![]() |
Viele Wörter sind blau unterstrichen und es poppen Werbefenster aller Art auf Guten Abend, Ich versuche seit Tagen dieses hartnäckigen Virus zu entfernen. Nun habe ich eine passende Beschreibung des Virus im Trojaner Board gefunden. " Viele Wörter sind blau unterstrichen und es poppen Werbefenster aller Art auf. Firefox und glaube auch Internet Explorer. " Ich habe schon versucht das Problem per Anleitung selber zu lösen,jedoch findet "FRST" die Fixlist.txt nicht. Über jegliche Hilfe wäre ich seeehr Dankbar :) Hier schonmal die Editor Logs FRST.txt FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-02-2015 --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- --- Addition.txtFRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-02-2015 Hier noch die mbam.txt Es ist die neuste, jedoch habe ich in den letzten Tagen mehrfache Suchdurchläufe gemacht, deshalb weiss ich nicht ob folgende Informationen ausreichen Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Suchlauf Datum: 14.02.2015 Suchlauf-Zeit: 22:42:27 Logdatei: mbam.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.02.14.05 Rootkit Datenbank: v2015.02.03.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 8.1 CPU: x64 Dateisystem: NTFS Benutzer: Maxim Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 336768 Verstrichene Zeit: 4 Min, 57 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 1 PUP.Optional.EDealPop.A, C:\Program Files (x86)\eDealPop\eDealPop.exe, 2868, Löschen bei Neustart, [b6a71e00b9d13006c80308975aa93bc5] Module: 1 PUP.Optional.eDealsPop.A, C:\Program Files (x86)\eDealPop\msvcr100.dll, Löschen bei Neustart, [f964001eb2d82511557b4d3cf90a2cd4], Registrierungsschlüssel: 1 PUP.Optional.eDealsPop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\eDeals_is1, In Quarantäne, [f964001eb2d82511557b4d3cf90a2cd4], Registrierungswerte: 1 PUP.Optional.EDealPop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|eDealPop, "C:\Program Files (x86)\eDealPop\eDealPop.exe", In Quarantäne, [b6a71e00b9d13006c80308975aa93bc5] Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 1 PUP.Optional.eDealsPop.A, C:\Program Files (x86)\eDealPop, Löschen bei Neustart, [f964001eb2d82511557b4d3cf90a2cd4], Dateien: 6 PUP.Optional.EDeals.A, C:\Windows\Temp\UptUpdater.exe, In Quarantäne, [93ca37e7e3a7e254d8f9b6a1916f22de], PUP.Optional.EDealPop.A, C:\Program Files (x86)\eDealPop\eDealPop.exe, Löschen bei Neustart, [b6a71e00b9d13006c80308975aa93bc5], PUP.Optional.eDealsPop.A, C:\Program Files (x86)\eDealPop\msvcp100.dll, In Quarantäne, [f964001eb2d82511557b4d3cf90a2cd4], PUP.Optional.eDealsPop.A, C:\Program Files (x86)\eDealPop\msvcr100.dll, Löschen bei Neustart, [f964001eb2d82511557b4d3cf90a2cd4], PUP.Optional.eDealsPop.A, C:\Program Files (x86)\eDealPop\unins000.dat, In Quarantäne, [f964001eb2d82511557b4d3cf90a2cd4], PUP.Optional.eDealsPop.A, C:\Program Files (x86)\eDealPop\unins000.exe, In Quarantäne, [f964001eb2d82511557b4d3cf90a2cd4], Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) ADW CleanerAdwCleaner Logfile: Code: # AdwCleaner v4.110 - Bericht erstellt 14/02/2015 um 23:00:10 Junkware Renoval ToolJRT Logfile: Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
HI, in welchem Browser? |
Ich besitze nur Firefox und Explorer und in beiden ist der Virus vorhanden. |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-06] (Lenovo) Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-02-2015 Ran by Maxim at 2015-02-16 14:21:34 Run:1 Running from C:\Users\Maxim\Desktop Loaded Profiles: Maxim (Available profiles: Maxim) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM-x32\...\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-06] (Lenovo) HKLM-x32\...\Run: [eDealPop] => C:\Program Files (x86)\eDealPop\eDealPop.exe [6144 2014-12-03] () C:\Program Files (x86)\Lenovo\Yoga Picks C:\Program Files (x86)\eDealPop HKU\S-1-5-21-2168408397-1879668375-2819476295-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION ProxyEnable: [S-1-5-21-2168408397-1879668375-2819476295-1001] => Internet Explorer proxy is enabled. ProxyServer: [S-1-5-21-2168408397-1879668375-2819476295-1001] => http=127.0.0.1:11166 S2 cgimetafileMonitor.exe; C:\Users\Maxim\AppData\Local\cgimetafileMonitor\cgimetafileMonitor.exe [X] S2 iconcomdlgx86.exe; C:\Users\Maxim\AppData\Local\iconcomdlgx86\iconcomdlgx86.exe [X] S2 pythonvbicodecRec.exe; C:\Users\Maxim\AppData\Local\pythonvbicodecRec\pythonvbicodecRec.exe [X] S2 qeditkerberosBckp.exe; C:\Users\Maxim\AppData\Local\qeditkerberosBckp\qeditkerberosBckp.exe [X] S2 runtimeregidleDrv.exe; C:\Users\Maxim\AppData\Local\runtimeregidleDrv\runtimeregidleDrv.exe [X] S2 wdipsisrndr_64.exe; C:\Users\Maxim\AppData\Local\wdipsisrndr_64\wdipsisrndr_64.exe [X] S2 wpcumicomdlgProvider.exe; C:\Users\Maxim\AppData\Local\wpcumicomdlgProvider\wpcumicomdlgProvider.exe [X] C:\Users\Maxim\AppData\Local\cgimetafileMonitor C:\Users\Maxim\AppData\Local\iconcomdlgx86 C:\Users\Maxim\AppData\Local\pythonvbicodecRec C:\Users\Maxim\AppData\Local\qeditkerberosBckp C:\Users\Maxim\AppData\Local\runtimeregidleDrv C:\Users\Maxim\AppData\Local\wdipsisrndr_64 C:\Users\Maxim\AppData\Local\wpcumicomdlgProvider Emptytemp: ***************** HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\Yoga Picks => value deleted successfully. HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\eDealPop => value deleted successfully. "C:\Program Files (x86)\Lenovo\Yoga Picks" directory move: C:\Program Files (x86)\Lenovo\Yoga Picks\Icon.ico => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\LAPTOP_h.png => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Lenovo.YogaPicks.NotifyArea.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Lenovo.YogaPicks.ShortCut.exe => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\mfc110u.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\microsoft.windows.softwarelogo.shared.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Microsoft.WindowsAPICodePack.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Microsoft.WindowsAPICodePack.Shell.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\msvcr110.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\smallIcon.ico => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\STAND_h.png => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\TABLET_h.png => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\TENT_h.png => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Util.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe.config => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\YogaMode.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\YogaMode.lib => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\lvcomm.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\mfc110u.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\Microsoft.WindowsAPICodePack.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\Microsoft.WindowsAPICodePack.Shell.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\msvcr110.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\Util.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\YogaPicks.AppService.exe => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\YogaPicks.AppService.exe.config => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\YPServiceInstaller.bat => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x86\YPServiceUnInstaller.bat => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\lvcomm.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\mfc110u.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\Microsoft.WindowsAPICodePack.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\Microsoft.WindowsAPICodePack.Shell.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\msvcr110.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\Util.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe.config => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.InstallLog => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.InstallState => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YPServiceInstallerX64.bat => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YPServiceUnInstallerX64.bat => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\MetaFile\d291d26b-45a7-43d7-9b80-0c7dfc0d7c6a.devicemetadata-ms => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\ar-SA.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\cs.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\da.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\de.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\el.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\en.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\es.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\fi.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\fr.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\he-IL.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\hr.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\hu.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\it.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\ja.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\ko.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\nb.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\nl.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\nn.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\no.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\pl.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\pt-BR.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\pt-PT.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\ro.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\ru.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\sk.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\sl.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\sr-Latn.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\sv.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\tr.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\zh-CN.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\zh-HK.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Language\zh-TW.xml => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\d291d26b-45a7-43d7-9b80-0c7dfc0d7c6a.devicemetadata-ms => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.1\devcon.exe => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.1\install.cmd => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.1\uninstall.cmd => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.1\WUDFUpdate_01011.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.1\yogapicks.cat => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.1\YogaPicks.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.1\YogaPicks.inf => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.0\devcon.exe => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.0\install.cmd => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.0\uninstall.cmd => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.0\WUDFUpdate_01011.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.0\yogapicks.cat => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.0\YogaPicks.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x86\win8.0\YogaPicks.inf => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.1\devcon.exe => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.1\install.cmd => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.1\uninstall.cmd => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.1\WUDFUpdate_01011.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.1\yogapicks.cat => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.1\YogaPicks.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.1\YogaPicks.inf => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.0\devcon.exe => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.0\install.cmd => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.0\uninstall.cmd => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.0\WUDFUpdate_01011.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.0\yogapicks.cat => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.0\YogaPicks.dll => Moved successfully. C:\Program Files (x86)\Lenovo\Yoga Picks\Drivers\x64\win8.0\YogaPicks.inf => Moved successfully. Could not move "C:\Program Files (x86)\Lenovo\Yoga Picks" directory. => Scheduled to move on reboot. "C:\Program Files (x86)\eDealPop" directory move: C:\Program Files (x86)\eDealPop\eDealPop.exe => Moved successfully. C:\Program Files (x86)\eDealPop\msvcp100.dll => Moved successfully. C:\Program Files (x86)\eDealPop\msvcr100.dll => Moved successfully. C:\Program Files (x86)\eDealPop\unins000.dat => Moved successfully. C:\Program Files (x86)\eDealPop\unins000.exe => Moved successfully. Could not move "C:\Program Files (x86)\eDealPop" directory. => Scheduled to move on reboot. "HKU\S-1-5-21-2168408397-1879668375-2819476295-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. HKU\S-1-5-21-2168408397-1879668375-2819476295-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\S-1-5-21-2168408397-1879668375-2819476295-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. cgimetafileMonitor.exe => Service deleted successfully. iconcomdlgx86.exe => Service deleted successfully. pythonvbicodecRec.exe => Service deleted successfully. qeditkerberosBckp.exe => Service deleted successfully. runtimeregidleDrv.exe => Service deleted successfully. wdipsisrndr_64.exe => Service deleted successfully. wpcumicomdlgProvider.exe => Service deleted successfully. "C:\Users\Maxim\AppData\Local\cgimetafileMonitor" => File/Directory not found. "C:\Users\Maxim\AppData\Local\iconcomdlgx86" => File/Directory not found. "C:\Users\Maxim\AppData\Local\pythonvbicodecRec" => File/Directory not found. "C:\Users\Maxim\AppData\Local\qeditkerberosBckp" => File/Directory not found. "C:\Users\Maxim\AppData\Local\runtimeregidleDrv" => File/Directory not found. "C:\Users\Maxim\AppData\Local\wdipsisrndr_64" => File/Directory not found. "C:\Users\Maxim\AppData\Local\wpcumicomdlgProvider" => File/Directory not found. EmptyTemp: => Removed 415.4 MB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-02-16 14:22:59)<= C:\Program Files (x86)\Lenovo\Yoga Picks => Is moved successfully. C:\Program Files (x86)\eDealPop => Is moved successfully. ==== End of Fixlog 14:22:59 ==== Ich musste die Eset Log.txt manuell suchen, hoffe es ist die richtige Es wurden bei dem Suchlauf auf jeden Fall Funde endeckt ESETSmartInstaller@High as downloader log: all ok ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=3a761db4dbed6c43b092b01371f95575 # engine=22494 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-02-16 01:48:34 # local_time=2015-02-16 02:48:34 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.2.9200 NT # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 2241 14398833 0 0 # scanned=82565 # found=147 # cleaned=0 # scan_time=779 sh=8C2439E8D9A3BBE3A1790C01CD9E212AFF790035 ft=1 fh=c907a1331702b73d vn="a variant of Win32/Toolbar.BitCocktail.C potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bjvkh.dll.vir" sh=D11010E4EED9D0324F0E72B546D3AD80F1517B8E ft=1 fh=f12251822dd89e48 vn="a variant of Win64/Toolbar.Perion.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bjvkh64.dll.vir" sh=A5D0D9FB2D04555945246A51EC3A7E58D96E23D2 ft=1 fh=8f98caf3bbf8c057 vn="Win32/Toolbar.BitCocktail.C potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\blnj32.dll.vir" sh=58DC437A09A5F656052D295D548BF6825130B048 ft=1 fh=4db2d3ad4566f2f2 vn="Win64/Toolbar.Perion.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\blnj64.dll.vir" sh=F4C9980BF1CD209E6F6E6A32E9BAF7C309D68F96 ft=1 fh=430038d1149beb5a vn="a variant of Win32/Toolbar.Perion.J potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bntf.exe.vir" sh=7B7FEDE270EAE0E5B9719F9417A5D0D84A7F7EA4 ft=1 fh=64f6a8a64afa5750 vn="a variant of Win64/Toolbar.Perion.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bntf64.exe.vir" sh=5A15DB05E4581697B24B28883B0A234ADC04A587 ft=1 fh=198cff53a76f0f84 vn="a variant of Win32/Toolbar.Perion.J potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bop32.dll.vir" sh=B21106C75151F351C67169879DA0D46AB292CB62 ft=1 fh=0479ab0e0daa015d vn="a variant of Win64/Toolbar.Perion.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bop64.dll.vir" sh=D12EC3E24E166E3F360DA5B65A828D114F29AA1D ft=1 fh=fd4b015062f8b4ca vn="a variant of Win32/Toolbar.BitCocktail.C potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\brbsrv.exe.vir" sh=5A37606E544B59D411FA4E3C283DACFFBACAD582 ft=1 fh=0e6c10b7d4b47283 vn="a variant of Win32/Toolbar.BitCocktail.C potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\brgb.dll.vir" sh=72FF0A87BD5FB80F102AA73D6B935FB294DC5F77 ft=1 fh=4226fd59860a2aff vn="Win64/Toolbar.Perion.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\brgb64.dll.vir" sh=879A232C7553A5206B1AF01F170C018FF79A6D2D ft=1 fh=d0a16c35eb77a596 vn="Win32/VMDetect.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bvmn.exe.vir" sh=C62D763B9C2CEAAED8FA9B7188ADADA4A47D8F66 ft=1 fh=ee4670e681195ba3 vn="a variant of Win32/Toolbar.BitCocktail.C potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bwbk.dll.vir" sh=B598A7E97869C9E8A2A13AFDB53FCA522A33006F ft=1 fh=bc0504c92b3fc380 vn="a variant of Win32/Toolbar.Perion.K potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\bwbk64.dll.vir" sh=81701CBC8F1A816F7239704758F52BA4E0DC8BF8 ft=1 fh=6df414b049bce859 vn="a variant of Win32/Toolbar.BitCocktail.C potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\dfsrvex.exe.vir" sh=BCCDB5542E80159FD177031B2DAFA8AF58E4BD14 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Perion.K potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\Firefox\{970050F4-B21B-4c84-ACAB-DFEB867A4776}.xpi.vir" sh=7D53811BC59129DDD3FD21EEBB564F902D865C13 ft=0 fh=0000000000000000 vn="Win32/Toolbar.Perion.K potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files\shopperz\Firefox\chrome\content\main.js.vir" sh=0FADB783C6C38284E5819BCADED2A1C50503F7AF ft=1 fh=fcdd72b19b62f8d2 vn="Win32/AdWare.SmartApps.E application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Bench\BService\1.1\bhelper.dll.vir" sh=CCFCD73F208F834C854E46E6F31DB11AADA5CF08 ft=1 fh=6a366370a714a51b vn="Win32/AdWare.SmartApps.E application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Bench\BService\1.1\bservice.exe.vir" sh=1C5EF364255BBF5353713D0D1A66995AC3C7BCBC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\a23ef7dc-b8d4-4344-9aef-7bcd3148cba7.crx.vir" sh=76CD54A18AE02AA374C097E636F6ED551466AFCA ft=1 fh=f165f790444f3ef7 vn="a variant of Win32/Toolbar.CrossRider.BA potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\CinePlus-1.2V03.12-bg.exe.vir" sh=E25CE1FFB8ADB737267B29D95D5C8D0100A33C94 ft=1 fh=b61f051a4d67768f vn="a variant of Win32/Toolbar.CrossRider.BA potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\CinePlus-1.2V03.12-bho.dll.vir" sh=75611A641C8281A9BC683692234EA2E0B86B7705 ft=1 fh=1a5accfc68e6b555 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\CinePlus-1.2V03.12-bho64.dll.vir" sh=C0630690303964DE269C6552A7FF808238571103 ft=1 fh=f82e47e94d03b43f vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\CinePlus-1.2V03.12-codedownloader.exe.vir" sh=530C28E462B3C5B4B67E284A9C9709B6A55468FD ft=1 fh=b3ff689f1d85860d vn="a variant of Win32/Toolbar.CrossRider.BC potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\deb832e9-307b-4a81-b13c-218a494065c9.exe.vir" sh=EB4DA21705FD0CE27EDF662B2EE794F949DFBB06 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\e2f12637-69ca-4bcd-ae6b-30df6c9ca0ea.crx.vir" sh=4206B97236144FC82333B2465582AC7C0DBC5C5D ft=1 fh=c80ee3dde8066d3a vn="a variant of Win32/Toolbar.CrossRider.AS potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\f2ba4662-32db-4cd9-8c8f-917d50d71a41.exe.vir" sh=1035C124E6353318570FCC0B2289E93E9388142C ft=1 fh=6c0606b7fe1d405e vn="a variant of Win32/Toolbar.CrossRider.CB potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\face9c15-888c-48b5-a742-4909d58692f0-11.exe.vir" sh=1035C124E6353318570FCC0B2289E93E9388142C ft=1 fh=6c0606b7fe1d405e vn="a variant of Win32/Toolbar.CrossRider.CB potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\face9c15-888c-48b5-a742-4909d58692f0-3.exe.vir" sh=5178CC5FE30B47F295EBB9B03735922D8C6B4A14 ft=1 fh=20f7d48d21fffa1a vn="a variant of Win32/Toolbar.CrossRider.CB potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\face9c15-888c-48b5-a742-4909d58692f0-4.exe.vir" sh=AFF4647B017DDB70270E5AE57883D814CA926A36 ft=1 fh=ed1843adfc28a979 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\face9c15-888c-48b5-a742-4909d58692f0-5.exe.vir" sh=1C5EF364255BBF5353713D0D1A66995AC3C7BCBC ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\face9c15-888c-48b5-a742-4909d58692f0.crx.vir" sh=E8D7F3055BE015D07EDE7C3B44B5AAE8CEC3024C ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\face9c15-888c-48b5-a742-4909d58692f0.xpi.vir" sh=E35D1A382E339D97C2C7F9BCA40EBED96D080CFE ft=1 fh=d5ba07cefa0e911b vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\Interop.IWshRuntimeLibrary.dll.vir" sh=B17F30CC785B7B5267AF2E1A0F1CC14CE94A5B6E ft=1 fh=5e6ac6ea5620ad9d vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\Newtonsoft.Json.dll.vir" sh=914074CC24B4147D3D961CF346FBF5FB208E7D60 ft=1 fh=a4c5c2264bee6d48 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\SuperSocket.ClientEngine.Common.dll.vir" sh=175E4491EE0614094EE1353F7A8A742C7AC1F2DB ft=1 fh=332c76f956654375 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\SuperSocket.ClientEngine.Core.dll.vir" sh=6D5170AF59E9E9A41A13B62693157BAAA8C8CB41 ft=1 fh=3b113494bbebc0c7 vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\SuperSocket.ClientEngine.Protocol.dll.vir" sh=5A395AA801E2F692C8DC2B5C9654D7A65B0461C4 ft=1 fh=ddc61e410cf85c4d vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\Uninstall.exe.vir" sh=F3A8E36B6B2026B9BC428C7C9535F5BFC8183BDC ft=1 fh=a98264a67277c12b vn="Win32/Packed.VMDetector.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\utils.exe.vir" sh=3A9B8609D6FD8E7267FA540FF75CA74A20C193BD ft=1 fh=1ffd70f3c1a21f1c vn="a variant of Win32/Toolbar.CrossRider.BM potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinePlus-1.2V03.12\WebSocket4Net.dll.vir" sh=AA505B093673BE249A0A3AC33D5B8244DBDAEF23 ft=1 fh=7f170b0de0a938a0 vn="a variant of Win32/Adware.SoftwareRefresher.A application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Davenport\Intercepter\x86\1.3\intercepter.dll.vir" sh=7D99FBA462856BC4DD46A7B18E1D79D1C2BC0789 ft=1 fh=0c98b06ccc654f7d vn="a variant of Win32/Conduit.SearchProtect.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\cltmng.exe.vir" sh=01B1F9CB2D50A5609593744320463E46B91EEED4 ft=1 fh=769d3a4457a9efb0 vn="a variant of Win32/ClientConnect.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPTool64.exe.vir" sh=C91A0FA1B6D1087BFFF881365E2985A011B401C2 ft=1 fh=4fa76ddc1441696b vn="a variant of Win32/Conduit.SearchProtect.H potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32.dll.vir" sh=FA71B8789F7BB0D1FC4A4F6EB9E082D234DD4E8A ft=1 fh=5c4c6b425e2cebc2 vn="a variant of Win32/ClientConnect.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32Loader.dll.vir" sh=8FF3027FD5B24AF549A476472735F525E5A82E79 ft=1 fh=8958c815348aafc1 vn="a variant of Win32/ClientConnect.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC64.dll.vir" sh=621A43829E928D10CDA8CE4ECCF5C11E6BCFD5A8 ft=1 fh=1402f114ad354e9d vn="a variant of Win32/Conduit.SearchProtect.H potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LenovoBrowserGuard\Main\bin\CltMngSvc.exe.vir" sh=DDB78884545DF16760E10BFC482D1719DDCA5C90 ft=1 fh=3db9760f8b27cec5 vn="a variant of Win32/Conduit.SearchProtect.H potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LenovoBrowserGuard\Main\bin\SPTool.dll.vir" sh=E56595B052627D2E0F79BFEB1113B85CF5E373DB ft=1 fh=fd73c4a1721c52d6 vn="a variant of Win32/ClientConnect.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LenovoBrowserGuard\Main\bin\uninstall.exe.vir" sh=1B64473A9F6DC51107678E8649727FADE9D9B4F2 ft=1 fh=d771a5c9edd3de6b vn="a variant of Win32/Conduit.SearchProtect.Y potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LenovoBrowserGuard\UI\bin\cltmngui.exe.vir" sh=F676BCF3517B59DEE8E317E93A00CD74E18B186A ft=1 fh=459f9b9de46bfdf7 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\lrrot.dll.vir" sh=ED57FCF0E5CB3CF08429F8E13A929079F46CC3E6 ft=1 fh=c674b888749b41e5 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll.vir" sh=F669C332B2A8A976F4E2C1CDE50495D0257FEB53 ft=1 fh=0fd5d3ce8534e7e5 vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\smia.exe.vir" sh=A618AE4225D0D22004DD3A3FEDF8F87F8569BF8D ft=1 fh=c76a0a9a24bc64b5 vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\smia64.exe.vir" sh=FDAE1ABB987092C657356CBAE77151A6B7263878 ft=1 fh=ae9ece6f5652883f vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\sppsm.dll.vir" sh=237F01578E40FD1E6D95E0D4C97DBCA92827B58B ft=1 fh=17cb05aa2baad328 vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\spusm.dll.vir" sh=C30487F2387695F6C86DD380A75C4EBA7209316C ft=1 fh=88450590942ada21 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\srbs.dll.vir" sh=73352E3095535C799AE2799D14B45A6E9DFCAAC4 ft=1 fh=0e2cbb2d9f87df33 vn="a variant of MSIL/Toolbar.Linkury.F potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\srbu.dll.vir" sh=439BDFB9E3B0713B2588A9879299E76D5C7EA7D9 ft=1 fh=9a09a4157acaada5 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\srpt.dll.vir" sh=847CDB78BE32D1A20115F2B2C4C9FC0BEE407554 ft=1 fh=4e1353972007adfb vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\srptc.dll.vir" sh=1DB34B41763B34193632D97A95183E5B42C9D628 ft=1 fh=0d2f1079954527fb vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\srut.dll.vir" sh=F1CACFE1E4324879E14BEE5F2BE6B3E2F9872039 ft=1 fh=55edbda80ae3c26d vn="a variant of Win32/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\Resources\ntdis_32.dll.vir" sh=6EE13540DA0238F204AD735A84EC7E774E3FE3C2 ft=1 fh=1dcb219991998987 vn="a variant of Win64/Toolbar.Linkury.A.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\LPT\Resources\ntdis_64.dll.vir" sh=C07D98031E67DD7268505B4BE06691D763A2106E ft=1 fh=742ddfee9fbec440 vn="a variant of Win32/Conduit.SearchProtect.N potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ORBTR\orbiter.dll.vir" sh=781F9B92B453B90F3C04D98B5153DD5C6C26F589 ft=1 fh=135374a5b4967ccc vn="a variant of Win32/Conduit.SearchProtect.N potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ORBTR\uninstall.exe.vir" sh=AFB95723B245EB95106EC407D2443BE30426C079 ft=1 fh=045fdc84af3b3525 vn="a variant of Win32/Thinknice.F potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\BHOEnabler.exe.vir" sh=53F226B3D1D3828304E40C6C7A50667ADF23B42A ft=1 fh=e1ea10a5e9416a5c vn="Win32/Thinknice.E potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir" sh=0CB68F399D491465198E3E86F1D2923A211614E7 ft=1 fh=021f675753f993f2 vn="Win64/Thinknice.F potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface64.dll.vir" sh=86EA851108D635D9ED47C01E86899845DFDA3EC7 ft=1 fh=90733a3b10b3e858 vn="a variant of Win32/Thinknice.F potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\HpUI.exe.vir" sh=A8E3A9E6972C6F8B253EA0E1837AEEBF0A07B187 ft=1 fh=e2a5b168a3934371 vn="Win32/Thinknice.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir" sh=30E2FB1C671B2808D2E80518D793575965AF2416 ft=1 fh=d06e6f3f3f60e357 vn="a variant of Win32/Thinknice.E potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect32.dll.vir" sh=AC11914CC02E023E2EF06A80DEE1701419A5473A ft=1 fh=4cb2d0bd10147652 vn="Win64/Thinknice.F potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect64.dll.vir" sh=36F969E522FD53A189312D946C430EFD02D5A982 ft=1 fh=5d022c015afe1524 vn="a variant of Win32/ELEX.AV potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe.vir" sh=D037F58CF4B36F3B437FAA0D9500720445B27D65 ft=1 fh=b07c7921935b766c vn="Win32/Thinknice.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir" sh=4139F95644E13A650D4827C943BCC9F2F0F6AA93 ft=1 fh=3b96e1736604b8bc vn="Win32/Thinknice.E potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\uninstall.exe.vir" sh=79C9BD304C93AB8FD0544108656A899993DB14EF ft=1 fh=e6f80544d6e8089f vn="a variant of Win32/Thinknice.F potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\WindowsSupportDll32.dll.vir" sh=96B85214CD9E4FF85AC6144E7EF3DDF9E0F215E6 ft=1 fh=098a6735f96a550a vn="a variant of Win32/Thinknice.F potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\WindowsSupportDll64.dll.vir" sh=8767A98255ABA8AAD795522966A097F381111C4B ft=1 fh=c71c00111c9a800d vn="a variant of Win32/Adware.AddLyrics.CE application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver8SpeedChecker\181.dll.vir" sh=C7025C8F1C8CEFE3D46B0E8AE2F725B750BE06DE ft=1 fh=315191cba1c68c76 vn="a variant of Win64/Adware.AddLyrics.I application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver8SpeedChecker\181_x64.dll.vir" sh=4CF0A9B547F3091788473FE758D4E643A5731ED6 ft=1 fh=c71c001119b4527c vn="a variant of Win32/Adware.AddLyrics.CF application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver8SpeedChecker\B6SpeedCheckerd35.exe.vir" sh=262D6773FD95E5D10E2D1D2CBE3620DA99441945 ft=1 fh=83285b8172e395fc vn="a variant of Win32/Adware.AddLyrics.CG application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver8SpeedChecker\Uninstall.exe.vir" sh=CC1A5E195AE5DB046539D18C5048C4A2E285711A ft=1 fh=95d6957437a66324 vn="a variant of Win64/Adware.AddLyrics.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver8SpeedChecker\x64\TandemRunner.exe.vir" sh=6E5D0AB18B498E8EBC6BAB9C850F38D26CE427F9 ft=1 fh=8a80bf55b7b691e4 vn="Win64/Adware.AddLyrics.D application" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\ver8SpeedChecker\x64\webinstrNew.sys.vir" sh=CC7395FC0FE4D7F536FA2538FAD5A854FE7F360A ft=1 fh=6b5409c5ed5e1594 vn="a variant of Win32/Adware.PicColor.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\PicColor Utility\CMWFP.sys.vir" sh=249FE3168142E647F07D557616078FB119B4B888 ft=1 fh=7d872963e7673028 vn="a variant of Win32/Adware.PicColor.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\PicColor Utility\CMWFP64.sys.vir" sh=E1E435F92DBDCCDF087FF5EACD59967B69E44DA5 ft=1 fh=8ef5e37be386900b vn="a variant of Win32/Adware.PicColor.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\PicColor Utility\ColorMedia.exe.vir" sh=DF03905F5DB732477F667E214F737E536C208728 ft=1 fh=39f8ce88aad631c6 vn="a variant of Win32/Adware.PicColor.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\PicColor Utility\ColorMediaWFPInst.exe.vir" sh=559BA97B49DABCBE1535FAE94F212EF09D38B72A ft=1 fh=2e4a6a303cb12274 vn="a variant of Win32/Adware.PicColor.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\PicColor Utility\PicColor.exe.vir" sh=53D56362669EC3A7483148269A1059FD690A7033 ft=1 fh=c71c0011a6df79d7 vn="a variant of Win32/ELEX.BH potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir" sh=F676BCF3517B59DEE8E317E93A00CD74E18B186A ft=1 fh=459f9b9de46bfdf7 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\lrrot.dll.vir" sh=ED57FCF0E5CB3CF08429F8E13A929079F46CC3E6 ft=1 fh=c674b888749b41e5 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\Smartbar.Resources.HistoryAndStatsWrapper.dll.vir" sh=57F11D7D6BFF92E85AE2934FAA54AB68F7698D16 ft=1 fh=15eb380b82c951e9 vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\smia.exe.vir" sh=A618AE4225D0D22004DD3A3FEDF8F87F8569BF8D ft=1 fh=c76a0a9a24bc64b5 vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\smia64.exe.vir" sh=FDAE1ABB987092C657356CBAE77151A6B7263878 ft=1 fh=ae9ece6f5652883f vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\sppsm.dll.vir" sh=237F01578E40FD1E6D95E0D4C97DBCA92827B58B ft=1 fh=17cb05aa2baad328 vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\spusm.dll.vir" sh=C30487F2387695F6C86DD380A75C4EBA7209316C ft=1 fh=88450590942ada21 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\srbs.dll.vir" sh=73352E3095535C799AE2799D14B45A6E9DFCAAC4 ft=1 fh=0e2cbb2d9f87df33 vn="a variant of MSIL/Toolbar.Linkury.F potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\srbu.dll.vir" sh=439BDFB9E3B0713B2588A9879299E76D5C7EA7D9 ft=1 fh=9a09a4157acaada5 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\srpt.dll.vir" sh=847CDB78BE32D1A20115F2B2C4C9FC0BEE407554 ft=1 fh=4e1353972007adfb vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\srptc.dll.vir" sh=1DB34B41763B34193632D97A95183E5B42C9D628 ft=1 fh=0d2f1079954527fb vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\srut.dll.vir" sh=F1CACFE1E4324879E14BEE5F2BE6B3E2F9872039 ft=1 fh=55edbda80ae3c26d vn="a variant of Win32/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\Resources\ntdis_32.dll.vir" sh=6EE13540DA0238F204AD735A84EC7E774E3FE3C2 ft=1 fh=1dcb219991998987 vn="a variant of Win64/Toolbar.Linkury.A.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\LPT\Resources\ntdis_64.dll.vir" sh=CDBC46A4CB066D814F2C7C016D5DCB51CDCDB3F1 ft=1 fh=98fec1d5be7bac80 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\Lrcnta.exe.vir" sh=F676BCF3517B59DEE8E317E93A00CD74E18B186A ft=1 fh=459f9b9de46bfdf7 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\lrrot.dll.vir" sh=E938C7EC00746D250DDD3BB16C2CDCD37637FC15 ft=1 fh=8f640dc234059585 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll.vir" sh=4688ABD3D83BE51CB1C18CD1DF01CE87008BFD96 ft=1 fh=f5b2a45531e8558f vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll.vir" sh=806B2C68C39023603E72545B99803B450F15254B ft=1 fh=19659d4116c762de vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.ChromeLocalPlugin.dll.vir" sh=8C8FCCE63430BEBCA2C2FE12888E39B08F547968 ft=1 fh=0f817919bc031016 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.FireFoxLocalPlugin.dll.vir" sh=51855894EA1560FC5BEA97C48AAC2FE6DD8A8E45 ft=1 fh=2e9cd49756f2bd79 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll.vir" sh=ED57FCF0E5CB3CF08429F8E13A929079F46CC3E6 ft=1 fh=c674b888749b41e5 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll.vir" sh=239C502ADECA7F68D82B15A55D1432E5ECE4B54F ft=1 fh=ddb1f160ff412319 vn="a variant of MSIL/Toolbar.Linkury.E potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO.dll.vir" sh=239C502ADECA7F68D82B15A55D1432E5ECE4B54F ft=1 fh=ddb1f160ff412319 vn="a variant of MSIL/Toolbar.Linkury.E potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\SmartbarInternetExplorerBHO2.dll.vir" sh=DA67BE2893B4CC01A3074B9FA9F833814B69D155 ft=1 fh=88b0445aa40c5b9b vn="a variant of MSIL/Toolbar.Linkury.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension.dll.vir" sh=DA67BE2893B4CC01A3074B9FA9F833814B69D155 ft=1 fh=88b0445aa40c5b9b vn="a variant of MSIL/Toolbar.Linkury.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\SmartbarInternetExplorerExtension2.dll.vir" sh=A618AE4225D0D22004DD3A3FEDF8F87F8569BF8D ft=1 fh=c76a0a9a24bc64b5 vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\smia64.exe.vir" sh=AD6255AFD8E3AD941DCA402F50CACE839C855AB7 ft=1 fh=880bb8ce411e751d vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\smsp.dll.vir" sh=3347D58B7CB4C631D0A35D9CC1BBAC204A39C8FA ft=1 fh=872f9a0bf4fa4f6b vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\smta.dll.vir" sh=BB2D5AD1E4B96FE744BC7BFE76F664FFFE5C785D ft=1 fh=1c3f6ff53ec6c873 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\smtu.dll.vir" sh=2A6CD48011130D963C6F241ED9764F4397E3537E ft=1 fh=73a5a02ffe34c750 vn="a variant of MSIL/Toolbar.Linkury.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\SnapDo.exe.vir" sh=2E8AF508AE416EB4CB3540C38CA8BE6A061FDF08 ft=1 fh=44f09cae14c76f3b vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\spbe.dll.vir" sh=7C8170E08078B4DF3AD3453D202F9429236FB3F4 ft=1 fh=723453c6a2900a9e vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\spbl.dll.vir" sh=FDAE1ABB987092C657356CBAE77151A6B7263878 ft=1 fh=ae9ece6f5652883f vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\sppsm.dll.vir" sh=237F01578E40FD1E6D95E0D4C97DBCA92827B58B ft=1 fh=17cb05aa2baad328 vn="a variant of MSIL/Toolbar.Linkury.G potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\spusm.dll.vir" sh=4C78B788320B0F18E7A062CAA018E5A3EA5933FB ft=1 fh=281515b26b1cb28f vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\srau.dll.vir" sh=C30487F2387695F6C86DD380A75C4EBA7209316C ft=1 fh=88450590942ada21 vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\srbs.dll.vir" sh=73352E3095535C799AE2799D14B45A6E9DFCAAC4 ft=1 fh=0e2cbb2d9f87df33 vn="a variant of MSIL/Toolbar.Linkury.F potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\srbu.dll.vir" sh=BBC7B14957BD04EF7FB71AA3B21DD126E8168A0A ft=1 fh=e9035b320ea43e7e vn="a variant of MSIL/Toolbar.Linkury.I potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\srpu.dll.vir" sh=1DB34B41763B34193632D97A95183E5B42C9D628 ft=1 fh=0d2f1079954527fb vn="a variant of MSIL/Toolbar.Linkury.M.gen potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\srut.dll.vir" sh=806E1D82A6FE38385439EC3CE055E8B99C653B90 ft=1 fh=7ecd0e9f247e622e vn="Win32/Toolbar.Linkury.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\amfclgbdpgndipgoegfpkkgobahigbcl\GoogleChromeRemotePlugin.dll.vir" sh=C0E983273687F149F7465E56E499FC9CE8B45D8C ft=1 fh=96e13e572556f157 vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_28.dll.vi r" sh=98257D51FA765330DEFACEDC64135CE08DFBF088 ft=1 fh=ca51a056d7e710d8 vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_29.dll.vi r" sh=4B9F547AEF24928AF0BF1757F6482BCA3C84ECE7 ft=1 fh=d10067a3bdf76a69 vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_30.dll.vi r" sh=49637AC422CAF861A8174E8E8718C055FB1A9A61 ft=1 fh=08b7ce0d879c9f46 vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_31.dll.vi r" sh=CC1FCB7653CFD865A7EE501252C508C7344747A4 ft=1 fh=672eb3737de1717d vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_32.dll.vi r" sh=D7BD3417122951E13F95886C5F9736ADF7F16152 ft=1 fh=921735928170c030 vn="a variant of Win32/Toolbar.Linkury.D potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\SmartbarFireFoxRemotePlugin_33.dll.vi r" sh=091D4BA10BBB4E2CFB9457230813E32A43D1EE2A ft=1 fh=89b59d0d8749feeb vn="a variant of Win32/AdWare.SpeedingUpMyPC.N application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Local\Temp\OptimizerPro.exe.vir" sh=03517F89D3F20D2D4E2B1A956F8248C9DA9FFC18 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Roaming\Mozilla\Firefox\Profiles\dmlq24z8.default\Extensions\23fb8bb3-ac21-4230-bbfa-49b94968bc63@gmail.com\extensionData\plugins\91.js.vir" sh=A01CAE4A9C48BEB8A490C3E88CB03F9B95C31671 ft=1 fh=5c1219a5576ddaa1 vn="a variant of Win32/ClientConnect.A potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Maxim\AppData\Roaming\RHEng\463E7991F6464DAC84F98078BC9E58F4\sp-downloader.exe.vir" sh=249FE3168142E647F07D557616078FB119B4B888 ft=1 fh=7d872963e7673028 vn="a variant of Win32/Adware.PicColor.C application" ac=I fn="C:\AdwCleaner\Quarantine\C\WINDOWS\System32\drivers\CMWFP64.sys.vir" sh=6E5D0AB18B498E8EBC6BAB9C850F38D26CE427F9 ft=1 fh=8a80bf55b7b691e4 vn="Win64/Adware.AddLyrics.D application" ac=I fn="C:\AdwCleaner\Quarantine\C\WINDOWS\System32\drivers\webinstrNew.sys.vir" sh=83F0543DF9233DBE19DCA183E2738C9A1F1036C2 ft=1 fh=34e7354aef346a57 vn="a variant of Win64/Toolbar.Perion.B potentially unwanted application" ac=I fn="C:\AdwCleaner\Quarantine\C\WINDOWS\SysWOW64\lsdprn.exe.vir" sh=83608A35CC60E1AEA0A7424F37D74E3C0C68BA9D ft=1 fh=c71c0011d9b46d79 vn="a variant of Win32/Adware.Pirrit.R application" ac=I fn="C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\applicationsharewareUI.exe" sh=DDD7E789E67132CF6C5D8169B2F46E3498FCA60F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.C potentially unwanted application" ac=I fn="C:\Users\Maxim\AppData\Roaming\AZEKCUHV" sh=9413821E4285C46DAF48156B472065FC2D763FE8 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.C potentially unwanted application" ac=I fn="C:\Users\Maxim\AppData\Roaming\PPI" sh=7AFC4C94C9B89AFB2BC17BFFC4078076A55C4688 ft=1 fh=d4a2d80261445fc7 vn="a variant of Win32/DownloadGuide.D potentially unwanted application" ac=I fn="C:\Users\Maxim\Downloads\HitmanPro-32_64_CB-DL-Manager.exe" sh=DC2884CC1CED19603CCCAD873EB90C134E093325 ft=1 fh=ab7b4d1e33ebb2e1 vn="a variant of MSIL/Adware.Pirrit.A application" ac=I fn="C:\Windows\wauctla.exe" Hier noch der SecurityCheck Results of screen317's Security Check version 0.99.96 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java 64-bit 8 Update 31 Adobe Flash Player 16.0.0.305 Mozilla Firefox (35.0.1) ````````Process Check: objlist.exe by Laurent```````` Windows Defender MSMpEng.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` und die frische Frst.Log FRST Logfile: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-02-2015 --- --- --- --- --- --- Es scheint jetzt soweit alles wieder normal zu funktionieren, großartig :D Vielen lieben Dank |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte. |
Komisch, FRST findet die Fixlist.txt nicht, ich habe alles versucht. Sie ist auch in dem FRST Ordner. Leider scheint der Virus doch nicht entfernt zu sein, gestern war alles ok, doch heute morgen erschienen wieder Pop ups und blau makierte Schrift. Mein Fehler, habe die Fixlist.txt von dem Ornder auf den Deskop verschoben und es ging. Nachdem der Computer neu gestartet ist, hat mein Proxyserver die Verbindung mit Trojaner Board verweigert, musste dann erst auf "kein Proxy" den Haken setzten damit es wieder geht. Hier die Fixlog.txt Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-02-2015 Ran by Maxim at 2015-02-17 19:44:43 Run:1 Running from C:\Users\Maxim\Desktop Loaded Profiles: Maxim (Available profiles: Maxim) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery C:\Users\Maxim\AppData\Roaming\AZEKCUHV C:\Users\Maxim\AppData\Roaming\PPI C:\Windows\wauctla.exe ProxyEnable: [S-1-5-21-2168408397-1879668375-2819476295-1001] => Internet Explorer proxy is enabled. ProxyServer: [S-1-5-21-2168408397-1879668375-2819476295-1001] => http=127.0.0.1:11740 R2 filequartzx86; C:\WINDOWS\SysWOW64\filequartzx86\filequartzx86.exe [69120 2014-11-04] () [File not signed] C:\WINDOWS\SysWOW64\filequartzx86 S2 directxformatClient.exe; C:\Users\Maxim\AppData\Local\directxformatClient\directxformatClient.exe [X] C:\Users\Maxim\AppData\Local\directxformatClient R2 wauctla Service; C:\WINDOWS\wauctla.exe [188928 2015-02-06] () [File not signed] R2 softwarelocalsplRecovery.exe; C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\softwarelocalsplRecovery.exe [211968 2015-02-14] () [File not signed] C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery Emptytemp: ***************** "C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery" directory move: C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\applicationsharewareUI.exe => Moved successfully. C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\msvcp100.dll => Moved successfully. C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\msvcr100.dll => Moved successfully. C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\qjson0.dll => Moved successfully. C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\QtCore4.dll => Moved successfully. C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\QtNetwork4.dll => Moved successfully. C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\softwarelocalsplRecovery.exe => Moved successfully. C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery\SrDt.exe => Moved successfully. Could not move "C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery" directory. => Scheduled to move on reboot. C:\Users\Maxim\AppData\Roaming\AZEKCUHV => Moved successfully. C:\Users\Maxim\AppData\Roaming\PPI => Moved successfully. C:\Windows\wauctla.exe => Moved successfully. HKU\S-1-5-21-2168408397-1879668375-2819476295-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable => value deleted successfully. HKU\S-1-5-21-2168408397-1879668375-2819476295-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value deleted successfully. filequartzx86 => Unable to stop service filequartzx86 => Service deleted successfully. C:\WINDOWS\SysWOW64\filequartzx86 => Moved successfully. directxformatClient.exe => Service deleted successfully. "C:\Users\Maxim\AppData\Local\directxformatClient" => File/Directory not found. wauctla Service => Unable to stop service wauctla Service => Service deleted successfully. softwarelocalsplRecovery.exe => Unable to stop service softwarelocalsplRecovery.exe => Service deleted successfully. "C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery" directory move: Could not move "C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery" directory. => Scheduled to move on reboot. EmptyTemp: => Removed 445.4 MB temporary data. => Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2015-02-17 19:45:35)<= C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery => Is moved successfully. C:\Users\Maxim\AppData\Local\softwarelocalsplRecovery => Is moved successfully. ==== End of Fixlog 19:45:35 ==== |
Das frische FRST Log bitte noch :) |
Jap FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-02-2015 FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-02-2015 |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: Task: {1B5F6028-8A41-4875-AE79-8831EAE9F8BD} - System32\Tasks\PPI => C:\Users\Maxim\AppData\Roaming\PPI.exe <==== ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Frisches FRST log bitte. Noch Probleme? |
Nach dem letzten Fix funktioniert wieder alles ganz normal, soll ich trozdem nochmal eine Fix.log erstellen? Malwarebytes hat auch nichts mehr gefunden |
Nö, passt. Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 14:31 Uhr. |
Copyright ©2000-2025, Trojaner-Board