delete-on-Reboot, [8502fcfa5a2f3ff7d455d6165ba9b64a]

Modules: 0
(No malicious items detected)

Registry Keys: 51
PUP.Optional.WindowsProtectManger.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, Quarantined, [830426d0286149ed628b497ac1401ae6], 
PUP.Optional.WordProser.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wpsvc_1.10.0.6, Quarantined, [a6e1c531ff8aca6c6949eef2a06142be], 
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, Quarantined, [90f7d1256f1a72c4d1d773789d653bc5], 
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, Quarantined, [90f7d1256f1a72c4d1d773789d653bc5], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Quarantined, [8dfad71fa4e5fb3b8f84edfe0bf78080], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, Quarantined, [8dfad71fa4e5fb3b8f84edfe0bf78080], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, Quarantined, [8dfad71fa4e5fb3b8f84edfe0bf78080], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, Quarantined, [8dfad71fa4e5fb3b8f84edfe0bf78080], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, Quarantined, [8dfad71fa4e5fb3b8f84edfe0bf78080], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Quarantined, [8dfad71fa4e5fb3b8f84edfe0bf78080], 
PUP.Optional.Snapdo.T, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [afd80aecef9a9f978202d350b84b4db3], 
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, Quarantined, [afd80aecef9a9f978202d350b84b4db3], 
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, Quarantined, [a9de6f8746433cfade5f27c09e645ba5], 
PUP.Optional.DefaultSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2498}, Quarantined, [a9de6f8746433cfade5f27c09e645ba5], 
PUP.Optional.WordProser.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\wpnfd_1_10_0_6, Quarantined, [f88fde18f09935011154b1c505fec63a], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{886f5d30-5b8b-42ab-98f8-31d062b96dc3}Gw64, Quarantined, [d8af9b5b0d7cdd59fc572264a65dbf41], 
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{a6994947-8316-401e-82e4-23da215413fb}Gw64, Quarantined, [731411e5414841f52231e1a5bb4846ba], 
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Quarantined, [5f287a7ccfbab77f53d1468b6a9acb35], 
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, Quarantined, [61264da9cbbe1521643c816873912bd5], 
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, Quarantined, [6e19c234ed9c3006c3dcd712808434cc], 
PUP.Optional.ClickCaption.A, HKLM\SOFTWARE\WOW6432NODE\ClickCaption_1.10.0.5, Quarantined, [3453f0069eeb9f974606dc97897aad53], 
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\Flowsurf, Quarantined, [6d1a6d892069f244a91ab03e1fe5bb45], 
PUP.Optional.IHProtect.A, HKLM\SOFTWARE\WOW6432NODE\IHProtect, Quarantined, [3d4a787e6f1a171f7242d7937291c13f], 
PUP.Optional.ISearch.A, HKLM\SOFTWARE\WOW6432NODE\omiga-plusSoftware, Quarantined, [5631e214e5a489ad95eca23bbe46e41c], 
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SmdmF, Quarantined, [f7904ea802875cda29e4c8ba8a7935cb], 
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, Quarantined, [e2a5f9fd44450135fe7b6d780004a957], 
PUP.Optional.WordProser.A, HKLM\SOFTWARE\WOW6432NODE\WordProser_1.10.0.6, Quarantined, [d9ae985ee7a293a370f85125e91a14ec], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE, Quarantined, [1e6904f2e0a9f3434a4b4e3aae552fd1], 
PUP.Optional.Linkury.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}, Quarantined, [266133c3b9d049edb5070d89a95ad62a], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Quarantined, [790e619567223bfb5322c4244cb852ae], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Quarantined, [47404da9662373c30f6730b830d412ee], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, Quarantined, [4b3c09eddfaacd692633aad661a2a55b], 
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, Quarantined, [097e3bbbd9b04fe7dbd31674b54e48b8], 
PUP.Optional.ClickCaption.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ccnfd_1_10_0_5, Quarantined, [07807b7b256487af301a87ecd62d768a], 
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, Quarantined, [f295cf2774154cea1a694134cb3808f8], 
PUP.Optional.Linkury.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\LPTSYSTEMUPDATER, Quarantined, [fe898d6994f5b28440906148ee15a759], 
PUP.Optional.Score.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RCORES, Quarantined, [8502fcfa5a2f3ff7d455d6165ba9b64a], 
PUP.Optional.GeForce.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Ge-Force, Quarantined, [c0c7f204395062d425525690fb0922de], 
PUP.Optional.CrossRider.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQPro-Video 1.6V10.01, Quarantined, [93f4ed0953362511969e314331d28e72], 
PUP.Optional.MediaPlayerVideo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Media+PlayerVidEd2.5, Quarantined, [3156a353315863d39e3ed19d37ccd22e], 
PUP.Optional.StormWatchApp.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\StormWatchApp, Quarantined, [06819561018869cd3597304654af23dd], 
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TutoTag, Quarantined, [563103f33b4ea88eb9efaf39dd27a45c], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [ee9952a492f796a0ad14fbde48bc19e7], 
PUP.Optional.MultiIE.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, Quarantined, [6f188c6a1c6d42f42bb8fae8ea1a619f], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Quarantined, [bdcad125ed9c181e6c14cce3d42feb15], 
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Quarantined, [850234c2d1b8ae884650863fd72d6a96], 
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR, Quarantined, [f295c82ef396c96d027b6a1727dcc53b], 
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, Quarantined, [acdb0cea286140f67d304f3b4fb49967], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.WordProser.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WordProser_1.10.0.6, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 

Registry Values: 12
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, Quarantined, [305718de5732de5859a5aad4ce358c74]
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\WOW6432NODE\GLOBALUPDATE\UPDATE|path, C:\Program Files (x86)\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [1e6904f2e0a9f3434a4b4e3aae552fd1]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, Quarantined, [f4935e98fc8dd46252aceb93da29e41c]
PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_de_78, Quarantined, [13749c5a355401355be6bcb36f94c13f], 
PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_de_80, Quarantined, [97f09b5b117872c419288be428db2ed2], 
PUP.Optional.MBot.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mbot_de_406, Quarantined, [2a5db145b7d29c9a06b997ea48bb57a9], 
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, tugs, Quarantined, [4b3c09eddfaacd692633aad661a2a55b]
PUP.Optional.Linkury.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\LPTSYSTEMUPDATER|ImagePath, "C:\Program Files (x86)\LPT\srpts.exe", Quarantined, [fe898d6994f5b28440906148ee15a759]
PUP.Optional.Score.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RCORES|ImagePath, C:\Windows\rcore.exe, Quarantined, [8502fcfa5a2f3ff7d455d6165ba9b64a]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0Q1O1R1R0D1G1J1S, Quarantined, [850234c2d1b8ae884650863fd72d6a96]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [335412e41c6d8da9badc5a2ef0132ad6]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SMARTBAR|publisher, IrsSF, Quarantined, [f295c82ef396c96d027b6a1727dcc53b]

Registry Data: 12
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420919252&from=tugs&uid=STTXFTM64GX25H_P569318-btix-6269013, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420919252&from=tugs&uid=STTXFTM64GX25H_P569318-btix-6269013),Replaced,[186fe90d276274c2878a0d861bea5da3]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[3651a1554c3dc37389b6622f21e4ec14]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420919252&from=tugs&uid=STTXFTM64GX25H_P569318-btix-6269013, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420919252&from=tugs&uid=STTXFTM64GX25H_P569318-btix-6269013),Replaced,[3651bc3abdcc4ceaa170543f57ae946c]
PUP.Optional.SafeFinder.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyahHISZMPSu3Vv0UGtPsXvs&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyahHISZMPSu3Vv0UGtPsXvs&q={searchTerms}),Replaced,[236427cf4445be784ce15630689d5fa1]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}),Replaced,[90f7cd290386112531f5295d56afb54b]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCSH6gc8-7TDgQXhxYEloZ5bmvGguuDX11bYCBT6-B25m6HH_IaaV5Io90RgwFx3BGxOSudEc9ytaPWkOnpeyBlN, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCSH6gc8-7TDgQXhxYEloZ5bmvGguuDX11bYCBT6-B25m6HH_IaaV5Io90RgwFx3BGxOSudEc9ytaPWkOnpeyBlN),Replaced,[0582a84eacddbb7bc55e582ebc4959a7]
PUP.Optional.OmigaPlus.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420919252&from=tugs&uid=STTXFTM64GX25H_P569318-btix-6269013, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/?type=hppp&ts=1420919252&from=tugs&uid=STTXFTM64GX25H_P569318-btix-6269013),Replaced,[f1964da98dfc4beb4ebb088bda2b26da]
PUP.Optional.OmigaPlus.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1420919252&from=tugs&uid=STTXFTM64GX25H_P569318-btix-6269013&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://isearch.omiga-plus.com/web/?type=dspp&ts=1420919252&from=tugs&uid=STTXFTM64GX25H_P569318-btix-6269013&q={searchTerms}),Replaced,[3d4ab4427a0fea4c8e85dca937ced52b]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}),Replaced,[9becaf475d2c90a6fa2ed7af27de32ce]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}),Replaced,[32552dc92e5bfc3a63c88afc8a7be21e]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}),Replaced,[5b2c70864d3c072f121aa9dd3ec7a858]
PUP.Optional.SafeFinder.A, HKU\S-1-5-21-2100642859-3274675363-52059511-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://feed.safefinder.com/?p=mKO_AwFzXIpYRak5VLd2-qQdkN5729vVFWxou9hoxUv82Ac0l78Z5A1nEmRSUhC4s2s4BBwiY8BHHkfnEAObOW8yk0Z3BJq_5cISz9jLZd-YXBu8_Tn_YCg3JRvQR20wDIpiZi0wzjVR6OtkBVIwpqQBlG4XljOFU9V-rEFsp9CYEPWgLWIeHyG_-nL33GG0VUvBdRaAVUiq&q={searchTerms}),Replaced,[9deab6401d6c4ceaa787dbab6d983cc4]

Folders: 16
PUP.Optional.OpenCandy, C:\Users\JDR\AppData\Roaming\OpenCandy, Quarantined, [8502c630791091a50ce16cc71ee5f60a], 
PUP.Optional.OpenCandy, C:\Users\JDR\AppData\Roaming\OpenCandy\OpenCandy_F84DC9210CC144FDAC59644E772CE2C2, Quarantined, [8502c630791091a50ce16cc71ee5f60a], 
PUP.Optional.Extutil.A, C:\Users\JDR\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B, Quarantined, [c8bf06f0aedb88aebbe861ea0cf7e31d], 
PUP.Optional.Managera.A, C:\Users\JDR\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42, Quarantined, [d1b634c23f4a2115089c52f9986b43bd], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Delete-on-Reboot, [cdbab83e1a6f979f5063a1aace35a35d], 
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, Quarantined, [cdbab83e1a6f979f5063a1aace35a35d], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6, Delete-on-Reboot, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\3rd Party Licenses, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\Service, Delete-on-Reboot, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate, Quarantined, [abdc8e68f495e84ee72f7cedd33035cb], 
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update, Quarantined, [abdc8e68f495e84ee72f7cedd33035cb], 

Files: 111
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Delete-on-Reboot, [830426d0286149ed628b497ac1401ae6], 
PUP.Optional.VeriStaff, C:\Program Files (x86)\LPT\srptsl.exe, Delete-on-Reboot, [fa8d44b2dfaa2511126a0b528779a45c], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\Service\wpsvc.exe, Delete-on-Reboot, [a6e1c531ff8aca6c6949eef2a06142be], 
PUP.Optional.SupTab.A, C:\Program Files (x86)\XTab\SupTab.dll, Quarantined, [8dfad71fa4e5fb3b8f84edfe0bf78080], 
PUP.Optional.OutBrowse, C:\Users\JDR\AppData\Local\Temp\292195.exe.exe, Quarantined, [e4a3d323c0c9ba7c300d8b7c43bf5da3], 
PUP.Optional.OutBrowse, C:\Users\JDR\AppData\Local\Temp\312419.exe.exe, Quarantined, [9fe8c23495f457df61f8d33533cf41bf], 
PUP.Optional.OutBrowse, C:\Users\JDR\AppData\Local\Temp\350425.exe.exe, Quarantined, [12753fb75930f046e376b94fb15134cc], 
PUP.Optional.OutBrowse, C:\Users\JDR\AppData\Local\Temp\nsq73C9.tmp\utu.dll, Quarantined, [7b0caf473d4cd660c37aaa5d07fbd030], 
PUP.Optional.Tuto4PC.A, C:\Users\JDR\AppData\Local\Temp\81c83413-b1a5-42b2-9c78-cb8e7761d798\games desktop.exe, Quarantined, [c0c773838108171fed7cdf1c50b1936d], 
PUP.Optional.Tuto4PC.A, C:\Users\JDR\AppData\Local\Temp\is-3AVA1.tmp\package_speedup_installer_multilang.exe, Quarantined, [147319dda3e6f73f39b50be6a160b24e], 
PUP.Optional.Tuto4PC.A, C:\Users\JDR\AppData\Local\Temp\is-JI9OR.tmp\package_mybestofferstoday_installer_multilang.exe, Quarantined, [7a0db73f91f85fd7b7376a87d62b847c], 
PUP.Optional.Tuto4PC.A, C:\Users\JDR\AppData\Local\Temp\is-V0QH0.tmp\package_speedup_installer_multilang.exe, Quarantined, [4047f9fd1a6f2412e20cea07946d22de], 
PUP.Optional.Tuto4PC.A, C:\Users\JDR\AppData\Local\Temp\is-V6A5H.tmp\package_mybestofferstoday_installer_multilang.exe, Quarantined, [bec920d69bee67cf599523ce61a017e9], 
PUP.Optional.XTab.A, C:\Users\JDR\AppData\Local\Temp\~dlFCF4\~dljyb\tmp\STab_v4.0.exe, Quarantined, [2f581fd797f2e4527b8631d4659d13ed], 
PUP.Optional.WindowsProtectManger.A, C:\Users\JDR\AppData\Local\Temp\~dlFCF4\~dljyb\tmp\wpm_v20.0.0.1337.exe, Quarantined, [741355a191f8f046c12cf6cd8e7343bd], 
PUP.Optional.SpeedCheck.A, C:\Users\JDR\AppData\Local\Temp\cd06f77b-2e4b-407a-9f5a-bf4099dbff09\3333-2081_speedcheck.exe, Quarantined, [b6d152a4becb4fe75c42baabb050eb15], 
PUP.Optional.SoftPulse, C:\Users\JDR\Downloads\ChromeSetup.exe, Quarantined, [a1e61bdbd6b36ccabb4f0efa659db34d], 
PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\AppPatch64\VCLdr64.dll, Quarantined, [5a2d8b6be0a9c76ff16c04aa04fde11f], 
PUP.Optional.VeriStaff, C:\Windows\Installer\6702f.msi, Quarantined, [ec9b37bf216854e2502f5d00f709827e], 
PUP.Optional.SmartBar, C:\Windows\Installer\MSICC0B.tmp-\Smartbar.Installer.CustomActions.dll, Quarantined, [3c4bc72fb7d222141e6553db8080c937], 
PUP.Optional.SmartBar, C:\Windows\Installer\MSIEB2.tmp-\Smartbar.Installer.CustomActions.dll, Quarantined, [8ef917dfaadf1521f88b49e5e11f33cd], 
PUP.Optional.SmartBar, C:\Windows\Installer\MSI69A0.tmp-\Smartbar.Installer.CustomActions.dll, Quarantined, [325510e672176cca196ab07e0ff11be5], 
PUP.Optional.WebInstr.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNHK_01009.Wdf, Quarantined, [54339a5c2d5cf046c73fea801fe4f709], 
PUP.Optional.Flowsurf.A, C:\Windows\System32\abengineOff.ini, Quarantined, [60271dd9e3a61e18fed8d99237cce31d], 
PUP.Optional.Flowsurf.A, C:\Windows\SysWOW64\abengineOff.ini, Quarantined, [9ceb29cd76139c9af0e6610aef1413ed], 
PUP.Optional.Flowsurf.A, C:\Windows\SysWOW64\abengine.ini, Quarantined, [e99efbfb98f169cd9b3cdd8e6c97a060], 
PUP.Optional.Flowsurf.A, C:\Windows\Temp\abengine.log, Quarantined, [83044aacfe8b999ddffd9ecdbc470af6], 
PUP.Optional.BoostSaves.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage, Delete-on-Reboot, [fb8c80763b4e3afc0622125c35ceaf51], 
PUP.Optional.BoostSaves.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal, Delete-on-Reboot, [ddaa7b7bf495ce68cc5c6509bf4413ed], 
PUP.Optional.WordProser.A, C:\Windows\System32\drivers\wpnfd_1_10_0_6.sys, Quarantined, [f88fde18f09935011154b1c505fec63a], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{886f5d30-5b8b-42ab-98f8-31d062b96dc3}Gw64.sys, Quarantined, [d8af9b5b0d7cdd59fc572264a65dbf41], 
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{a6994947-8316-401e-82e4-23da215413fb}Gw64.sys, Quarantined, [731411e5414841f52231e1a5bb4846ba], 
PUP.Optional.Boost.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage, Delete-on-Reboot, [4e3941b5fb8e3402cd9fa2e6a95a11ef], 
PUP.Optional.Boost.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal, Quarantined, [4047d5214c3d16204824097f07fcf10f], 
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, Quarantined, [dbac20d601887bbba8fb44a592726997], 
PUP.Optional.ReMarkable.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, Delete-on-Reboot, [8502b83ecabfe84ef6939555fc08916f], 
PUP.Optional.ReMarkable.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, Delete-on-Reboot, [bfc85a9c45441c1a3f4a04e60202b64a], 
PUP.Optional.Vitruvian.A, C:\Users\JDR\AppData\Local\Temp\vitruvian-installer-hardwareprofile-v0001, Quarantined, [384fa74f860383b35f79c42a09fb12ee], 
PUP.Optional.Vitruvian.A, C:\Users\JDR\AppData\Local\Temp\vitruvian-installer-install-v0003, Quarantined, [6720ad49e5a4df5709cf549a71932ed2], 
PUP.Optional.Vitruvian.A, C:\Users\JDR\AppData\Local\Temp\vitruvian-installer-processes-v0002, Quarantined, [6720c1355c2d58de0fc9b03e0ff5d22e], 
PUP.Optional.Vitruvian.A, C:\Users\JDR\AppData\Local\Temp\vitruvian-installer-scheduledtasks-v0001, Quarantined, [830419dde2a72511a533eb0373917f81], 
PUP.Optional.Vitruvian.A, C:\Users\JDR\AppData\Local\Temp\vitruvian-installer-softwareregkeys-v0002, Quarantined, [a1e646b07910999d6474d11ddc28ef11], 
PUP.Optional.Vitruvian.A, C:\Users\JDR\AppData\Local\Temp\vitruvian-installer-uninstall-v0002, Quarantined, [e0a7787e2a5f4fe7597f3eb0eb19659b], 
PUP.Optional.Linkury.A, C:\Program Files (x86)\LPT\srpts.exe, Delete-on-Reboot, [fe898d6994f5b28440906148ee15a759], 
PUP.Optional.Score.A, C:\Windows\rcore.exe, Delete-on-Reboot, [8502fcfa5a2f3ff7d455d6165ba9b64a], 
PUP.Optional.OpenCandy, C:\Users\JDR\AppData\Roaming\OpenCandy\OpenCandy_F84DC9210CC144FDAC59644E772CE2C2\syesubc3_p2v3.exe, Quarantined, [8502c630791091a50ce16cc71ee5f60a], 
PUP.Optional.Extutil.A, C:\Users\JDR\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\bk.js, Quarantined, [c8bf06f0aedb88aebbe861ea0cf7e31d], 
PUP.Optional.Extutil.A, C:\Users\JDR\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\cs.js, Quarantined, [c8bf06f0aedb88aebbe861ea0cf7e31d], 
PUP.Optional.Extutil.A, C:\Users\JDR\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\manifest.json, Quarantined, [c8bf06f0aedb88aebbe861ea0cf7e31d], 
PUP.Optional.Managera.A, C:\Users\JDR\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js, Quarantined, [d1b634c23f4a2115089c52f9986b43bd], 
PUP.Optional.Managera.A, C:\Users\JDR\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json, Quarantined, [d1b634c23f4a2115089c52f9986b43bd], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\GoogleCrashHandler.exe, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\GoogleUpdate.exe, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\GoogleUpdateBroker.exe, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\GoogleUpdateHelper.msi, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\GoogleUpdateOnDemand.exe, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\goopdate.dll, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\goopdateres_en.dll, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\npGoogleUpdate4.dll, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\psmachine.dll, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.127565\psuser.dll, Quarantined, [bdca85715c2d78bee9b8ff4ec63d7987], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\GoogleCrashHandler.exe, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\GoogleUpdate.exe, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\GoogleUpdateBroker.exe, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\GoogleUpdateHelper.msi, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\GoogleUpdateOnDemand.exe, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\goopdate.dll, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\goopdateres_en.dll, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\npGoogleUpdate4.dll, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\psmachine.dll, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.145177\psuser.dll, Quarantined, [4a3da84e88011c1a425f222bf50e7b85], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\GoogleCrashHandler.exe, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\GoogleUpdate.exe, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\GoogleUpdateBroker.exe, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\GoogleUpdateHelper.msi, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\GoogleUpdateOnDemand.exe, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\goopdate.dll, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\goopdateres_en.dll, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\npGoogleUpdate4.dll, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\psmachine.dll, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.158125\psuser.dll, Quarantined, [2e59995dc9c088aee6bb64e940c3d927], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\GoogleCrashHandler.exe, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\GoogleUpdate.exe, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\GoogleUpdateBroker.exe, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\GoogleUpdateHelper.msi, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\GoogleUpdateOnDemand.exe, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\goopdate.dll, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\goopdateres_en.dll, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\npGoogleUpdate4.dll, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\psmachine.dll, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.406763\psuser.dll, Quarantined, [6423876fa7e263d39e03f25bcc372cd4], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\GoogleCrashHandler.exe, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\GoogleUpdate.exe, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\GoogleUpdateBroker.exe, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\GoogleUpdateHelper.msi, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\GoogleUpdateOnDemand.exe, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\goopdate.dll, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\goopdateres_en.dll, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\npGoogleUpdate4.dll, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\psmachine.dll, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.GlobalUpdate.A, C:\Users\JDR\AppData\Local\Temp\comh.459338\psuser.dll, Quarantined, [ccbb7a7cc8c1ff379809fd50db288d73], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\terms-of-service.rtf, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\Uninstall.exe, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\3rd Party Licenses\buildcrx-license.txt, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\3rd Party Licenses\Info-ZIP-license.txt, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\3rd Party Licenses\JSON-simple-license.txt, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\3rd Party Licenses\nsJSON-license.txt, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\3rd Party Licenses\Nustache-license.txt, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\3rd Party Licenses\TaskScheduler-license.txt, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.WordProser.A, D:\Program Files\WordProser_1.10.0.6\3rd Party Licenses\UAC-license.txt, Quarantined, [a2e5f402a2e7979f9bdded7216edac54], 
PUP.Optional.IHProtectUpDate.A, C:\ProgramData\IHProtectUpDate\update\conf, Quarantined, [abdc8e68f495e84ee72f7cedd33035cb], 

Physical Sectors: 0
(No malicious items detected)


(end)
         
Log 2
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Scan Date: 12.01.2015
Scan Time: 19:30:41
Logfile: Mal Log 2.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.12.07
Rootkit Database: v2015.01.07.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: JDR

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 311797
Time Elapsed: 7 min, 41 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 6
PUP.Optional.BoostSaves.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage, Delete-on-Reboot, [cdbaf00692f7e74f8f996d01c73c31cf], 
PUP.Optional.BoostSaves.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal, Delete-on-Reboot, [e1a651a593f63204fc2cdd91e51ec838], 
PUP.Optional.Boost.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage, Delete-on-Reboot, [5136ec0ad4b592a43b31e1a742c1639d], 
PUP.Optional.Boost.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal, Delete-on-Reboot, [563139bdb2d744f2610bb7d1e0235aa6], 
PUP.Optional.ReMarkable.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, Delete-on-Reboot, [31561dd934552a0c1a6f6585dc28e818], 
PUP.Optional.ReMarkable.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, Delete-on-Reboot, [295eb3432d5cca6c5633da105aaad62a], 

Physical Sectors: 0
(No malicious items detected)


(end)
         
Log 3
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Scan Date: 12.01.2015
Scan Time: 19:39:28
Logfile: Mal Log 3.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.01.12.07
Rootkit Database: v2015.01.07.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: JDR

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 312794
Time Elapsed: 8 min, 50 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 6
PUP.Optional.BoostSaves.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage, Delete-on-Reboot, [b1e7e70d4d3c24125fc9066821e23dc3], 
PUP.Optional.BoostSaves.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_static.boostsaves.com_0.localstorage-journal, Delete-on-Reboot, [2078e014eb9ea591eb3d2747cb3852ae], 
PUP.Optional.Boost.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage, Delete-on-Reboot, [adeb22d2177238feadbf751307fc1ce4], 
PUP.Optional.Boost.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.boostsaves.com_0.localstorage-journal, Delete-on-Reboot, [2e6a579d7a0f999df67630587e85d32d], 
PUP.Optional.ReMarkable.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, Delete-on-Reboot, [a0f81dd7abdeb086bacfe5059272cb35], 
PUP.Optional.ReMarkable.A, C:\Users\JDR\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, Delete-on-Reboot, [dfb98272c2c766d0711809e1a0648977], 

Physical Sectors: 0
(No malicious items detected)


(end)
         


 

Themen zu Windows 7: Webseiten werden auf Werbung umgeleitet.
.dll, adware, antivirus, auf werbung umgeleitet, bonjour, browser, cpu, defender, dllhost.exe, downloader, explorer, failed, firewall, flash player, google, homepage, mozilla, problem, registry, revo uninstaller, security, seiten, software, svchost.exe, system, teredo, tracker, webseiten werden auf werbung umgeleitet., werbung, windows, winlogon.exe, ytdownloader




Ähnliche Themen: Windows 7: Webseiten werden auf Werbung umgeleitet.


  1. Windows 7: Webseiten werden auf Werbung umgeleitet.
    Log-Analyse und Auswertung - 30.07.2015 (8)
  2. Windows 7: Webseiten werden auf Werbung umgeleitet.
    Log-Analyse und Auswertung - 08.05.2015 (16)
  3. Windows 7: Webseiten werden auf Werbung umgeleitet
    Log-Analyse und Auswertung - 24.04.2015 (31)
  4. Windows 7: Webseiten werden auf Werbung umgeleitet.
    Log-Analyse und Auswertung - 11.02.2015 (19)
  5. Windows 8.1: Webseiten werden auf Werbung umgeleitet
    Log-Analyse und Auswertung - 13.01.2015 (8)
  6. Windows 7: Webseiten werden auf Werbung umgeleitet.
    Log-Analyse und Auswertung - 10.01.2015 (10)
  7. Windows 7: Webseiten werden auf Werbung umgeleitet.
    Plagegeister aller Art und deren Bekämpfung - 25.11.2014 (9)
  8. Windows 7: Webseiten werden auf Werbung umgeleitet
    Log-Analyse und Auswertung - 11.09.2014 (13)
  9. Windows 8: Webseiten werden auf Werbung umgeleitet.
    Log-Analyse und Auswertung - 01.08.2014 (5)
  10. Windows 7: Internet Explorer startet automatisch Werbung/ Webseiten werden auf Werbung umgeleitet
    Log-Analyse und Auswertung - 27.07.2014 (7)
  11. Windows 7: Webseiten werden auf Werbung umgeleitet
    Log-Analyse und Auswertung - 19.05.2014 (15)
  12. Windows 7: Webseiten werden auf Werbung umgeleitet.
    Plagegeister aller Art und deren Bekämpfung - 26.04.2014 (4)
  13. Windows 7: Webseiten werden auf Werbung umgeleitet
    Plagegeister aller Art und deren Bekämpfung - 16.02.2014 (9)
  14. Windows 7: Webseiten werden auf Werbung umgeleitet
    Log-Analyse und Auswertung - 07.01.2014 (6)
  15. Windows 7: Webseiten werden auf Werbung umgeleitet.
    Log-Analyse und Auswertung - 30.11.2013 (12)
  16. Windows 7: Webseiten werden auf Werbung umgeleitet.
    Plagegeister aller Art und deren Bekämpfung - 12.09.2013 (3)
  17. Windows 8: Webseiten werden auf Werbung umgeleitet
    Log-Analyse und Auswertung - 24.08.2013 (5)

Zum Thema Windows 7: Webseiten werden auf Werbung umgeleitet. - Ok sorry, hier als TXT. Log 1 Code: Alles auswählen Aufklappen ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 12.01.2015 Scan Time: 19:17:00 Logfile: Mal Log 1.txt Administrator: Yes Version: 2.00.4.1028 Malware - Windows 7: Webseiten werden auf Werbung umgeleitet....
Archiv
Du betrachtest: Windows 7: Webseiten werden auf Werbung umgeleitet. auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.