hallo, hier haben wir den MbAM Log Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 14.02.2015
Suchlauf-Zeit: 12:29:35
Logdatei: MBAM Verlaufsprotokoll.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.02.14.02
Rootkit Datenbank: v2015.02.03.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Royale
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 398644
Verstrichene Zeit: 29 Min, 8 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 11
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1476, Löschen bei Neustart, [f96128f64d3dd95d650481fc9e63ce32]
PUP.Optional.AdPeak.A, C:\Program Files\005\jxbalvtmyz64.exe, 2020, Löschen bei Neustart, [d78344da3654c571ef94a3f059acfd03]
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 4244, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f]
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 4536, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f]
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 4584, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f]
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 4724, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f]
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 4984, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f]
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 5012, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f]
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 4056, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f]
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, 4544, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f]
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, 2092, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f]
Module: 10
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\libEGL.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\libEGL.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
Registrierungsschlüssel: 45
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [f96128f64d3dd95d650481fc9e63ce32],
PUP.Optional.AdPeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\jxbalvtmyz64, In Quarantäne, [d78344da3654c571ef94a3f059acfd03],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, In Quarantäne, [203a0a1492f8df579c48162acc37629e],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, In Quarantäne, [203a0a1492f8df579c48162acc37629e],
PUP.Optional.BizzyBolt, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{13070af0-bc6c-4185-8baa-40a4cf05b323}, In Quarantäne, [95c5fe2007835cda18690a028c774eb2],
PUP.Optional.BizzyBolt, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{13070AF0-BC6C-4185-8BAA-40A4CF05B323}, In Quarantäne, [95c5fe2007835cda18690a028c774eb2],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0}, In Quarantäne, [9dbd5cc2fb8fe650ffb076934ab9837d],
PUP.Optional.FlowSurf.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{E3F1CA13-EA0E-4617-8D03-3EAA6A94A7E0}, In Quarantäne, [9dbd5cc2fb8fe650ffb076934ab9837d],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarantäne, [e7738d915f2baf8791fdb75430d3cc34],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [e7738d915f2baf8791fdb75430d3cc34],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [e7738d915f2baf8791fdb75430d3cc34],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarantäne, [e7738d915f2baf8791fdb75430d3cc34],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [62f8dc42ec9ee84ea5edc47f63a009f7],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, In Quarantäne, [62f8dc42ec9ee84ea5edc47f63a009f7],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{CE681A67-9477-CBE6-EB9D-FE534875F98D}, In Quarantäne, [a8b2ae706525280e3c35dc2ad92a1ce4],
PUP.Optional.CompatibilityVerifier.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Verifies and fixes application compatibility issues, In Quarantäne, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.Adpeak.A, HKLM\SOFTWARE\AllDaySavings, In Quarantäne, [6befeb330684da5c1859bbf42ed5ff01],
PUP.Optional.CouponArific.A, HKLM\SOFTWARE\couponarific, In Quarantäne, [c298f8264c3e6accabd815889e65916f],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [213943dbbdcdf04663c553a61de73ec2],
PUP.Optional.Adpeak.A, HKLM\SOFTWARE\WOW6432NODE\AllDaySavings, In Quarantäne, [4a10b965c1c9171f5f126649a55ec43c],
PUP.Optional.CouponArific.A, HKLM\SOFTWARE\WOW6432NODE\couponarific, In Quarantäne, [99c1d74737531d196e15cdd0e71c6c94],
Adware.EoRezo, HKLM\SOFTWARE\WOW6432NODE\FREESOFTTODAY, In Quarantäne, [2a305ac40d7d90a692f6b241d62e7090],
PUP.Optional.ISearch.A, HKLM\SOFTWARE\WOW6432NODE\omiga-plusSoftware, In Quarantäne, [213963bbf1993204bdbf60a54bbae818],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [d882ba64d6b4ba7c3e247c9157ae6f91],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\supWPM, In Quarantäne, [9ac0db433654d85e2fcfb6f27d869f61],
PUP.Optional.SweetIM.A, HKLM\SOFTWARE\WOW6432NODE\SweetIM, In Quarantäne, [e27879a5c8c273c3a775118591720cf4],
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, In Quarantäne, [4911130b672338fef17edaf10ff425db],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [b9a13ae40486bf772efad128a4608b75],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB, In Quarantäne, [74e6b56918721d194ab3d5d3a0631ce4],
PUP.Optional.SystemSpeedup, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\ssd, In Quarantäne, [c89245d9f298c47252a2f0c21ce7bd43],
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS, In Quarantäne, [87d324fa880289ad6e9b2bef81840df3],
PUP.Optional.Adpeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\AllDaySavingsService64, In Quarantäne, [c59572acdcaebf7730447936fe054eb2],
PUP.Optional.CouponArific.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CouponarificService64, In Quarantäne, [a8b262bcb5d577bfd9ace3ba19eafa06],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [69f163bb7c0ea195230fd4ca8a79e51b],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, In Quarantäne, [0654b668ccbee35378bbe4baaa59b050],
PUP.Optional.CouponArific.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\couponarific, In Quarantäne, [fc5e75a97416c76f770beeaf4fb42ad6],
PUP.Optional.FlowSurf.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\FLOWSURF, In Quarantäne, [b5a5fb23751575c185730304ec19d828],
PUP.Optional.WebSearches.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SupHpUISoft, In Quarantäne, [3a2048d6bbcfbf77f2ba6c3e50b32cd4],
PUP.Optional.SweetIM.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SweetIM, In Quarantäne, [e278130bd4b6c670918a7026649fc23e],
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\TutoTag, In Quarantäne, [0a50d04ed8b2f24476dee729ad580bf5],
PUP.Optional.ViewPassword.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\ViewPassword, In Quarantäne, [3b1f20febdcd65d145bca610937036ca],
PUP.Optional.FlowSurf.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\FLOWSURF, In Quarantäne, [3b1f0519bcce3afc896f59ae0104ac54],
PUP.Optional.Qone8, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [99c160be444672c481a6f504729227d9],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT, In Quarantäne, [cb8fa579d1b9ef47817bf8de7b88f010],
PUP.Optional.SystemSpeedup, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SYSTWEAK\ssd, In Quarantäne, [3a208a94315946f08172605226ddac54],
Registrierungswerte: 7
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [362478a6414992a4366da9fedf241de3]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, In Quarantäne, [f8628f8f503aac8a940f07a081827987]
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\SUPTAB|ptid, vtt, In Quarantäne, [74e6b56918721d194ab3d5d3a0631ce4]
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS|HostGUID, 678875E6-BDEB-456F-AAB8-B25F1FA365BF, In Quarantäne, [87d324fa880289ad6e9b2bef81840df3]
PUP.Optional.FlowSurf.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\FLOWSURF|chrid, oglkiljdmflopemijdadoiepkhcaodjn, In Quarantäne, [b5a5fb23751575c185730304ec19d828]
PUP.Optional.FlowSurf.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\FLOWSURF|chrid, oglkiljdmflopemijdadoiepkhcaodjn, In Quarantäne, [3b1f0519bcce3afc896f59ae0104ac54]
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SEARCHPROTECTINT|Install, 1, In Quarantäne, [cb8fa579d1b9ef47817bf8de7b88f010]
Registrierungsdaten: 12
PUP.Optional.CalcIt.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://websearch.calcitapp.info/, Gut: (www.google.com), Schlecht: (hxxp://websearch.calcitapp.info/),Ersetzt,[d28833ebeb9f201641b4981c32d3f40c]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[d2888e90e3a73afc514c3c8324e16c94]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1407110393&from=amt&uid=ST9500325AS_S2WCPKTLXXXXS2WCPKTL&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1407110393&from=amt&uid=ST9500325AS_S2WCPKTLXXXXS2WCPKTL&q={searchTerms}),Ersetzt,[eb6ffd211d6dd95d5f61288df21315eb]
PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1407110393&from=amt&uid=ST9500325AS_S2WCPKTLXXXXS2WCPKTL, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/?type=hp&ts=1407110393&from=amt&uid=ST9500325AS_S2WCPKTLXXXXS2WCPKTL),Ersetzt,[b6a46bb395f564d23e81ffb631d436ca]
PUP.Optional.CalcIt.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://websearch.calcitapp.info/, Gut: (www.google.com), Schlecht: (hxxp://websearch.calcitapp.info/),Ersetzt,[8cceeb3393f7c2746491684c07fe35cb]
PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1407110393&from=amt&uid=ST9500325AS_S2WCPKTLXXXXS2WCPKTL&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://istart.webssearches.com/web/?type=ds&ts=1407110393&from=amt&uid=ST9500325AS_S2WCPKTLXXXXS2WCPKTL&q={searchTerms}),Ersetzt,[d486e8363c4e9f973aff93200302b050]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[203a4ad43456bf779c0117a89f66ce32]
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6XvwT609gzClVbU6TQmH5QwOJlslfhPmHJM-TdXDwoXa_-DI6585TEGEVmxrtqcM9STbWAxzEMLh3GkNQpqn16yPojUGXAtetG1_kIzqz4jhDmlGVbjH8AYU1FVXUUUJOQXLrtAALV_Z5RcVyfLG_dUjBMVRnBL4DqJEgOLpnoDtksZ8t6qzOWuzatoAU,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6XvwT609gzClVbU6TQmH5QwOJlslfhPmHJM-TdXDwoXa_-DI6585TEGEVmxrtqcM9STbWAxzEMLh3GkNQpqn16yPojUGXAtetG1_kIzqz4jhDmlGVbjH8AYU1FVXUUUJOQXLrtAALV_Z5RcVyfLG_dUjBMVRnBL4DqJEgOLpnoDtksZ8t6qzOWuzatoAU,&q={searchTerms}),Ersetzt,[78e215093b4f6ec81bac2293a65ff010]
PUP.Optional.CalcIt.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://websearch.calcitapp.info/, Gut: (www.google.com), Schlecht: (hxxp://websearch.calcitapp.info/),Ersetzt,[ea70f5298efc0531aa4cb9fbc24359a7]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6XvwT609gzClVbU6TQmH5QwOJlslfhPmHJM-TdXDwoXa_-DI6585TEGEVmxrtqcM9STbWAxzEMLh3GkNQpqn16yPojUGXAtetG1_kIzqz4jhDmlGVbjH8AYU1FVXUUUJOQXLrtAALV_Z5RcVyfLG_dUjBMVRnBL4DqJEgOLpnoDt7yuw3nLSeDImyh4Ek,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6XvwT609gzClVbU6TQmH5QwOJlslfhPmHJM-TdXDwoXa_-DI6585TEGEVmxrtqcM9STbWAxzEMLh3GkNQpqn16yPojUGXAtetG1_kIzqz4jhDmlGVbjH8AYU1FVXUUUJOQXLrtAALV_Z5RcVyfLG_dUjBMVRnBL4DqJEgOLpnoDt7yuw3nLSeDImyh4Ek,&q={searchTerms}),Ersetzt,[075335e9c9c18da9785400b5aa5b14ec]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6XvwT609gzClVbU6TQmH5QwOJlslfhPmHJM-TdXDwoXa_-DI6585TEGEVmxrtqcM9STbWAxzEMLh3GkNQpqn16yPojUGXAtetG1_kIzqz4jhDmlGVbjH8AYU1FVXUUUJOQXLrtAALV_Z5RcVyfLG_dUjBMVRnBL4DqJEgOLpnoDt7yuw3nLSeDImyh4Ek,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6XvwT609gzClVbU6TQmH5QwOJlslfhPmHJM-TdXDwoXa_-DI6585TEGEVmxrtqcM9STbWAxzEMLh3GkNQpqn16yPojUGXAtetG1_kIzqz4jhDmlGVbjH8AYU1FVXUUUJOQXLrtAALV_Z5RcVyfLG_dUjBMVRnBL4DqJEgOLpnoDt7yuw3nLSeDImyh4Ek,&q={searchTerms}),Ersetzt,[4218cc52ec9e4ee8f0dd5d5872931ce4]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-3031782414-876842572-2210241059-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6XvwT609gzClVbU6TQmH5QwOJlslfhPmHJM-TdXDwoXa_-DI6585TEGEVmxrtqcM9STbWAxzEMLh3GkNQpqn16yPojUGXAtetG1_kIzqz4jhDmlGVbjH8AYU1FVXUUUJOQXLrtAALV_Z5RcVyfLG_dUjBMVRnBL4DqJEgOLpnoDt7yuw3nLSeDImyh4Ek,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StKZmhdFMQ5NhCfKoItf6XvwT609gzClVbU6TQmH5QwOJlslfhPmHJM-TdXDwoXa_-DI6585TEGEVmxrtqcM9STbWAxzEMLh3GkNQpqn16yPojUGXAtetG1_kIzqz4jhDmlGVbjH8AYU1FVXUUUJOQXLrtAALV_Z5RcVyfLG_dUjBMVRnBL4DqJEgOLpnoDt7yuw3nLSeDImyh4Ek,&q={searchTerms}),Ersetzt,[93c752cc1179e74ffecadcd909fc9d63]
Ordner: 28
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\locales, In Quarantäne, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.InetStat.A, C:\Users\Royale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat, In Quarantäne, [a5b56eb01f6b56e01640e92de61f8779],
PUP.Optional.OpenCandy, C:\Users\Royale\AppData\Roaming\OpenCandy, In Quarantäne, [cf8bbc62bbcfcf6738ef035118ebe020],
PUP.Optional.OpenCandy, C:\Users\Royale\AppData\Roaming\OpenCandy\217583B4170746B5B60B3BDC69136402, In Quarantäne, [cf8bbc62bbcfcf6738ef035118ebe020],
PUP.Optional.OpenCandy, C:\Users\Royale\AppData\Roaming\OpenCandy\OpenCandy_217583B4170746B5B60B3BDC69136402, In Quarantäne, [cf8bbc62bbcfcf6738ef035118ebe020],
PUP.Optional.WeatherAlerts, C:\Users\Royale\AppData\Local\WeatherAlerts, In Quarantäne, [89d131ed4248fe38ff3592c4937052ae],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [560425f998f2af8737f7343563a0c43c],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [560425f998f2af8737f7343563a0c43c],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, In Quarantäne, [a5b58d910981b284e377b8b339ca43bd],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [a5b58d910981b284e377b8b339ca43bd],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [a5b58d910981b284e377b8b339ca43bd],
PUP.Optional.SystemSpeedup, C:\Users\Royale\AppData\Roaming\Systweak\ssd, In Quarantäne, [9fbb45d91c6e4fe710eb91dac83b3dc3],
PUP.Optional.MultiPlug.A, C:\ProgramData\cosstminn, In Quarantäne, [d38776a80684fd39f076c8a5b94a29d7],
PUP.Optional.MultiPlug.A, C:\Program Files (x86)\cosstminn, In Quarantäne, [e37769b5b9d145f16502e28bef146f91],
PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings, In Quarantäne, [77e38698365450e6d6d3620c5da642be],
PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings\SSL, In Quarantäne, [77e38698365450e6d6d3620c5da642be],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector, In Quarantäne, [2f2b5fbfb7d31c1a15c9482823e051af],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\2.1.1000.13665, In Quarantäne, [2f2b5fbfb7d31c1a15c9482823e051af],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\signatures, In Quarantäne, [2f2b5fbfb7d31c1a15c9482823e051af],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\updates, In Quarantäne, [2f2b5fbfb7d31c1a15c9482823e051af],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Royale\AppData\Roaming\Systweak\Advanced-System-Protector, In Quarantäne, [6af08c9299f14fe7af2f561a4eb5f20e],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Royale\AppData\Roaming\Systweak\Advanced-System-Protector\2.1.1000.13665, In Quarantäne, [6af08c9299f14fe7af2f561a4eb5f20e],
PUP.Optional.GenesisOffers, C:\Users\Royale\AppData\Local\Genesis_07251819, In Quarantäne, [95c587978604f343acec3c38857e10f0],
PUP.Optional.CouponArific, C:\Program Files\Couponarific, In Quarantäne, [adad5ac44347c2742738c0bf29dae51b],
PUP.Optional.CouponArific, C:\Program Files\Couponarific\SSL, In Quarantäne, [adad5ac44347c2742738c0bf29dae51b],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf, In Quarantäne, [61f93ce2c0ca1c1af55dff8342c1cb35],
PUP.Optional.AdPeak.A, C:\Program Files (x86)\0892CCEA-3029-46F2-BD98-F3177431F5F8, In Quarantäne, [d38749d5d4b654e2dc69f78e9b686c94],
Dateien: 56
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [f96128f64d3dd95d650481fc9e63ce32],
PUP.Optional.AdPeak.A, C:\Program Files\005\jxbalvtmyz64.exe, Löschen bei Neustart, [d78344da3654c571ef94a3f059acfd03],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\flowsurf.dll, In Quarantäne, [9dbd5cc2fb8fe650ffb076934ab9837d],
PUP.Optional.WindowsProtectManger.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, In Quarantäne, [ec6ea8768604c17580113d8c04fd57a9],
PUP.Optional.OpenCandy, C:\Users\Royale\AppData\Roaming\PowerISO\Upgrade\PowerISO5.exe, In Quarantäne, [0d4dec324f3b9b9bc052b630768fdd23],
PUP.Optional.Verti, C:\Users\Royale\Downloads\7zip_RocketFuelInstaller.exe, In Quarantäne, [8ecc40de7f0b1b1bbb29ec7d0cf9cf31],
PUP.Optional.FreeNew.A, C:\Users\Royale\Downloads\Razer_Game_Booster_downloader.exe, In Quarantäne, [2d2db16d3d4d68cea390231760a14cb4],
PUP.Optional.SmartBar, C:\Windows\Installer\MSID70A.tmp-\Smartbar.Installer.CustomActions.dll, In Quarantäne, [bd9d34ea4c3e6acc0090c66854ac867a],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\cef.pak, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\cef_100_percent.pak, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\cef_200_percent.pak, In Quarantäne, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitycheck.exe, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\compatibilitychecksvc.exe, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\d3dcompiler_46.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\debug.log, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\ffmpegsumo.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\icudtl.dat, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\libEGL.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\libGLESv2.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\NPSWF32_15_0_0_189.dll, Löschen bei Neustart, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.CompatibilityVerifier.A, C:\Users\Royale\AppData\Roaming\Compatibility Verifier\vcredist_x86.exe, In Quarantäne, [9fbb7aa4167462d4abb5d3c060a3718f],
PUP.Optional.InetStat.A, C:\Users\Royale\AppData\Roaming\InetStat\inetstat.exe, In Quarantäne, [302a948a0e7cc4721238c9d4d231cf31],
PUP.Optional.CalcIt.A, C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.calcitapp.info_0.localstorage, In Quarantäne, [0a50908efe8cc571b7387c3722e148b8],
PUP.Optional.CalcIt.A, C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_websearch.calcitapp.info_0.localstorage-journal, In Quarantäne, [91c9f628f09a340239b64c675ba81fe1],
PUP.Optional.YourfileDownloader.A, C:\Windows\System32\Tasks\YourFile DownloaderUpdate, In Quarantäne, [18428995d2b866d02e4b2293ad5623dd],
PUP.Optional.BetterDeals.A, C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage, In Quarantäne, [d486e23c7b0f3bfbd029a01aaf5415eb],
PUP.Optional.BetterDeals.A, C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal, In Quarantäne, [8ad0081691f99f97a851ae0c31d2f40c],
PUP.Optional.ReMarkable.A, C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, In Quarantäne, [e179041af5950531e156b65c0df8c53b],
PUP.Optional.ReMarkable.A, C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, In Quarantäne, [3723110d3b4f70c6a98ef12113f2728e],
PUP.Optional.InetStat.A, C:\Users\Royale\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat\InetStat.lnk, In Quarantäne, [a5b56eb01f6b56e01640e92de61f8779],
Malware.Trace.E, C:\Users\Royale\AppData\Roaming\die.bat, In Quarantäne, [db7fdb43c5c52511344249cd669f22de],
PUP.Optional.Adpeak.A, C:\Program Files (x86)\FF822B94-D02A-4A2C-BF00-D6D6A858F456\etmajyzoqm64.exe, In Quarantäne, [c59572acdcaebf7730447936fe054eb2],
PUP.Optional.CouponArific.A, C:\Program Files (x86)\0892CCEA-3029-46F2-BD98-F3177431F5F8\xtloowpkjv64.exe, In Quarantäne, [a8b262bcb5d577bfd9ace3ba19eafa06],
PUP.Optional.OpenCandy, C:\Users\Royale\AppData\Roaming\OpenCandy\217583B4170746B5B60B3BDC69136402\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, In Quarantäne, [cf8bbc62bbcfcf6738ef035118ebe020],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-07-25[20-17-26-517].log, In Quarantäne, [a5b58d910981b284e377b8b339ca43bd],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-08-04[02-00-39-118].log, In Quarantäne, [a5b58d910981b284e377b8b339ca43bd],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-08-04[02-00-40-886].log, In Quarantäne, [a5b58d910981b284e377b8b339ca43bd],
PUP.Optional.SystemSpeedup, C:\Users\Royale\AppData\Roaming\Systweak\ssd\SSDPTstub.exe, In Quarantäne, [9fbb45d91c6e4fe710eb91dac83b3dc3],
PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings\mfs2DF5.tmp, In Quarantäne, [77e38698365450e6d6d3620c5da642be],
PUP.Optional.Adpeak.A, C:\Program Files\AllDaySavings\mfs2E82.tmp, In Quarantäne, [77e38698365450e6d6d3620c5da642be],
PUP.Optional.AdvancedSystemProtector.A, C:\ProgramData\Systweak\Advanced-System-Protector\updates\1835completedatabase.zip, In Quarantäne, [2f2b5fbfb7d31c1a15c9482823e051af],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Royale\AppData\Roaming\Systweak\Advanced-System-Protector\QDetail.db, In Quarantäne, [6af08c9299f14fe7af2f561a4eb5f20e],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Royale\AppData\Roaming\Systweak\Advanced-System-Protector\Settings.db, In Quarantäne, [6af08c9299f14fe7af2f561a4eb5f20e],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Royale\AppData\Roaming\Systweak\Advanced-System-Protector\Update.ini, In Quarantäne, [6af08c9299f14fe7af2f561a4eb5f20e],
PUP.Optional.AdvancedSystemProtector.A, C:\Users\Royale\AppData\Roaming\Systweak\Advanced-System-Protector\2.1.1000.13665\ASPLog.txt, In Quarantäne, [6af08c9299f14fe7af2f561a4eb5f20e],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\atl110.dll, In Quarantäne, [61f93ce2c0ca1c1af55dff8342c1cb35],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\fsupd.exe, In Quarantäne, [61f93ce2c0ca1c1af55dff8342c1cb35],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\install.ico, In Quarantäne, [61f93ce2c0ca1c1af55dff8342c1cb35],
PUP.Optional.FlowSurf.A, C:\Program Files (x86)\Flowsurf\msvcr110.dll, In Quarantäne, [61f93ce2c0ca1c1af55dff8342c1cb35],
PUP.Optional.AdPeak.A, C:\Program Files (x86)\0892CCEA-3029-46F2-BD98-F3177431F5F8\64.ico, In Quarantäne, [d38749d5d4b654e2dc69f78e9b686c94],
PUP.Optional.AdPeak.A, C:\Program Files (x86)\0892CCEA-3029-46F2-BD98-F3177431F5F8\libeay32.dll, In Quarantäne, [d38749d5d4b654e2dc69f78e9b686c94],
PUP.Optional.AdPeak.A, C:\Program Files (x86)\0892CCEA-3029-46F2-BD98-F3177431F5F8\nfapi.dll, In Quarantäne, [d38749d5d4b654e2dc69f78e9b686c94],
PUP.Optional.AdPeak.A, C:\Program Files (x86)\0892CCEA-3029-46F2-BD98-F3177431F5F8\nfregdrv.exe, In Quarantäne, [d38749d5d4b654e2dc69f78e9b686c94],
PUP.Optional.AdPeak.A, C:\Program Files (x86)\0892CCEA-3029-46F2-BD98-F3177431F5F8\ProtocolFilters.dll, In Quarantäne, [d38749d5d4b654e2dc69f78e9b686c94],
PUP.Optional.AdPeak.A, C:\Program Files (x86)\0892CCEA-3029-46F2-BD98-F3177431F5F8\ssleay32.dll, In Quarantäne, [d38749d5d4b654e2dc69f78e9b686c94],
PUP.Optional.CalcIt.A, C:\Users\Royale\AppData\Roaming\Mozilla\Firefox\Profiles\21ddgmvy.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://websearch.calcitapp.info/");), Ersetzt,[5505c05e7a10c96d7bdba05b20e5ba46]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) und hier den ADwcleaner Log Code:
# AdwCleaner v4.110 - Bericht erstellt 14/02/2015 um 13:29:16
# Aktualisiert 05/02/2015 von Xplode
# Datenbank : 2015-02-14.2 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : Royale - ROYALE-PC
# Gestarted von : D:\Software\AdwCleaner_4.110.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : netfilter64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Systweak
Ordner Gelöscht : C:\ProgramData\5o0Coupoons
Ordner Gelöscht : C:\ProgramData\350ea50b1f65a54c
Ordner Gelöscht : C:\Program Files (x86)\Optimizer Pro
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Windows\SysWOW64\SearchProtect
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\torch
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\Gast\AppData\Local\torch
Ordner Gelöscht : C:\Users\Royale\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\Royale\AppData\Local\torch
Ordner Gelöscht : C:\Users\Royale\AppData\Local\RGMService
Ordner Gelöscht : C:\Users\Royale\AppData\Roaming\InetStat
Ordner Gelöscht : C:\Users\Royale\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Royale\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Royale\AppData\Roaming\YourFileDownloader
Ordner Gelöscht : C:\Users\Royale\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\Royale\AppData\Roaming\Mozilla\Firefox\Profiles\21ddgmvy.default\Extensions\2iaeuy1e8hh@kigg-dbaz.com
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Windows\System32\drivers\netfilter64.sys
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Mozilla\Firefox\Profiles\21ddgmvy.default\user.js
Datei Gelöscht : C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_click.dealshark.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_static.betterdeals00.betterdeals.co_0.localstorage
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_static.betterdeals00.betterdeals.co_0.localstorage-journal
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxps_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_static.re-markable00.re-markable.net_0.localstorage-journal
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxps_static.olark.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Local Storage\hxxp_click.dealshark.com_0.localstorage-journal
***** [ Geplante Tasks ] *****
Task Gelöscht : fsupdate
Task Gelöscht : YourFile DownloaderUpdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKCU\Software\Classes\Applications\inetstat.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\50Couuponss.50Couuponss
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\50Couuponss.50Couuponss.1.8
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3967C728-DE2C-BCB3-B369-635699792DDB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A8018C54-B702-4D52-9ACC-8CA78911E633}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C6A846C5-D67F-48B4-8552-C22354E56966}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3967C728-DE2C-BCB3-B369-635699792DDB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{3967C728-DE2C-BCB3-B369-635699792DDB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A8018C54-B702-4D52-9ACC-8CA78911E633}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C6A846C5-D67F-48B4-8552-C22354E56966}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\ContextFree
Schlüssel Gelöscht : HKCU\Software\genesis
Schlüssel Gelöscht : HKCU\Software\IGearSettings
Schlüssel Gelöscht : HKCU\Software\InetStat
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\YourFileDownloader
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Schlüssel Gelöscht : HKLM\SOFTWARE\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
Schlüssel Gelöscht : HKLM\SOFTWARE\YourFileDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\AllDaySavings
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v31.0 (x86 de)
[21ddgmvy.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.GqE.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"sumorobo.net[...]
[21ddgmvy.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.swchJu.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.indexOf(\"sumorobo.[...]
-\\ Google Chrome v36.0.1985.143
-\\ Comodo Dragon v
-\\ Opera v27.0.1689.69
-\\ Chrome Canary v
*************************
AdwCleaner[R0].txt - [10077 Bytes] - [14/02/2015 13:27:31]
AdwCleaner[S0].txt - [9265 Bytes] - [14/02/2015 13:29:16]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9324 Bytes] ########## hier den JRT log Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Royale on 14.02.2015 at 13:35:05,22
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Windows\wininit.ini"
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Royale\appdata\local\{01154F1A-4F2E-4EC0-B4C1-9AABDD3B9ADE}
Successfully deleted: [Empty Folder] C:\Users\Royale\appdata\local\{19203CB1-C2C0-4425-A6FB-F0942C8C3D62}
Successfully deleted: [Empty Folder] C:\Users\Royale\appdata\local\{653DE087-300F-47EA-9EF9-E4E78F815D7A}
Successfully deleted: [Empty Folder] C:\Users\Royale\appdata\local\{B327499A-D4A5-44C9-A6CE-7F4284BED1EF}
Successfully deleted: [Empty Folder] C:\Users\Royale\appdata\local\{BD7333B3-00BD-4091-BDFE-386ABD128770}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.02.2015 at 13:38:12,29
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und zu guter letzt den FRST log
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-02-2015
Ran by Royale (administrator) on ROYALE-PC on 14-02-2015 13:41:33
Running from D:\Software\FRST
Loaded Profiles: Royale (Available profiles: Royale)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
() C:\Program Files (x86)\Opera\27.0.1689.69\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\27.0.1689.69\opera.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1332296 2015-01-30] (Microsoft Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\...\Run: [BCSSync] => D:\Software\Microsoft Office professional\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => D:\Software\Microsoft Office professional\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => D:\Software\Microsoft Office professional\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => D:\Software\Microsoft Office professional\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => D:\Software\Microsoft Office professional\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => D:\Software\Microsoft Office professional\Office14\GROOVEEX.DLL (Microsoft Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3031782414-876842572-2210241059-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3031782414-876842572-2210241059-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> D:\Software\Microsoft Office professional\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Software\java\bin\ssv.dll No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Software\Microsoft Office professional\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Software\java\bin\jp2ssv.dll No File
Toolbar: HKU\S-1-5-21-3031782414-876842572-2210241059-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Royale\AppData\Roaming\Mozilla\Firefox\Profiles\21ddgmvy.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> D:\Software\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 -> D:\Software\java\bin\dtplugin\npDeployJava1.dll No File
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 -> D:\Software\java\bin\plugin2\npjp2.dll No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> D:\Software\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> D:\Software\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3031782414-876842572-2210241059-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Royale\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Extension: Adblock Plus - C:\Users\Royale\AppData\Roaming\Mozilla\Firefox\Profiles\21ddgmvy.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-08-09]
StartMenuInternet: FIREFOX.EXE - D:\Software\Firefox\firefox.exe
Chrome:
=======
CHR Profile: C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-08-15]
CHR Extension: (Google Drive) - C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-08-15]
CHR Extension: (YouTube) - C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-08-15]
CHR Extension: (Google Search) - C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-08-15]
CHR Extension: (Google Wallet) - C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-08-15]
CHR Extension: (Gmail) - C:\Users\Royale\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-08-15]
Opera:
=======
OPR Extension: (Adblock Plus) - C:\Users\Royale\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2014-08-15]
StartMenuInternet: (HKLM) Opera - D:\Software\Opera\Opera.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [867712 2011-01-05] (Acer Incorporated)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
R2 GREGService; C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [36456 2011-05-30] (Acer Incorporated)
S2 Live Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [244624 2011-04-22] (Acer Incorporated)
S3 Microsoft SharePoint Workspace Audit Service; D:\Software\Microsoft Office professional\Office14\GROOVE.EXE [30814400 2013-12-19] (Microsoft Corporation)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2015-01-30] (Microsoft Corporation)
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [366512 2015-01-30] (Microsoft Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [255744 2010-06-28] (NewTech Infosystems, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-06-03] (DT Soft Ltd)
S3 Impcd; C:\Windows\System32\DRIVERS\Impcd.sys [158976 2010-02-27] (Intel Corporation) [File not signed]
S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [317440 2011-08-23] (Intel(R) Corporation) [File not signed]
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [274696 2014-11-15] (Microsoft Corporation)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124560 2014-11-15] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 WinRing0_1_2_0; \??\D:\Software\Game Booster\Razer Game Booster\Driver\WinRing0x64.sys [X]
S3 X6va021; \??\C:\Windows\SysWOW64\Drivers\X6va021 [X]
S3 X6va022; \??\C:\Windows\SysWOW64\Drivers\X6va022 [X]
S3 X6va023; \??\C:\Windows\SysWOW64\Drivers\X6va023 [X]
S3 X6va025; \??\C:\Windows\SysWOW64\Drivers\X6va025 [X]
S3 X6va026; \??\C:\Windows\SysWOW64\Drivers\X6va026 [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-14 13:38 - 2015-02-14 13:38 - 00001220 _____ () C:\Users\Royale\Desktop\JRT.txt
2015-02-14 13:27 - 2015-02-14 13:29 - 00000000 ____D () C:\AdwCleaner
2015-02-14 12:28 - 2015-02-14 13:17 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-14 12:28 - 2015-02-14 12:28 - 00000738 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-14 12:28 - 2015-02-14 12:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-14 12:27 - 2015-02-14 12:27 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-14 12:27 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-14 12:27 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-14 12:27 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-13 14:31 - 2015-02-13 14:31 - 00036418 _____ () C:\ComboFix.txt
2015-02-13 14:07 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-13 14:07 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-13 14:07 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-13 14:07 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-13 14:07 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-13 14:07 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-13 14:07 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-13 14:07 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-13 14:06 - 2015-02-13 14:31 - 00000000 ____D () C:\Qoobox
2015-02-13 14:05 - 2015-02-13 14:29 - 00000000 ____D () C:\Windows\erdnt
2015-02-13 14:04 - 2015-02-13 14:04 - 05611771 ____R (Swearware) C:\Users\Royale\Desktop\ComboFix.exe
2015-02-12 18:29 - 2015-02-14 13:41 - 00000000 ____D () C:\FRST
2015-01-23 03:30 - 2015-02-01 22:08 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Compatibility Verifier
2015-01-23 03:30 - 2015-02-01 22:08 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Compatibility Verifier
2015-01-23 03:18 - 2015-01-23 03:18 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Adobe
2015-01-23 03:18 - 2015-01-23 03:18 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Adobe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-14 13:37 - 2009-07-14 05:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-14 13:37 - 2009-07-14 05:45 - 00024400 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-14 13:33 - 2013-05-09 19:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-14 13:30 - 2014-09-01 13:31 - 00036874 _____ () C:\Windows\PFRO.log
2015-02-14 13:30 - 2014-09-01 13:31 - 00014280 _____ () C:\Windows\setupact.log
2015-02-14 13:30 - 2013-05-26 21:16 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-14 13:30 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-14 13:29 - 2013-05-09 16:43 - 01604335 _____ () C:\Windows\WindowsUpdate.log
2015-02-14 13:12 - 2013-05-26 21:16 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-14 13:08 - 2014-08-04 01:03 - 00000000 ____D () C:\Program Files\005
2015-02-14 13:07 - 2014-08-04 01:05 - 00000000 ____D () C:\Program Files (x86)\FF822B94-D02A-4A2C-BF00-D6D6A858F456
2015-02-14 12:12 - 2013-05-09 18:12 - 00000000 ____D () C:\Users\Royale\AppData\Roaming\AIMP3
2015-02-13 14:31 - 2013-05-25 11:38 - 00000000 ____D () C:\Users\Royale\AppData\Local\Apps\2.0
2015-02-13 14:31 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-02-13 14:26 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-02-13 14:23 - 2013-06-13 10:23 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-02-13 14:23 - 2009-07-14 03:34 - 00000478 _____ () C:\Windows\win.ini
2015-02-13 14:19 - 2013-05-09 20:58 - 00002155 _____ () C:\Windows\epplauncher.mif
2015-02-13 14:19 - 2013-05-09 20:58 - 00002129 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-02-13 14:18 - 2013-08-16 01:14 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-13 14:18 - 2013-05-09 20:57 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-02-13 14:18 - 2013-05-09 20:57 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2015-02-13 14:06 - 2013-05-09 20:36 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-02-12 18:41 - 2013-06-16 12:47 - 00000000 ____D () C:\ProgramData\boost_interprocess
2015-02-12 17:44 - 2013-05-26 12:35 - 00000000 ____D () C:\Users\Royale\AppData\Roaming\uTorrent
2015-02-12 16:23 - 2015-01-13 14:33 - 00000112 _____ () C:\ProgramData\tQ0PhRps.dat
2015-02-12 09:32 - 2014-08-15 00:06 - 00003854 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1408057574
2015-02-12 09:32 - 2014-08-15 00:06 - 00000000 ____D () C:\Program Files (x86)\Opera
2015-02-12 09:30 - 2013-05-09 19:04 - 00767152 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-12 09:30 - 2013-05-09 19:04 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-12 09:30 - 2011-10-28 14:58 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-16 00:05 - 2013-05-25 11:38 - 00000000 ____D () C:\Users\Royale\AppData\Local\Deployment
==================== Files in the root of some directories =======
2014-12-22 12:35 - 2014-12-22 12:35 - 0000017 _____ () C:\Users\Royale\AppData\Local\resmon.resmoncfg
2013-06-14 08:39 - 2013-06-14 08:39 - 0000032 _____ () C:\ProgramData\Temp.log
2015-01-13 14:33 - 2015-02-12 16:23 - 0000112 _____ () C:\ProgramData\tQ0PhRps.dat
Files to move or delete:
====================
C:\ProgramData\tQ0PhRps.dat
Some content of TEMP:
====================
C:\Users\Royale\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-09 14:01
==================== End Of Log ============================ --- --- --- |