Haus meister | 03.01.2018 20:18 | Hallo Aneri,
vielen Dank für deine Hilfe!
Nachdem ich deine ersten Anweisungen durchgeführt hatte, habe ich noch deinen Hinweis zum Revo Uninstaller gelesen. Ich konnte aber in der Anwendung keinen Eintrag mit dem Namen PCKeeper gefunden. Weder unter dem Admin noch unter dem normalen Benutzer-Account.
Ich habe deinen Anweisungen alle unter dem Admin-Account durchgeführt (wegen der einfacheren Installation). Nachdem ich fertig war, keine Besserung unter dem Benutzer-Account. Unter verschiedenen Webseiten wie z.B. kicker.de wird weiterhin Werbung eingeblendet. Unter Spiegel.de ist das aber nicht passiert?!.
Wenn ich in Google eine Suche druchführe, werden die Suchergebnisse nach kurzer Zeit nach unten verschoben und irgendwelche anderen Links zu verschiedenen Themen und verschiedenen Zielen angezeigt. Ich habe das mit meinem eigenen Laptop verglichen, da sind beide Verhalten so nicht festzustellen. Also schließe ich dieses Verhalten durch die Webseite selbst aus.
Komisch ist für mich aber immer noch, dass das o.a. Verhalten nicht zu beobachten ist, wenn ich mit dem Admin-Account surfe. Weder das Einblenden der Werbung noch das Verhalten bei den Google-Suchergebnissen ist dort reproduzierbar.
Soll ich die einzelnen Schritte nochmals unter dem Benutzer-Account durchführen?
Nach meinem Verständnis müsste das aber doch eigentlich unerheblich sein, unter welchem Account ich die Bereinigungen durchführe?!
Hier nun die Logs:
AdwCleaner[Cx].txt: Code:
# AdwCleaner 7.0.6.0 - Logfile created on Wed Jan 03 17:32:48 2018
# Updated on 2017/21/12 by Malwarebytes
# Running on Windows 7 Home Premium (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support
***** [ Services ] *****
Deleted: PCKeeper2Service
Deleted: PCKeeperOcfService
Deleted: AccountService
Deleted: PCKAVService
Deleted: PCKeeper2Service
Deleted: PCKeeperOcfService
***** [ Folders ] *****
Deleted: C:\Program Files (x86)\VideoPlayer
Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Essentware
Deleted: C:\ProgramData\Essentware
Deleted: C:\ProgramData\Application Data\Essentware
Deleted: C:\Program Files\Essentware
Deleted: C:\Users\All Users\Essentware
Deleted: C:\Users\Lapp\AppData\Local\Essentware
Deleted: C:\Users\Paul\AppData\Local\Essentware
Deleted: C:\Program Files (x86)\VideoPlayer
***** [ Files ] *****
Deleted: C:\Users\Paul\Downloads\ReimageRepair.exe
Deleted: C:\Windows\SysNative\drivers\fileHiders.sys
Deleted: C:\Windows\SysNative\drivers\zeoscanner.sys
Deleted: C:\Windows\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Deleted: C:\Users\All Users\Desktop\PCKeeper.lnk
Deleted: C:\Users\Public\Desktop\PCKeeper.lnk
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
Deleted: PCKeeper-Aktualisierungsprogramm
***** [ Registry ] *****
Deleted: [Key] - HKLM\SOFTWARE\SPPDCOM
Deleted: [Key] - HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\Probit Software
Deleted: [Key] - HKCU\Software\Probit Software
Deleted: [Key] - HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\CLKAPP
Deleted: [Key] - HKCU\Software\CLKAPP
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E7E7B26A-88AA-48B0-A47C-173C062FD904}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E44BBEE3-3F83-4670-9E2E-EE0556442287}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10ECCE17-29B5-4880-A8F5-EAD298611484}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{990F7D4F-09EF-47DF-9ABE-BAF2DCCF5C4B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{CF6E1E3B-5B36-4A71-9105-DC75B4089D8C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{CF6E1E3B-5B36-4A71-9105-DC75B4089D8C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{0319DE47-F039-45DC-A213-DBB61C6AE509}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{0319DE47-F039-45DC-A213-DBB61C6AE509}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{074BFF31-CA38-43C4-8F25-79213AD708EF}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{074BFF31-CA38-43C4-8F25-79213AD708EF}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{0D838143-D511-4555-8B97-16C3CF5A780D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{0D838143-D511-4555-8B97-16C3CF5A780D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{16A94A89-66C4-4990-896C-5FC3E1557FFD}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{206E5E13-3B8F-4146-9C21-F18A63A9689B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{206E5E13-3B8F-4146-9C21-F18A63A9689B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{2B5E8E95-F503-4530-A340-53DE89F3358F}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{2B5E8E95-F503-4530-A340-53DE89F3358F}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{2F8F99FD-7C0E-4150-8DFD-13B1F4FBD916}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{33B2A2E0-18F6-45CB-8080-04320066A4A1}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{40B50C00-06BB-415F-8F4E-6DEF53957ABA}
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{40B50C00-06BB-415F-8F4E-6DEF53957ABA}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{503F82AB-1549-4B08-AF10-289CCCF3BE4B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{6AF595D6-D4A0-4ACA-ADD4-62034EE9FF3A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{6F09F687-2C4C-4A37-8D7A-2CB76D2B3F71}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{6F09F687-2C4C-4A37-8D7A-2CB76D2B3F71}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{723F0E89-F10C-4D28-A46C-934513EA963A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{7944171A-50CC-479E-A6FC-B1E25E665C25}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{7A2BA8C4-F382-4DD1-A6D2-A86C6D66C4F9}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{7A2BA8C4-F382-4DD1-A6D2-A86C6D66C4F9}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{80E9CB05-9C8B-4B85-8A66-D81092F5AF60}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{817BF5D8-380E-44F4-8E61-43E7ECF74B53}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{828FB706-5749-4255-862F-3D30FCF017E1}
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{828FB706-5749-4255-862F-3D30FCF017E1}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{8888A22B-3380-4C2B-950F-A5B6EC527A4B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{8888A22B-3380-4C2B-950F-A5B6EC527A4B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{9443C19D-B318-4EBD-8A7F-6A50D0472FB4}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{95CAD169-7912-410E-8C8A-7BA1729BD8F7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{B462C1CA-E368-4321-B0B1-0453E4AB6FDB}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{CCF68051-721D-40C7-812D-86ED0FDE7411}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{D8F2F7F9-F8F3-4562-9FDA-C1E2DAE60A30}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{D8F2F7F9-F8F3-4562-9FDA-C1E2DAE60A30}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{DEE0443A-95B1-41DF-B50A-409FDEA53644}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{F55EA208-E122-4B4E-8483-4404A1CC9569}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{F6649783-7559-4772-96C7-02D33BEACD8C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{F6649783-7559-4772-96C7-02D33BEACD8C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{D062B23B-F8EE-40EC-BF3F-7DB0E9FE1232}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{D3F79FC5-65FE-4650-8979-3BF0CCF02C1A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{05562BE7-0EFC-4BD2-BD8F-FAA363E68410}
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{05562BE7-0EFC-4BD2-BD8F-FAA363E68410}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{B52115B1-936F-4EEA-A363-A535FB1942B7}
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved|{B52115B1-936F-4EEA-A363-A535FB1942B7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{56AD7EEE-D6C0-410E-8A7B-811DEA764554}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{E8EB2F1F-661E-4A7F-8F9A-77DEB757A906}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{AF85DB83-06F2-4ECF-97CF-C46EDB06BE29}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2311DC2B5C57F724B860D95A705A2A6B
Deleted: [Key] - HKLM\SOFTWARE\Classes\Installer\Features\2311DC2B5C57F724B860D95A705A2A6B
Deleted: [Key] - HKLM\SOFTWARE\Classes\Installer\Products\2311DC2B5C57F724B860D95A705A2A6B
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\630675D588826C6418C7CC05C5C31E17
Deleted: [Key] - HKLM\SOFTWARE\Classes\Installer\Features\630675D588826C6418C7CC05C5C31E17
Deleted: [Key] - HKLM\SOFTWARE\Classes\Installer\Products\630675D588826C6418C7CC05C5C31E17
Deleted: [Value] - HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\Microsoft\Windows\CurrentVersion\Run|PCKeeper Antivirus
Deleted: [Value] - HKCU\Software\Microsoft\Windows\CurrentVersion\Run|PCKeeper Antivirus
Deleted: [Value] - HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\Microsoft\Windows\CurrentVersion\Run|PCKeeperLive
Deleted: [Value] - HKCU\Software\Microsoft\Windows\CurrentVersion\Run|PCKeeperLive
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\REI_AxControl.DLL
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{05660A04-00F1-3A04-AB3B-BC1074B84D67}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{37AC0F3B-749F-3B22-811B-5A019EED2E85}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{4392A6CC-7940-310E-8E16-799A8D93A438}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{66DF7821-ED6D-3534-893C-0E89E74B0F91}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{755CAFCC-F016-3B06-8F22-945EAA3AD10D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{76552F88-640C-314D-82B6-0D8A740907F7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{903F9872-E87F-3B74-83B0-DBE10073B29D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{9558EEB4-CDA6-3778-B53B-98076F0A1E90}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{B25AA9BA-FD52-3E5E-BFE3-9B106779DA6E}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{C852CF9F-37DC-35AC-926A-7E6CFFF7C501}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{C9777796-4378-3C90-B52D-7238FFFC2A5C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{DB1BC8B2-FDBF-30E7-BE1C-AFF9160059E6}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{F3D5729C-7DEB-3850-A026-D0E323ECFEF5}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{FEC70973-CB8B-351C-8047-CAE1274CE249}
Deleted: [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\chrome.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Deleted: [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\firefox.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Deleted: [Key] - HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\PCKeeperShell32
Deleted: [Key] - HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\PCKeeperShell32
Deleted: [Key] - HKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\PCKeeperShell32
Deleted: [Key] - HKLM\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\PCKeeperShell32
Deleted: [Key] - HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\PCKeeperShell32
Deleted: [Key] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\SPVC32LDR
Deleted: [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\LAYERS\SPVC32Ldr|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Deleted: [Key] - HKLM\SOFTWARE\Classes\Directory\Background\shellex\ContextMenuHandlers\PCKeeperShell64
Deleted: [Key] - HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\PCKeeperShell64
Deleted: [Key] - HKLM\SOFTWARE\Classes\Drive\shellex\ContextMenuHandlers\PCKeeperShell64
Deleted: [Key] - HKLM\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\PCKeeperShell64
Deleted: [Key] - HKLM\SOFTWARE\Classes\lnkfile\shellex\ContextMenuHandlers\PCKeeperShell64
Deleted: [Value] - HKLM\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\AppCompatFlags\Custom\chrome.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Deleted: [Value] - HKLM\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\AppCompatFlags\Custom\firefox.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Deleted: [Value] - HKLM\SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\AppCompatFlags\Custom\iexplore.exe|{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\Layers\SPVC32LDR
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{181480C8-90AC-3430-B39A-CD121E034A1A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Record\{8F54FA54-1DF8-3B20-890C-CDD95364BC95}
Deleted: [Value] - HKLM\SOFTWARE\CLASSES\UNKNOWN\SHELL\OPENAS\COMMAND|ADVANCED SYSTEM PROTECTOR.BAK
Deleted: [Value] - HKLM\SOFTWARE\CLASSES\UNKNOWN\SHELL\OPENDLG\COMMAND|ADVANCED SYSTEM PROTECTOR.BAK
Deleted: [Key] - HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
Deleted: [Key] - HKCU\Software\Local AppWizard-Generated Applications\Reimage - Windows Problem Relief.
Deleted: [Key] - HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Deleted: [Key] - HKU\.DEFAULT\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
Deleted: [Key] - HKU\S-1-5-18\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Deleted: [Key] - HKU\S-1-5-18\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\_CrossriderRegNamePlaceHolder_
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID|{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
Deleted: [Value] - HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\CUSTOM\explorer.xxx|{8A4D5A43-C64A-45AB-BDF4-804FE18CEAFD}.SDB
Deleted: [Key] - HKU\.DEFAULT\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Deleted: [Key] - HKU\S-1-5-18\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Deleted: [Key] - HKLM\SOFTWARE\Essentware
Deleted: [Key] - HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\Essentware
Deleted: [Key] - HKCU\Software\Essentware
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B2CD1132-75C5-427F-8B06-9DA507A5A2B6}
Deleted: [Key] - HKLM\SOFTWARE\CLASSES\APPID\PCKElevatedHost.exe
Deleted: [Key] - HKLM\SOFTWARE\CLASSES\APPID\PCKElevatedHost.exe
Deleted: [Key] - HKLM\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKeeperShell32
Deleted: [Key] - HKLM\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKeeperShell64
Deleted: [Value] - HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing|bProtectShowTabsWelcome
Deleted: [Key] - HKU\.DEFAULT\Software\AppDataLow\Software\SpeedChecker
Deleted: [Key] - HKU\S-1-5-18\Software\AppDataLow\Software\SpeedChecker
Deleted: [Key] - HKLM\SOFTWARE\REG\CLEAN\pro
Deleted: [Key] - HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\REG\CLEAN\pro
Deleted: [Key] - HKCU\Software\REG\CLEAN\pro
Deleted: [Key] - HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\CoinisRS
Deleted: [Key] - HKCU\Software\CoinisRS
Deleted: [Key] - HKLM\SOFTWARE\Reg\Clean
Deleted: [Key] - HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\Reg\Clean
Deleted: [Key] - HKCU\Software\Reg\Clean
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B0864033-83D7-404D-A19E-D19BF584504D}
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries deleted.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries deleted.
*************************
::Tracing keys deleted
::Winsock settings cleared
::Proxy settings cleared
::IE policies deleted
::Chrome policies deleted
::Additional Actions: 0
*************************
C:/AdwCleaner/AdwCleaner[S0].txt - [17587 B] - [2018/1/3 17:31:19]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ########## Fixlog.txt: Code:
Entfernungsergebnis von Farbar Recovery Scan Tool (x64) Version: 02.01.2018
durchgeführt von Lapp (03-01-2018 18:36:52) Run:1
Gestartet von C:\Users\Lapp\Desktop
Geladene Profile: Lapp (Verfügbare Profile: Lapp & Paul)
Start-Modus: Normal
==============================================
fixlist Inhalt:
*****************
HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Beschr�nkung <==== ACHTUNG
R2 AccountService; C:\Program Files\Essentware\Common\AccountService.exe [211136 2016-02-29] (Essentware) <==== ACHTUNG
R2 PCKeeper2Service; C:\Program Files\Essentware\PCKeeper\PCKeeperService.exe [216512 2016-11-11] (Essentware) <==== ACHTUNG
R2 PCKeeperOcfService; C:\Program Files\Essentware\PCKeeper\OneClickFixService.exe [1179840 2016-11-11] (Essentware) <==== ACHTUNG
U5 AppMgmt; C:\windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ACHTUNG
S3 fileHiders; C:\windows\System32\DRIVERS\fileHiders.sys [32352 2016-11-11] () <==== ACHTUNG
S3 cpuz134; \??\C:\Users\Lapp\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] <==== ACHTUNG
Task: {BFFFB3D3-4D9D-410E-9043-C78C0E84566C} - System32\Tasks\{DFEE10EA-24B7-49A2-A080-0C4F5AC8DE75} => C:\windows\system32\pcalua.exe -a C:\Users\Lapp\AppData\Roaming\omiga-plus\UninstallManager.exe -c -ptid=tugs <==== ACHTUNG
Task: {E789C4CC-F4C0-45DD-BF0A-4FF899BD0530} - System32\Tasks\PCKeeper-Aktualisierungsprogramm => C:\ProgramData\Essentware\installer.exe [2017-10-30] (Essentware) <==== ACHTUNG
emptytemp:
*****************
"HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => erfolgreich entfernt
AccountService => Dienst nicht gefunden.
PCKeeper2Service => Dienst nicht gefunden.
PCKeeperOcfService => Dienst nicht gefunden.
"HKLM\System\CurrentControlSet\Services\AppMgmt" => erfolgreich entfernt
AppMgmt => Dienst erfolgreich entfernt
"HKLM\System\CurrentControlSet\Services\fileHiders" => erfolgreich entfernt
fileHiders => Dienst erfolgreich entfernt
"HKLM\System\CurrentControlSet\Services\cpuz134" => erfolgreich entfernt
cpuz134 => Dienst erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BFFFB3D3-4D9D-410E-9043-C78C0E84566C} => konnte nicht entfernt werden Schlüssel. ErrorCode1: 0x00000002
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BFFFB3D3-4D9D-410E-9043-C78C0E84566C}" => erfolgreich entfernt
C:\windows\System32\Tasks\{DFEE10EA-24B7-49A2-A080-0C4F5AC8DE75} => erfolgreich verschoben
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{DFEE10EA-24B7-49A2-A080-0C4F5AC8DE75}" => erfolgreich entfernt
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E789C4CC-F4C0-45DD-BF0A-4FF899BD0530} => Schlüssel nicht gefunden
"C:\windows\System32\Tasks\PCKeeper-Aktualisierungsprogramm" => nicht gefunden
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PCKeeper-Aktualisierungsprogramm => Schlüssel nicht gefunden
=========== EmptyTemp: ==========
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 21263973 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 205572620 B
Edge => 0 B
Chrome => 3072 B
Firefox => 223029391 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 83492 B
systemprofile32 => 66228 B
LocalService => 0 B
NetworkService => 185190474 B
Lapp => 39660101 B
Paul => 464834638 B
RecycleBin => 26450759 B
EmptyTemp: => 1.1 GB temporäre Dateien entfernt.
================================
Das System musste neu gestartet werden.
==== Ende von Fixlog 18:39:08 ==== mbam.txt: Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 03.01.18
Scan-Zeit: 18:50
Protokolldatei: 85f6a384-f0ae-11e7-83a6-b870f4234108.json
Administrator: Ja
-Softwaredaten-
Version: 3.3.1.2183
Komponentenversion: 1.0.262
Version des Aktualisierungspakets: 1.0.3616
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Lapp-PC\Lapp
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 285392
Erkannte Bedrohungen: 75
In die Quarantäne verschobene Bedrohungen: 75
Abgelaufene Zeit: 13 Min., 8 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 35
PUP.Optional.SuperOptimizer, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, In Quarantäne, [2336], [243667],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{288A9C7F-AA4E-43FA-872D-26451032B08B}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29F3AF22-FFA4-4A4C-8979-847E2AA18280}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3CBD1E0B-468A-4E00-8D1B-BE52C0C0C5C5}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{413FF6A2-67F8-423D-991D-ACDA6EF4BC3F}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F4CCA1E-8A85-45A3-8826-D48E65DC34F8}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{54BD2C19-C717-4E7B-9638-B6D03257AC9C}, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{625F7AA1-9E79-4A05-A9EA-8A3D50CDCECF}, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6D811000-F4EE-4F5F-ADB5-355969BE277A}, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{75404FFE-700D-46C6-B1D3-DF25DE4B88F5}, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8EC0A48C-5D4E-40B3-ACE4-DBD316BD3C55}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{941814C3-E50C-45FC-A986-1C3B6E2B696D}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A09FD2DA-9F86-47E9-99DD-999D47376083}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7318058-4AFB-4C11-B0D2-8DC255C1A625}, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D841950E-4972-422F-86FF-847E1EE1B4ED}, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E711040E-DF8D-4E00-9538-8171E5D1A840}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.RegCleanPro, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\REG\Clean, In Quarantäne, [1398], [347493],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29F3AF22-FFA4-4A4C-8979-847E2AA18280}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B9CDC56-652A-4F70-B6A8-4B6F69917FB5}, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ACC60E82-F19D-431D-B920-37FE7562D5A1}, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB4923DE-8C85-4C14-84F1-34747A20FB72}, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKAVShell32, In Quarantäne, [811], [261775],1.0.3616
PUP.Optional.PCKeeper, HKLM\SOFTWARE\CLASSES\*\SHELLEX\CONTEXTMENUHANDLERS\PCKAVShell64, In Quarantäne, [811], [261775],1.0.3616
PUP.Optional.PCKeeper, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\Essentware, In Quarantäne, [811], [384779],1.0.3616
PUP.Optional.SysTweak, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\Systweak, In Quarantäne, [217], [327156],1.0.3616
PUP.Optional.PCKeeper, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\ESSENTWARE\PCKeeper, In Quarantäne, [811], [260410],1.0.3616
PUP.Optional.GlobalUpdate, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY, In Quarantäne, [742], [238772],1.0.3616
PUP.Optional.PCKeeper, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\f4e836bd_0, In Quarantäne, [811], [260411],1.0.3616
PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5A4A7D29-7589-427B-86BC-8C313278BF89}, In Quarantäne, [811], [260413],1.0.3616
PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{F7DA7463-F666-41B3-B16B-8968A43BA6D4}, In Quarantäne, [811], [260413],1.0.3616
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\REI_AxControl.ReiEngine.1, In Quarantäne, [1096], [327197],1.0.3616
PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\REI_AxControl.ReiEngine, In Quarantäne, [1096], [327197],1.0.3616
PUP.Optional.PCKeeper, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\f4e836bd_0, In Quarantäne, [811], [260411],1.0.3616
PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\TRACING\PCKeeper_RASAPI32, In Quarantäne, [811], [241577],1.0.3616
PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\TRACING\PCKeeper_RASMANCS, In Quarantäne, [811], [241577],1.0.3616
Registrierungswert: 27
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{288A9C7F-AA4E-43FA-872D-26451032B08B}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29F3AF22-FFA4-4A4C-8979-847E2AA18280}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{3CBD1E0B-468A-4E00-8D1B-BE52C0C0C5C5}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{413FF6A2-67F8-423D-991D-ACDA6EF4BC3F}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{4F4CCA1E-8A85-45A3-8826-D48E65DC34F8}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{54BD2C19-C717-4E7B-9638-B6D03257AC9C}|APPNAME, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{625F7AA1-9E79-4A05-A9EA-8A3D50CDCECF}|APPNAME, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6D811000-F4EE-4F5F-ADB5-355969BE277A}|APPNAME, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{75404FFE-700D-46C6-B1D3-DF25DE4B88F5}|APPNAME, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{8EC0A48C-5D4E-40B3-ACE4-DBD316BD3C55}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{941814C3-E50C-45FC-A986-1C3B6E2B696D}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{A09FD2DA-9F86-47E9-99DD-999D47376083}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{B7318058-4AFB-4C11-B0D2-8DC255C1A625}|APPNAME, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{D841950E-4972-422F-86FF-847E1EE1B4ED}|APPNAME, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E711040E-DF8D-4E00-9538-8171E5D1A840}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29F3AF22-FFA4-4A4C-8979-847E2AA18280}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{6B9CDC56-652A-4F70-B6A8-4B6F69917FB5}|APPNAME, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{ACC60E82-F19D-431D-B920-37FE7562D5A1}|APPNAME, In Quarantäne, [203], [237488],1.0.3616
PUP.Optional.CrossRider, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{CB4923DE-8C85-4C14-84F1-34747A20FB72}|APPNAME, In Quarantäne, [203], [237487],1.0.3616
PUP.Optional.GlobalUpdate, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\GLOBALUPDATE\UPDATE\PROXY|SOURCE, In Quarantäne, [742], [238772],1.0.3616
PUP.Optional.PCKeeper, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\f4e836bd_0|, In Quarantäne, [811], [260411],1.0.3616
PUP.Optional.PCKeeper, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PCKEEPERLIVE, In Quarantäne, [811], [260399],1.0.3616
PUP.Optional.PCKeeper, HKU\S-1-5-21-2147732465-1013433442-3662694159-1003\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|PCKEEPER ANTIVIRUS, In Quarantäne, [811], [260399],1.0.3616
PUP.Optional.Astromenda, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|APPPATH, In Quarantäne, [1847], [235613],1.0.3616
PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5A4A7D29-7589-427B-86BC-8C313278BF89}|DISPLAYNAME, In Quarantäne, [811], [260413],1.0.3616
PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{F7DA7463-F666-41B3-B16B-8968A43BA6D4}|DISPLAYNAME, In Quarantäne, [811], [260413],1.0.3616
PUP.Optional.PCKeeper, HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\f4e836bd_0|, In Quarantäne, [811], [260411],1.0.3616
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 2
PUP.Optional.FastPlayer, C:\Users\Lapp\AppData\Local\com\FastPlayer.exe_Url_ypw5ldaz5xtubzl3ykl5vaw3nmhswq1q\1.0.0.2, In Quarantäne, [3213], [177098],1.0.3616
PUP.Optional.FastPlayer, C:\USERS\LAPP\APPDATA\LOCAL\COM\FastPlayer.exe_Url_ypw5ldaz5xtubzl3ykl5vaw3nmhswq1q, In Quarantäne, [3213], [177098],1.0.3616
Datei: 11
PUP.Optional.FastPlayer, C:\Users\Lapp\AppData\Local\com\FastPlayer.exe_Url_ypw5ldaz5xtubzl3ykl5vaw3nmhswq1q\1.0.0.2\user.config, In Quarantäne, [3213], [177098],1.0.3616
PUP.Optional.Reimage, C:\USERS\PAUL\DOWNLOADS\REIMAGEREPAIR(3).EXE, In Quarantäne, [1096], [331559],1.0.3616
PUP.Optional.Reimage, C:\USERS\PAUL\DOWNLOADS\REIMAGEREPAIR(2).EXE, In Quarantäne, [1096], [331559],1.0.3616
Rogue.PCVARK, C:\USERS\PAUL\DOWNLOADS\ASCSETUP.EXE, In Quarantäne, [505], [437305],1.0.3616
Rogue.PCVARK, C:\USERS\PAUL\DOWNLOADS\ASCSETUP(1).EXE, In Quarantäne, [505], [437305],1.0.3616
PUP.Optional.Reimage, C:\USERS\PAUL\DOWNLOADS\REIMAGEREPAIR(1).EXE, In Quarantäne, [1096], [331559],1.0.3616
PUP.Optional.PCKeeper, C:\USERS\PAUL\DOWNLOADS\PCKEEPER INSTALLER.EXE, In Quarantäne, [811], [352238],1.0.3616
PUP.Optional.PCKeeper, C:\WINDOWS\INSTALLER\A2028.MSI, In Quarantäne, [811], [348428],1.0.3616
PUP.Optional.PCKeeper, C:\WINDOWS\INSTALLER\A203A.MSI, In Quarantäne, [811], [348428],1.0.3616
PUP.Optional.PCKeeper, C:\WINDOWS\INSTALLER\A202E.MSI, In Quarantäne, [811], [348428],1.0.3616
PUP.Optional.PCKeeper, C:\WINDOWS\INSTALLER\A2034.MSI, In Quarantäne, [811], [348428],1.0.3616
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end)
FRST: Code:
Untersuchungsergebnis von Farbar Recovery Scan Tool (FRST) (x64) Version: 02.01.2018
durchgeführt von Lapp (Administrator) auf LAPP-PC (03-01-2018 19:10:33)
Gestartet von C:\Users\Lapp\Desktop
Geladene Profile: Lapp (Verfügbare Profile: Lapp & Paul)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Sprache: Deutsch (Deutschland)
Internet Explorer Version 9 (Standard-Browser: FF)
Start-Modus: Normal
Anleitung für Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Prozesse (Nicht auf der Ausnahmeliste) =================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Prozess geschlossen. Die Datei wird nicht verschoben.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe
(Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(NETGEAR) C:\Program Files (x86)\NETGEAR\WN111v2\WN111v2.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\ControlCenter3\BrccMCtl.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
==================== Registry (Nicht auf der Ausnahmeliste) ===========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt. Die Datei wird nicht verschoben.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2741544 2011-04-08] (Synaptics Incorporated)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-07-23] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9753024 2011-07-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-07-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2010-04-28] ()
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-02-18] (Intel Corporation)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331_STI.EXE [536576 2010-01-15] (Vimicro)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [UpdatePRCShortCut] => "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery"
HKLM-x32\...\Run: [ControlCenter3] => C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-02-09] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642728 2012-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => Cmd.exe /c start "AMD Accelerated Video Transcoding device initialization" /min "C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe" aml
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [RestrictRun] 0
HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-02-15] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\...\Policies\Explorer: [RestrictRun] 0
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WN111v2 Setup-Assistent.lnk [2011-08-25]
ShortcutTarget: NETGEAR WN111v2 Setup-Assistent.lnk -> C:\Program Files (x86)\NETGEAR\WN111v2\WN111v2.exe (NETGEAR)
==================== Internet (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Eintrag entfernt oder auf den Standardwert zurückgesetzt, wenn es sich um einen Registryeintrag handelt.)
ProxyEnable: [.DEFAULT] => Proxy ist aktiviert.
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
Tcpip\..\Interfaces\{50107DA1-0F16-49DA-BB5F-BADDE3F6923D}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{63FFE849-A307-4B64-8193-7BC637BDF9C7}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{68928F98-BB10-48DF-BE6B-E41CCD5DE125}: [DhcpNameServer] 192.168.178.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2147732465-1013433442-3662694159-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKU\S-1-5-21-2147732465-1013433442-3662694159-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
FireFox:
========
FF DefaultProfile: orf310zd.default-1416514110202-1502113669925
FF ProfilePath: C:\Users\Lapp\AppData\Roaming\Mozilla\Firefox\Profiles\orf310zd.default-1416514110202-1502113669925 [2018-01-03]
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2018-01-02] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2018-01-02] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
==================== Dienste (Nicht auf der Ausnahmeliste) ====================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
S4 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173272 2013-11-01] (Microsoft Corp.)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [245760 2010-01-25] (Brother Industries, Ltd.) [Datei ist nicht signiert]
R2 DevoloNetworkService; C:\Program Files (x86)\devolo\dlan\devolonetsvc.exe [2231616 2010-07-19] ()
R2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1084432 2017-02-15] (Garmin Ltd. or its subsidiaries)
S3 jswpsapi; C:\Program Files (x86)\NETGEAR\WN111v2\jswpsapi.exe [942080 2008-02-29] (Atheros Communications, Inc.) [Datei ist nicht signiert]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Treiber (Nicht auf der Ausnahmeliste) ======================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [77432 2017-11-29] ()
S3 libusb0; C:\windows\System32\DRIVERS\libusb0.sys [44480 2011-05-17] (hxxp://libusb-win32.sourceforge.net)
R2 MBAMChameleon; C:\windows\System32\Drivers\MbamChameleon.sys [193968 2018-01-03] (Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\DRIVERS\farflt.sys [110016 2018-01-03] (Malwarebytes)
R3 MBAMProtection; C:\windows\System32\DRIVERS\mbam.sys [46008 2018-01-03] (Malwarebytes)
R0 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [253880 2018-01-03] (Malwarebytes)
R3 MBAMWebProtection; C:\windows\System32\DRIVERS\mwac.sys [84256 2018-01-03] (Malwarebytes)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation)
R3 NisDrv; C:\windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation)
R2 NPF_devolo; C:\windows\sysWOW64\drivers\npf_devolo.sys [34048 2010-06-10] (CACE Technologies)
S3 PCAMp50a64; C:\windows\System32\Drivers\PCAMp50a64.sys [43328 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
S3 PCASp50a64; C:\windows\System32\Drivers\PCASp50a64.sys [41280 2006-11-28] (Printing Communications Assoc., Inc. (PCAUSA))
R3 vm331avs; C:\windows\System32\Drivers\vm331avs.sys [228224 2010-10-21] (Vimicro Corporation)
R3 vmuvcflt; C:\windows\System32\Drivers\vmuvcflt.sys [8320 2010-08-16] (Vimicro Corporation)
S3 WFMC_VAD; C:\windows\System32\DRIVERS\wfmcvad.sys [24064 2010-02-08] (WiFi Media Connect)
S3 WN111v2; C:\windows\System32\DRIVERS\WN111v2w7x.sys [767488 2009-10-21] (Atheros Communications, Inc.)
U3 BcmSqlStartupSvc; kein ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U2 CLKMSVC10_3A60B698; kein ImagePath
U2 CLKMSVC10_C3B3B687; kein ImagePath
U2 DriverService; kein ImagePath
U2 iATAgentService; kein ImagePath
U2 idealife Update Service; kein ImagePath
U3 IGRS; kein ImagePath
U2 IviRegMgr; kein ImagePath
S1 lfputvzi; \??\C:\windows\system32\drivers\lfputvzi.sys [X]
U2 nvUpdatusService; kein ImagePath
U2 Oasis2Service; kein ImagePath
U2 PCCarerService; kein ImagePath
U2 ReadyComm.DirectRouter; kein ImagePath
U2 RichVideo; kein ImagePath
U2 RtLedService; kein ImagePath
U2 SeaPort; kein ImagePath
U2 SoftwareService; kein ImagePath
U3 SQLWriter; kein ImagePath
U2 Stereo Service; kein ImagePath
S3 ZeoScanner; system32\DRIVERS\zeoscanner.sys [X]
==================== NetSvcs (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
==================== Ein Monat: Erstellte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2018-01-03 19:10 - 2018-01-03 19:11 - 000015362 _____ C:\Users\Lapp\Desktop\FRST.txt
2018-01-03 19:09 - 2018-01-03 19:09 - 000015115 _____ C:\Users\Lapp\Desktop\mbam.txt
2018-01-03 18:49 - 2018-01-03 19:07 - 000110016 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2018-01-03 18:49 - 2018-01-03 19:07 - 000084256 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2018-01-03 18:49 - 2018-01-03 19:07 - 000046008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2018-01-03 18:49 - 2018-01-03 18:49 - 000193968 _____ (Malwarebytes) C:\windows\system32\Drivers\MbamChameleon.sys
2018-01-03 18:48 - 2018-01-03 18:48 - 000253880 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2018-01-03 18:48 - 2018-01-03 18:48 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-01-03 18:48 - 2018-01-03 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-01-03 18:48 - 2018-01-03 18:48 - 000000000 ____D C:\Program Files\Malwarebytes
2018-01-03 18:48 - 2017-11-29 09:11 - 000077432 _____ C:\windows\system32\Drivers\mbae64.sys
2018-01-03 18:36 - 2018-01-03 18:39 - 000003842 _____ C:\Users\Lapp\Desktop\Fixlog.txt
2018-01-03 18:34 - 2018-01-03 18:34 - 000015581 _____ C:\Users\Lapp\Desktop\AdwCleaner[C0].txt
2018-01-03 18:31 - 2018-01-03 18:31 - 000017587 _____ C:\Users\Lapp\Desktop\AdwCleaner[S0].txt
2018-01-03 18:26 - 2018-01-03 18:26 - 000000000 ____D C:\Users\Lapp\AppData\Local\{5DC50887-8001-4918-AAD1-4EE937A115D4}
2018-01-03 18:24 - 2018-01-03 18:24 - 022851472 _____ (Malwarebytes ) C:\Users\Lapp\Desktop\mbam-setup-2.2.1.1043.exe
2018-01-03 18:21 - 2018-01-03 18:22 - 008198432 _____ (Malwarebytes) C:\Users\Lapp\Desktop\AdwCleaner_7.0.6.0.exe
2018-01-02 19:05 - 2018-01-02 19:05 - 000000000 ____D C:\Users\Lapp\AppData\Local\ESET
2018-01-02 18:52 - 2018-01-03 19:10 - 000000000 ____D C:\FRST
2018-01-02 18:46 - 2018-01-02 18:45 - 002393088 _____ (Farbar) C:\Users\Lapp\Desktop\FRST64.exe
2018-01-02 18:23 - 2018-01-02 18:23 - 006974584 _____ (ESET spol. s r.o.) C:\Users\Paul\Downloads\esetonlinescanner_deu.exe
==================== Ein Monat: Geänderte Dateien und Ordner ========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Datei/der Ordner verschoben.)
2018-01-03 19:06 - 2011-07-23 03:32 - 000156913 _____ C:\windows\system32\fastboot.set
2018-01-03 19:05 - 2009-07-14 06:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-01-03 19:03 - 2014-10-26 17:34 - 000000000 ____D C:\Users\Lapp\AppData\Local\com
2018-01-03 18:58 - 2009-07-14 05:45 - 000028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-03 18:58 - 2009-07-14 05:45 - 000028704 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-03 18:54 - 2011-07-22 18:37 - 000713954 _____ C:\windows\system32\perfh007.dat
2018-01-03 18:54 - 2011-07-22 18:37 - 000154006 _____ C:\windows\system32\perfc007.dat
2018-01-03 18:54 - 2009-07-14 06:13 - 001647544 _____ C:\windows\system32\PerfStringBackup.INI
2018-01-03 18:54 - 2009-07-14 04:20 - 000000000 ____D C:\windows\inf
2018-01-03 18:48 - 2013-11-22 23:22 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-01-03 18:38 - 2012-05-02 15:08 - 000000000 ____D C:\Users\Lapp\AppData\LocalLow\Temp
2018-01-03 18:32 - 2014-04-17 20:01 - 000000000 ____D C:\AdwCleaner
2018-01-03 18:24 - 2017-03-15 16:05 - 000000000 ____D C:\Users\Lapp\AppData\LocalLow\Mozilla
2018-01-03 18:19 - 2016-11-20 21:11 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-01-03 18:16 - 2014-11-20 20:44 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-01-02 23:07 - 2016-11-22 20:55 - 000000000 ____D C:\Users\Paul\AppData\LocalLow\Mozilla
2018-01-02 22:31 - 2011-08-31 12:33 - 000003922 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{22EC8DB8-E9FB-4135-AF4A-B2C108DD28BE}
2018-01-02 22:25 - 2012-12-25 23:58 - 000000000 ____D C:\Users\Lapp\AppData\Roaming\Mozilla
2018-01-02 18:26 - 2016-11-01 17:05 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-01-02 18:26 - 2014-04-18 16:53 - 000004366 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2018-01-02 18:26 - 2014-04-18 16:52 - 000803328 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2018-01-02 18:26 - 2014-04-18 16:52 - 000144896 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-01-02 18:25 - 2014-04-18 16:52 - 000000000 ____D C:\windows\system32\Macromed
2018-01-02 18:25 - 2011-07-23 03:18 - 000000000 ____D C:\windows\SysWOW64\Macromed
==================== Dateien im Wurzelverzeichnis einiger Verzeichnisse =======
2013-08-05 22:56 - 2014-10-31 18:38 - 000000177 _____ () C:\Users\Lapp\AppData\Roaming\WB.CFG
2013-08-12 23:07 - 2013-08-18 20:55 - 000000005 _____ () C:\Users\Lapp\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-08-05 22:56 - 2013-12-28 22:17 - 000000006 _____ () C:\Users\Lapp\AppData\Roaming\WBPU-TTL.DAT
==================== Bamital & volsnap ======================
(Es ist kein automatischer Fix für Dateien vorhanden, die an der Verifikation gescheitert sind.)
C:\windows\system32\winlogon.exe => Datei ist digital signiert
C:\windows\system32\wininit.exe => Datei ist digital signiert
C:\windows\SysWOW64\wininit.exe => Datei ist digital signiert
C:\windows\explorer.exe => Datei ist digital signiert
C:\windows\SysWOW64\explorer.exe => Datei ist digital signiert
C:\windows\system32\svchost.exe => Datei ist digital signiert
C:\windows\SysWOW64\svchost.exe => Datei ist digital signiert
C:\windows\system32\services.exe => Datei ist digital signiert
C:\windows\system32\User32.dll => Datei ist digital signiert
C:\windows\SysWOW64\User32.dll => Datei ist digital signiert
C:\windows\system32\userinit.exe => Datei ist digital signiert
C:\windows\SysWOW64\userinit.exe => Datei ist digital signiert
C:\windows\system32\rpcss.dll => Datei ist digital signiert
C:\windows\system32\dnsapi.dll => Datei ist digital signiert
C:\windows\SysWOW64\dnsapi.dll => Datei ist digital signiert
C:\windows\system32\Drivers\volsnap.sys => Datei ist digital signiert
LastRegBack: 2016-02-11 01:05
==================== Ende von FRST.txt ============================ Viele Grüße
Thomas |