StephanL | 07.08.2014 16:45 | okay, danke für den Hinweis! Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 07.08.2014
Scan Time: 15:22:24
Logfile: MWAB814.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.08.07.02
Rootkit Database: v2014.08.04.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8
CPU: x64
File System: NTFS
User: Wolfgang und Anne
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 285572
Time Elapsed: 10 min, 36 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 2
PUP.Optional.Whilokii.A, C:\Program Files (x86)\Whilokii\updateWhilokii.exe, 2416, Delete-on-Reboot, [a618665d13681d19e66d6df29b668f71]
PUP.Optional.Whilokii.A, C:\Program Files (x86)\Whilokii\bin\utilWhilokii.exe, 2852, Delete-on-Reboot, [97273d864c2f34029ab9372805fc827e]
Modules: 0
(No malicious items detected)
Registry Keys: 118
PUP.Optional.Whilokii.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Whilokii, Quarantined, [a618665d13681d19e66d6df29b668f71],
PUP.Optional.Whilokii.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util Whilokii, Quarantined, [97273d864c2f34029ab9372805fc827e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\APPID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}, Quarantined, [5b6310b3631840f6234fd0cf679b2dd3],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3COMClassService, Quarantined, [5b6310b3631840f6234fd0cf679b2dd3],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3COMClassService.1.0, Quarantined, [5b6310b3631840f6234fd0cf679b2dd3],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3COMClassService, Quarantined, [5b6310b3631840f6234fd0cf679b2dd3],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3COMClassService.1.0, Quarantined, [5b6310b3631840f6234fd0cf679b2dd3],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}, Quarantined, [5b6310b3631840f6234fd0cf679b2dd3],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{9EA8702C-EEDB-4731-BE68-E9A167DD3597}, Quarantined, [5b6310b3631840f6234fd0cf679b2dd3],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\APPID\{D34F391D-4CB7-467F-A543-F583857C63B0}, Quarantined, [7e4009ba671414220571623d9f6321df],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc, Quarantined, [7e4009ba671414220571623d9f6321df],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [7e4009ba671414220571623d9f6321df],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc, Quarantined, [7e4009ba671414220571623d9f6321df],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0, Quarantined, [7e4009ba671414220571623d9f6321df],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D34F391D-4CB7-467F-A543-F583857C63B0}, Quarantined, [7e4009ba671414220571623d9f6321df],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D34F391D-4CB7-467F-A543-F583857C63B0}, Quarantined, [7e4009ba671414220571623d9f6321df],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, Quarantined, [6c525172fc7fce68e1069607b64c3ac6],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, Quarantined, [6c525172fc7fce68e1069607b64c3ac6],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{118E1BF6-6279-432F-A285-373A77B90C7A}, Quarantined, [516df8cb5328f4425811f4aba45e07f9],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebSvc.1.0, Quarantined, [516df8cb5328f4425811f4aba45e07f9],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebSvc, Quarantined, [516df8cb5328f4425811f4aba45e07f9],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebSvc, Quarantined, [516df8cb5328f4425811f4aba45e07f9],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebSvc.1.0, Quarantined, [516df8cb5328f4425811f4aba45e07f9],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{14CEEA2F-3D21-46ED-A7D2-89056C520E5E}, Quarantined, [714dbe059fdcf1458dddcfd0c83a7d83],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.ProcessLauncher.1.0, Quarantined, [714dbe059fdcf1458dddcfd0c83a7d83],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.ProcessLauncher, Quarantined, [714dbe059fdcf1458dddcfd0c83a7d83],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.ProcessLauncher, Quarantined, [714dbe059fdcf1458dddcfd0c83a7d83],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.ProcessLauncher.1.0, Quarantined, [714dbe059fdcf1458dddcfd0c83a7d83],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{1CC8D970-F626-4F19-815F-890032BB6606}, Quarantined, [f9c520a364170531beadebb4c53dc43c],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachine.1.0, Quarantined, [f9c520a364170531beadebb4c53dc43c],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachine, Quarantined, [f9c520a364170531beadebb4c53dc43c],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachine, Quarantined, [f9c520a364170531beadebb4c53dc43c],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachine.1.0, Quarantined, [f9c520a364170531beadebb4c53dc43c],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}, Quarantined, [7747675cf08b2f0709638d1246bcb24e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLive.OneClickCtrl.9, Quarantined, [7747675cf08b2f0709638d1246bcb24e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLive.OneClickCtrl.9, Quarantined, [7747675cf08b2f0709638d1246bcb24e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}, Quarantined, [7747675cf08b2f0709638d1246bcb24e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}, Quarantined, [7747675cf08b2f0709638d1246bcb24e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{33BAF587-9647-4281-A34F-F4830CDC1B9F}, Quarantined, [fdc1645fb3c8c96de18c7c23b54df60a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLive.OneClickProcessLauncherMachine.1.0, Quarantined, [fdc1645fb3c8c96de18c7c23b54df60a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLive.OneClickProcessLauncherMachine, Quarantined, [fdc1645fb3c8c96de18c7c23b54df60a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLive.OneClickProcessLauncherMachine, Quarantined, [fdc1645fb3c8c96de18c7c23b54df60a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLive.OneClickProcessLauncherMachine.1.0, Quarantined, [fdc1645fb3c8c96de18c7c23b54df60a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{33BAF587-9647-4281-A34F-F4830CDC1B9F}, Quarantined, [fdc1645fb3c8c96de18c7c23b54df60a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5B5E5D0E-7C83-4A32-ADD2-E5F488DD6783}, Quarantined, [f0ce4d768eedbe7877f7e7b808fafe02],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6802463D-636F-41FE-9924-4CAD56906590}, Quarantined, [1ca2497a75068fa72748188750b2b749],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [1ca2497a75068fa72748188750b2b749],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine, Quarantined, [1ca2497a75068fa72748188750b2b749],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine, Quarantined, [1ca2497a75068fa72748188750b2b749],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine.1.0, Quarantined, [1ca2497a75068fa72748188750b2b749],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{806785D0-375F-4C2C-92E3-B8EE65D28E83}, Quarantined, [7747b40f205bbb7ba0d0e4bb2cd6ef11],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{944661E7-67B9-4DF7-BFF2-05388C166D34}, Quarantined, [8737784b93e8e4529ad7ecb36999a55b],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoreMachineClass.1, Quarantined, [8737784b93e8e4529ad7ecb36999a55b],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoreMachineClass, Quarantined, [8737784b93e8e4529ad7ecb36999a55b],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoreMachineClass, Quarantined, [8737784b93e8e4529ad7ecb36999a55b],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoreMachineClass.1, Quarantined, [8737784b93e8e4529ad7ecb36999a55b],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A7CF66EF-4F0D-46B1-AF71-A500378D6C34}, Quarantined, [26980ab9106b79bd4132d4cbcf337f81],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoreClass.1, Quarantined, [26980ab9106b79bd4132d4cbcf337f81],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoreClass, Quarantined, [26980ab9106b79bd4132d4cbcf337f81],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoreClass, Quarantined, [26980ab9106b79bd4132d4cbcf337f81],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoreClass.1, Quarantined, [26980ab9106b79bd4132d4cbcf337f81],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{B71934E5-6B93-448D-9D32-CBAA5150C5D8}, Quarantined, [8c32cff432491f174b29524de2208c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [8c32cff432491f174b29524de2208c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback, Quarantined, [8c32cff432491f174b29524de2208c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback, Quarantined, [8c32cff432491f174b29524de2208c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback.1.0, Quarantined, [8c32cff432491f174b29524de2208c74],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{C4BEF720-313C-420A-ACF6-77DD95D8F553}, Quarantined, [02bc7c47e49753e37500118ee61c6e92],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLive.Update3WebControl.3, Quarantined, [02bc7c47e49753e37500118ee61c6e92],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLive.Update3WebControl.3, Quarantined, [02bc7c47e49753e37500118ee61c6e92],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C4BEF720-313C-420A-ACF6-77DD95D8F553}, Quarantined, [02bc7c47e49753e37500118ee61c6e92],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C4BEF720-313C-420A-ACF6-77DD95D8F553}, Quarantined, [02bc7c47e49753e37500118ee61c6e92],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E970727E-0508-4BEB-8B72-BBA9D0D047C7}, Quarantined, [506e81423645082ea0d7029dd52db050],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoCreateAsync.1.0, Quarantined, [506e81423645082ea0d7029dd52db050],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CoCreateAsync, Quarantined, [506e81423645082ea0d7029dd52db050],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoCreateAsync, Quarantined, [506e81423645082ea0d7029dd52db050],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CoCreateAsync.1.0, Quarantined, [506e81423645082ea0d7029dd52db050],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{EBF1F869-D2F0-4D31-A877-386C853A9C3D}, Quarantined, [dbe3675cbbc0b38384f4356a7e84c23e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0, Quarantined, [dbe3675cbbc0b38384f4356a7e84c23e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.CredentialDialogMachine, Quarantined, [dbe3675cbbc0b38384f4356a7e84c23e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CredentialDialogMachine, Quarantined, [dbe3675cbbc0b38384f4356a7e84c23e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0, Quarantined, [dbe3675cbbc0b38384f4356a7e84c23e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F3CF4912-CF0A-451B-AF3B-C4F216C715E4}, Quarantined, [26986063ef8c59dd1960900fe41e37c9],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F904AC50-215C-42AB-A532-77E9FDBA9B19}, Quarantined, [d7e7299a9cdf4de9b9c16a359c66a65a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachineFallback.1.0, Quarantined, [d7e7299a9cdf4de9b9c16a359c66a65a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachineFallback, Quarantined, [d7e7299a9cdf4de9b9c16a359c66a65a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachineFallback, Quarantined, [d7e7299a9cdf4de9b9c16a359c66a65a],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\BonanzaDealsLiveUpdate.Update3WebMachineFallback.1.0, Quarantined, [d7e7299a9cdf4de9b9c16a359c66a65a],
PUP.Optional.Babylon.A, HKU\S-1-5-21-1682701105-3862308186-3827129608-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, Quarantined, [1da1bd063e3d0e288cc84d1799698878],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1231839B-064E-4788-B865-465A1B5266FD}, Quarantined, [06b8d9ea5d1eef47cff71a83ec16e917],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{2DAC2231-CC35-482B-97C5-CED1D4185080}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{57C91446-8D81-4156-A70E-624551442DE9}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{97DD820D-2E20-40AD-B01E-6730B2FCE630}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B177446D-54A4-4869-BABC-8566110B4BE0}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{F05B12E1-ADE8-4485-B45B-898748B53C37}, Quarantined, [d2ec457e6615c3737e48d4c95ba7857b],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Bonanza Deals, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{fed5e6b2-4fc4-43ba-8e95-001d959d8008}w64, Quarantined, [f1cd92312a51ee48ce8387b06f95c838],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\CLASSES\APPID\BonanzaDealsLive.exe, Quarantined, [5a646c57d8a375c1cfa8998672926b95],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\BonanzaDealsLive.exe, Quarantined, [734bd8ebcdaec472f48941de8c785ba5],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\BonanzaDealsLive, Quarantined, [9b2313b0c2b9a69077052df2c2423ec2],
PUP.Optional.Whilokii.A, HKLM\SOFTWARE\WOW6432NODE\Whilokii, Quarantined, [3688675c4833e35334c357d747bdae52],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\BONANZADEALS, Quarantined, [cfef299ae89334029dde66b955af827e],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\BonanzaDealsLive.exe, Quarantined, [1aa4efd499e285b1ef8862bd778d0cf4],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\BonanzaDealsLive.exe, Quarantined, [4579467dcbb00432ccb1a37cb84c2ad6],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.bdupdater.com/BonanzaDealsLive Update;version=3, Quarantined, [ab1330933b402412205ea37cda2a31cf],
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLAPLUGINS\@tools.bdupdater.com/BonanzaDealsLive Update;version=9, Quarantined, [8c322c9791ea3ef8e09e091662a234cc],
PUP.Optional.BitGuard.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BITGUARD, Quarantined, [04ba3390abd0dc5ad9d341da7b89ef11],
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-1682701105-3862308186-3827129608-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BonanzaDealsLive, Quarantined, [b509903313681323b9c1150a4bb9cb35],
PUP.Optional.Whilokii.A, HKU\S-1-5-21-1682701105-3862308186-3827129608-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Whilokii, Quarantined, [10aefec56f0ccc6aa155e14dde26ee12],
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-1682701105-3862308186-3827129608-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BONANZADEALS, Quarantined, [1da1774c433886b04b2e22fd8183f20e],
PUP.Optional.Updater.A, HKU\S-1-5-21-1682701105-3862308186-3827129608-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\UpdaterEX, Quarantined, [7c42348fe09b31053ebc05c9e220728e],
Registry Values: 3
PUP.Optional.BonanzaDeals.A, HKLM\SOFTWARE\WOW6432NODE\BONANZADEALS|ChromeCrxPath, C:\Program Files (x86)\BonanzaDeals\BonanzaDeals.crx, Quarantined, [cfef299ae89334029dde66b955af827e]
PUP.Optional.BitGuard.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\BITGUARD|ImagePath, C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-1111-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe, Quarantined, [04ba3390abd0dc5ad9d341da7b89ef11]
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-1682701105-3862308186-3827129608-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BONANZADEALS|ChromeCrxPath, C:\Program Files (x86)\BonanzaDeals\BonanzaDeals.crx, Quarantined, [1da1774c433886b04b2e22fd8183f20e]
Registry Data: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[289680431f5cac8a86a46f5632d216ea]
Folders: 9
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals, Quarantined, [6f4f09ba2556979f2e47fe210bf9e51b],
PUP.Optional.Delta.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\mt_ffx\Delta, Quarantined, [a717bf04e497b68093a2b6fb976b8080],
PUP.Optional.Delta.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\mt_ffx\Delta\delta, Quarantined, [a717bf04e497b68093a2b6fb976b8080],
PUP.Optional.Delta.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.24.6, Quarantined, [a717bf04e497b68093a2b6fb976b8080],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj, Quarantined, [bd01705336451125b3592f83d42e8e72],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0, Quarantined, [bd01705336451125b3592f83d42e8e72],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0\images, Quarantined, [bd01705336451125b3592f83d42e8e72],
PUP.Optional.Updater.A, C:\Users\Wolfgang und Anne\AppData\Roaming\UpdaterEX\UpdateProc, Quarantined, [7c42348fe09b31053ebc05c9e220728e],
Files: 47
PUP.Optional.Whilokii.A, C:\Program Files (x86)\Whilokii\updateWhilokii.exe, Delete-on-Reboot, [a618665d13681d19e66d6df29b668f71],
PUP.Optional.Whilokii.A, C:\Program Files (x86)\Whilokii\bin\utilWhilokii.exe, Delete-on-Reboot, [97273d864c2f34029ab9372805fc827e],
PUP.Optional.PayByAds.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\dsrlte.exe, Quarantined, [b5093b88a4d783b3df7431c2dd27af51],
PUP.Optional.Babylon.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\56C41213-BAB0-7891-848A-794D9950EB08\Latest\BExternal.dll, Quarantined, [3e8011b21c5f1c1a3cc95ac90000eb15],
PUP.Optional.Conduit.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\56C41213-BAB0-7891-848A-794D9950EB08\Latest\ccp.exe, Quarantined, [3e8042810f6c261066bec16ab0518779],
PUP.Optional.Babylon.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\56C41213-BAB0-7891-848A-794D9950EB08\Latest\CrxInstaller.dll, Quarantined, [35896e55e992cb6baca13be823de916f],
PUP.Optional.Delta.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\56C41213-BAB0-7891-848A-794D9950EB08\Latest\DSearchLink.exe, Quarantined, [26984182d1aac670251f621d758fbb45],
PUP.Optional.Babylon.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\56C41213-BAB0-7891-848A-794D9950EB08\Latest\MntrDLLInstall.dll, Quarantined, [8737576c205ba59125299b885da414ec],
PUP.Optional.Delta.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\56C41213-BAB0-7891-848A-794D9950EB08\Latest\MyDeltaTB.exe, Quarantined, [0db1418299e2c76f63f9ea908d74db25],
PUP.Optional.Babylon.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\56C41213-BAB0-7891-848A-794D9950EB08\Latest\Setup.exe, Quarantined, [18a65f64a1da9b9bb1f64fd2e51bd729],
PUP.Optional.CRX.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\bus5763\CrxUpdater_d.exe, Quarantined, [3e80853eff7c1a1c67d57111768ec33d],
PUP.Optional.Babylon.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366719373_stp\DeltaTB.exe, Quarantined, [fac4348f98e3d75f9b89aa6637caa25e],
PUP.Optional.Wajam.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366719389_stp\wajam_download.exe, Quarantined, [e8d6f5cef48741f5fc1cfe490ef2eb15],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366719549_stp\bd.exe, Quarantined, [3b83a91ab4c7f73f8d724ce0ec15bd43],
PUP.Optional.Elex, C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366809900_stp\cor_ar_201392319852_qvo6.exe, Quarantined, [9628477cc9b2ca6c98db859cbb45669a],
PUP.Optional.Elex, C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366906043_stp\cor_ar_201392319852_qvo6.exe, Quarantined, [e0de81423348f34382f12af757a9d030],
PUP.Optional.InstallCore, C:\Users\Wolfgang und Anne\Downloads\SkypeSetup(1).exe, Quarantined, [9e2002c1a9d2a1959efff58c986c817f],
PUP.Optional.BonanzaDeals.A, C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineCore, Quarantined, [06b8824123583006de906f6fa959bb45],
PUP.Optional.BonanzaDeals.A, C:\Windows\System32\Tasks\BonanzaDealsLiveUpdateTaskMachineUA, Quarantined, [8c32447f6c0f74c2422c518dd230e818],
PUP.Optional.BonanzaDeals.A, C:\Windows\System32\Tasks\BonanzaDealsUpdate, Quarantined, [e3db8142d6a5979facc203dbfd05cb35],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\BonanzaDeals.crx, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\BonanzaDeals.xpi, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE.dll, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\BonanzaDealsIE64.dll, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\BonanzaDealsUpdate.exe, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\BonanzaDealsUpdate.log, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\BonanzaDealsUpdateRun.exe, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\icon.ico, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Program Files (x86)\BonanzaDeals\uninst.exe, Quarantined, [e3db992a2f4ca88e5c18e23d0ff549b7],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals\Bonanza Deals Help.url, Quarantined, [6f4f09ba2556979f2e47fe210bf9e51b],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals\Bonanza Deals.url, Quarantined, [6f4f09ba2556979f2e47fe210bf9e51b],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BonanzaDeals\Uninstall Bonanza Deals.lnk, Quarantined, [6f4f09ba2556979f2e47fe210bf9e51b],
PUP.Optional.BonanzaDeals.A, C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineCore.job, Quarantined, [724cc201324963d35d19140b9e66f20e],
PUP.Optional.BonanzaDeals.A, C:\Windows\Tasks\BonanzaDealsLiveUpdateTaskMachineUA.job, Quarantined, [823cfac915669b9bda9ca7783dc748b8],
PUP.Optional.Sanbreel.A, C:\Windows\System32\Drivers\{fed5e6b2-4fc4-43ba-8e95-001d959d8008}w64.sys, Quarantined, [f1cd92312a51ee48ce8387b06f95c838],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0\background.js, Quarantined, [bd01705336451125b3592f83d42e8e72],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0\info.txt, Quarantined, [bd01705336451125b3592f83d42e8e72],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0\manifest.json, Quarantined, [bd01705336451125b3592f83d42e8e72],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0\images\icon128.png, Quarantined, [bd01705336451125b3592f83d42e8e72],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0\images\icon16.png, Quarantined, [bd01705336451125b3592f83d42e8e72],
PUP.Optional.BonanzaDeals.A, C:\Users\Wolfgang und Anne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj\3.5.0.0_0\images\icon48.png, Quarantined, [bd01705336451125b3592f83d42e8e72],
PUP.Optional.Updater.A, C:\Users\Wolfgang und Anne\AppData\Roaming\UpdaterEX\UpdateProc\config.dat, Quarantined, [7c42348fe09b31053ebc05c9e220728e],
PUP.Optional.Updater.A, C:\Users\Wolfgang und Anne\AppData\Roaming\UpdaterEX\UpdateProc\info.dat, Quarantined, [7c42348fe09b31053ebc05c9e220728e],
PUP.Optional.Updater.A, C:\Users\Wolfgang und Anne\AppData\Roaming\UpdaterEX\UpdateProc\prod.dat, Quarantined, [7c42348fe09b31053ebc05c9e220728e],
PUP.Optional.Updater.A, C:\Users\Wolfgang und Anne\AppData\Roaming\UpdaterEX\UpdateProc\STTL.DAT, Quarantined, [7c42348fe09b31053ebc05c9e220728e],
PUP.Optional.Updater.A, C:\Users\Wolfgang und Anne\AppData\Roaming\UpdaterEX\UpdateProc\TTL.DAT, Quarantined, [7c42348fe09b31053ebc05c9e220728e],
PUP.Optional.Updater.A, C:\Users\Wolfgang und Anne\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe, Quarantined, [7c42348fe09b31053ebc05c9e220728e],
Physical Sectors: 0
(No malicious items detected)
(end) AdwCleaner Logfile: Code:
# AdwCleaner v3.303 - Bericht erstellt am 07/08/2014 um 15:47:53
# Aktualisiert 06/08/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Wolfgang und Anne - WOLFGANG
# Gestartet von : C:\Users\Wolfgang und Anne\Downloads\adwcleaner_3.303.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Whilokii
Ordner Gelöscht : C:\Users\WOLFGA~1\AppData\Local\Temp\mt_ffx
Ordner Gelöscht : C:\Users\Wolfgang und Anne\AppData\Roaming\UpdaterEX
Datei Gelöscht : C:\Users\Wolfgang und Anne\AppData\Roaming\Mozilla\Firefox\Profiles\wldm4hs5.default\Extensions\{f9d03c26-0575-497e-821d-f7956d23e0ca}.xpi
***** [ Tasks ] *****
Task Gelöscht : BonanzaDealsUpdate
Task Gelöscht : UpdaterEX
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Wolfgang und Anne\Desktop\Search.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\d
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updatewhilokii_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updatewhilokii_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKCU\Software\UpdaterEX
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ac225167-00fc-452d-94c5-bb93600e7d9a}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Whilokii
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - c:\progra~3\bitguard\261694~1.246\{c16c1~1\bitguard.dll
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.17028
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Wolfgang und Anne\AppData\Roaming\Mozilla\Firefox\Profiles\wldm4hs5.default\prefs.js ]
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [17680 octets] - [29/09/2013 22:38:44]
AdwCleaner[R1].txt - [2990 octets] - [07/08/2014 15:46:29]
AdwCleaner[S0].txt - [15142 octets] - [29/09/2013 22:40:01]
AdwCleaner[S1].txt - [2742 octets] - [07/08/2014 15:47:53]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2802 octets] ########## --- --- ---
JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by Wolfgang und Anne on 07.08.2014 at 15:52:49,49
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1682701105-3862308186-3827129608-1001\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update whilokii
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 07.08.2014 at 15:58:32,10
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und hier noch ESET Code:
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDealsLive\Update\BonanzaDealsLive.exe.vir Win32/DealPly.L evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\BonanzaDealsLive.exe.vir Win32/DealPly.L evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\BonanzaDealsLiveBroker.exe.vir Win32/DealPly.L evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\BonanzaDealsLiveHandler.exe.vir Win32/DealPly.L evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\BonanzaDealsLiveOnDemand.exe.vir Variante von Win32/DealPly.L evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\goopdate.dll.vir Win32/DealPly.L evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\npGoogleUpdate3.dll.vir Win32/DealPly.N evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\psmachine.dll.vir Win32/DealPly.L evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDealsLive\Update\1.3.23.0\psuser.dll.vir Variante von Win32/DealPly.L evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\delta\delta\1.8.24.6\deltaApp.dll.vir Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\delta\delta\1.8.24.6\deltaEng.dll.vir möglicherweise Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\delta\delta\1.8.24.6\deltasrv.exe.vir Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\delta\delta\1.8.24.6\deltaTlbr.dll.vir Variante von Win32/Toolbar.Montiera.F evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\delta\delta\1.8.24.6\uninstall.exe.vir Win32/Toolbar.Montiera.B evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\delta\delta\1.8.24.6\bh\delta.dll.vir Variante von Win32/Toolbar.Escort.A evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Wajam\IE\priam_bho.dll.vir Variante von Win32/Wajam.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Wajam\Updater\WajamUpdater.exe.vir Win32/Wajam.A evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\WhilokiiUn.exe.vir möglicherweise Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\Whilokii.BrowserAdapter.exe.vir Variante von Win32/BrowseFox.I evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\Whilokii.BRT.Helper.exe.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\WhilokiiBAApp.dll.vir Win32/BrowseFox.N evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\{fed5e6b2-4fc4-43ba-8e95-001d959d8008}.dll.vir Variante von Win32/BrowseFox.M evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.Bromon.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.BroStats.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.BrowserAdapter.dll.vir möglicherweise Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.BrowserAdapterS.dll.vir möglicherweise Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.BRT.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.CompatibilityChecker.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.FeSvc.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.FFUpdate.dll.vir Variante von MSIL/BrowseFox.E evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.IEUpdate.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.OfSvc.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.PurBrowse.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.PurBrowseG.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Whilokii\bin\plugins\Whilokii.Repmon.dll.vir Variante von MSIL/BrowseFox.G evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\ProgramData\DSearchLink\DSearchLink.exe.vir Win32/Toolbar.Babylon.Y evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Users\Wolfgang und Anne\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung
C:\AdwCleaner\Quarantine\C\Users\Wolfgang und Anne\AppData\Roaming\Mozilla\Firefox\Profiles\wldm4hs5.default\Extensions\ffxtlbr@delta.com\uninstall.exe.vir Win32/Toolbar.Montiera.B evtl. unerwünschte Anwendung
C:\Users\Wolfgang und Anne\AppData\Local\Temp\56C41213-BAB0-7891-848A-794D9950EB08\Latest\BabMaint.exe Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung
C:\Users\Wolfgang und Anne\AppData\Local\Temp\56C41213-BAB0-7891-848A-794D9950EB08\Latest\IEHelper.dll Win32/Toolbar.Babylon.E evtl. unerwünschte Anwendung
C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366719332_stp\wajam_validate.exe Win32/Wajam.F evtl. unerwünschte Anwendung
C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366809812_stp\wajam_validate.exe Win32/Wajam.F evtl. unerwünschte Anwendung
C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366854570_stp\wajam_validate.exe Win32/Wajam.F evtl. unerwünschte Anwendung
C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366905956_stp\wajam_validate.exe Win32/Wajam.F evtl. unerwünschte Anwendung
C:\Users\Wolfgang und Anne\AppData\Local\Temp\is1275519350\366906226_stp\whilokii_is.exe Win32/BrowseFox.C evtl. unerwünschte Anwendung |