Virus
Når jeg er op internettet med min Crome browse hopper siden hele tiden over op en reklameside. :(Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Dato: 29-03-2015
Scan Tid: 15:28:37
Logfil: scan log.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Database: v2015.03.29.04
Rootkit Database: v2015.03.26.01
Licens: Retssag
Malware Protection: Aktiveret
Ondsindet Hjemmeside Beskyttelse: Aktiveret
Selvbeskyttelse: Handicappede
OS: Windows 8.1
CPU: x64
Fil system: NTFS
Bruger: Palle
Scan Type: Trussel Scanning
Resultater: Fuldført
Objekter Scannet: 361560
Forløbet Tid: 23 min, 57 sek
Hukommelse: Aktiveret
Startop: Aktiveret
Filsystem: Aktiveret
Arkiver: Aktiveret
Rootkits: Handicappede
Heuristics: Aktiveret
PUP: Aktiveret
PUM: Aktiveret
Processer: 0
(Ingen skadelige varer fundet)
Moduler: 0
(Ingen skadelige varer fundet)
Nøgle Register: 36
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{22a6c934-9b90-433d-a430-9175d4d2da83}, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{22A6C934-9B90-433D-A430-9175D4D2DA83}, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P22a6c934_9b90_433d_a430_9175d4d2da83_.P22a6c934_9b90_433d_a430_9175d4d2da83_, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\P22a6c934_9b90_433d_a430_9175d4d2da83_.P22a6c934_9b90_433d_a430_9175d4d2da83_.9, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P22a6c934_9b90_433d_a430_9175d4d2da83_.P22a6c934_9b90_433d_a430_9175d4d2da83_, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P22a6c934_9b90_433d_a430_9175d4d2da83_.P22a6c934_9b90_433d_a430_9175d4d2da83_.9, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P22a6c934_9b90_433d_a430_9175d4d2da83_.P22a6c934_9b90_433d_a430_9175d4d2da83_, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\P22a6c934_9b90_433d_a430_9175d4d2da83_.P22a6c934_9b90_433d_a430_9175d4d2da83_.9, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{22A6C934-9B90-433D-A430-9175D4D2DA83}, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{22A6C934-9B90-433D-A430-9175D4D2DA83}, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{22A6C934-9B90-433D-A430-9175D4D2DA83}\INPROCSERVER32, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{ff8890b2-568b-4ec4-9cec-1d45c78d5751}, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{FF8890B2-568B-4EC4-9CEC-1D45C78D5751}, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\Pff8890b2_568b_4ec4_9cec_1d45c78d5751_.Pff8890b2_568b_4ec4_9cec_1d45c78d5751_, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\Pff8890b2_568b_4ec4_9cec_1d45c78d5751_.Pff8890b2_568b_4ec4_9cec_1d45c78d5751_.9, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Pff8890b2_568b_4ec4_9cec_1d45c78d5751_.Pff8890b2_568b_4ec4_9cec_1d45c78d5751_, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Pff8890b2_568b_4ec4_9cec_1d45c78d5751_.Pff8890b2_568b_4ec4_9cec_1d45c78d5751_.9, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Pff8890b2_568b_4ec4_9cec_1d45c78d5751_.Pff8890b2_568b_4ec4_9cec_1d45c78d5751_, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\WOW6432NODE\Pff8890b2_568b_4ec4_9cec_1d45c78d5751_.Pff8890b2_568b_4ec4_9cec_1d45c78d5751_.9, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FF8890B2-568B-4EC4-9CEC-1D45C78D5751}, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{FF8890B2-568B-4EC4-9CEC-1D45C78D5751}, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.Multiplug, HKLM\SOFTWARE\CLASSES\CLSID\{FF8890B2-568B-4EC4-9CEC-1D45C78D5751}\INPROCSERVER32, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\20891, Karantæne, [7dcb71da8802072f7135a05c877cf30d],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Karantæne, [83c595b679110a2cb26936f4986d46ba],
PUP.Optional.ISearch.A, HKLM\SOFTWARE\WOW6432NODE\omiga-plusSoftware, Karantæne, [f751242792f80f272e3af343798c8878],
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\WOW6432NODE\INSTALLEDBROWSEREXTENSIONS\20891, Karantæne, [ad9b22297d0d90a606a0a755d72cf30d],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Karantæne, [48007bd07812a78f8596aa8063a240c0],
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS, Karantæne, [21273c0ffb8f8fa7b122d87292735ea2],
PUP.Optional.GeForce.A, HKU\S-1-5-18\SOFTWARE\Ge-Force-nv, Karantæne, [f355d7743e4cde5812213e0dae5749b7],
PUP.Optional.SavePass.A, HKU\S-1-5-18\SOFTWARE\SavePass 1.1-nv, Karantæne, [dd6b5dee5a30c96d0bd9ebf1946fcd33],
PUP.Optional.SavePass.A, HKU\S-1-5-18\SOFTWARE\APPDATALOW\SOFTWARE\SavePass 1.1, Karantæne, [54f491ba1d6d94a2469f26b6b0537987],
PUP.Optional.Tuto4PC.A, HKU\S-1-5-21-705963267-493827480-734421500-1001\SOFTWARE\TutoTag, Karantæne, [4dfb75d603873cfa032d063baf56ae52],
PUP.Optional.BlockAndSurf.A, HKU\S-1-5-21-705963267-493827480-734421500-1001\SOFTWARE\APPDATALOW\SOFTWARE\BlockAndSurf, Karantæne, [97b1c18a7e0cb87e7015ffe0c63de818],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-705963267-493827480-734421500-1001\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Karantæne, [cb7d72d94d3d90a6f9bba88acc39ae52],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-705963267-493827480-734421500-1001\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\20891, Karantæne, [03458ac14743310535ba9c3a2cd753ad],
PUP.Optional.Qone8, HKU\S-1-5-21-705963267-493827480-734421500-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Karantæne, [a3a598b3b7d3c47256c445e54db86a96],
Værdi Register: 2
PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_pl_39, Karantæne, [d276113ad7b380b6fdf94881cc375aa6],
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS|HostGUID, 64EBB389-56EE-4801-B712-1CAA1D3931A8, Karantæne, [21273c0ffb8f8fa7b122d87292735ea2]
Data Register: 13
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851, Godt:)iexplore.exe), Bad:)C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851),Erstattet,[d2769facb8d20c2ae455a3579c697a86]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://isearch.omiga-plus.com/web/?type=ds&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851&q={searchTerms}, Godt:)www.google.com), Bad:)http://isearch.omiga-plus.com/web/?type=ds&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851&q={searchTerms}),Erstattet,[3711e96265252a0cd765df1bb055bc44]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851, Godt:)www.google.com), Bad:)http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851),Erstattet,[73d574d723672313a19b26d4ea1b4eb2]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851, Godt:)www.google.com), Bad:)http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851),Erstattet,[f850c2894743c96dea5213e7ef16f709]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://isearch.omiga-plus.com/web/?type=ds&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851&q={searchTerms}, Godt:)www.google.com), Bad:)http://isearch.omiga-plus.com/web/?type=ds&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851&q={searchTerms}),Erstattet,[0a3e3417bbcf2b0b1c2041b9ad58b947]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Godt:){0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad:){33BB0A4E-99AF-4226-BDF6-49120163DE86}),Erstattet,[4107e3682e5c51e501b4ea0ea65f41bf]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851, Godt:)iexplore.exe), Bad:)C:\Program Files\Internet Explorer\iexplore.exe http://isearch.omiga-plus.com/?type=sc&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851),Erstattet,[1236ec5fbcce1e18b38602f8f4117a86]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, http://isearch.omiga-plus.com/web/?type=ds&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851&q={searchTerms}, Godt:)www.google.com), Bad:)http://isearch.omiga-plus.com/web/?type=ds&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851&q={searchTerms}),Erstattet,[fb4dc388becc7eb88eae26d43acb926e]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851, Godt:)www.google.com), Bad:)http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851),Erstattet,[c28694b74f3b31058cb0b941e223619f]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851, Godt:)www.google.com), Bad:)http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851),Erstattet,[ba8e6edd0f7b8da9f646ad4d52b350b0]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, http://isearch.omiga-plus.com/web/?type=ds&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851&q={searchTerms}, Godt:)www.google.com), Bad:)http://isearch.omiga-plus.com/web/?type=ds&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851&q={searchTerms}),Erstattet,[42069ead3b4fdc5a38041fdb17eeb64a]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Godt:){0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad:){33BB0A4E-99AF-4226-BDF6-49120163DE86}),Erstattet,[72d6ed5e1c6e42f414a141b739cc4ab6]
PUP.Optional.OmigaPlus.A, HKU\S-1-5-21-705963267-493827480-734421500-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851, Godt:)www.google.com), Bad:)http://isearch.omiga-plus.com/?type=hp&ts=1422468915&from=obw&uid=WDCXWD10JPVX-22JC3T0_WD-WX21A54N3851N3851),Erstattet,[f75171da7218da5cf44258a2be475ba5]
Mapper: 8
PUP.Optional.CoolnCheap.A, C:\Program Files (x86)\coolncheaP, Karantæne, [3c0ce36898f21026ba013877e122966a],
PUP.Optional.OfferApp.A, C:\Program Files (x86)\offeraPp, Karantæne, [82c6c58607837fb7498a555d3ec54bb5],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\installer, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\language, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\logs, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\scan_results, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\swf, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
Filer: 23
PUP.Optional.Multiplug, C:\Program Files (x86)\browsEeAndsehhop\Goh5P7Qk5D4cOJ.x64.dll, Karantæne, [2e1aaba0f09ae353139cef49bc46c937],
PUP.Optional.Multiplug, C:\Program Files (x86)\salepriazEs\3BBPgjpSLlmmaC.x64.dll, Karantæne, [4404cf7cd1b968ce9a15d7614fb3827e],
PUP.Optional.AnyProtect.A, C:\Windows\Tasks\APSnotifierPP1.job, Karantæne, [b98f85c64644af878353e0d55aa98977],
PUP.Optional.AnyProtect.A, C:\Windows\Tasks\APSnotifierPP2.job, Karantæne, [dc6c113adfab6acc19bdeacb38cb619f],
PUP.Optional.AnyProtect.A, C:\Windows\Tasks\APSnotifierPP3.job, Karantæne, [c088004b6b1f90a69046cde8976c5ba5],
PUP.Optional.AnyProtect.A, C:\Windows\System32\Tasks\APSnotifierPP1, Karantæne, [3c0c0d3ec1c9d660d502bcf96b9802fe],
PUP.Optional.AnyProtect.A, C:\Windows\System32\Tasks\APSnotifierPP2, Karantæne, [e95fc586c8c2a3934295caeb3dc652ae],
PUP.Optional.AnyProtect.A, C:\Windows\System32\Tasks\APSnotifierPP3, Karantæne, [8cbc71dae1a9f1453c9b5461b94a867a],
PUP.Optional.Patsearch.A, C:\Windows\patsearch.bin, Karantæne, [74d4f4578dfdd85e91f421a2b44f649c],
PUP.Optional.WebInstr.A, C:\Windows\System32\drivers\Msft_Kernel_webinstrNHKT_01009.Wdf, Karantæne, [e662c08bc6c4f442564b0db7d033d22e],
PUP.Optional.SmartWeb.A, C:\Users\Palle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SmartWeb.lnk, Karantæne, [95b370db602a83b3eea602c9ba497888],
PUP.Optional.CoolnCheap.A, C:\Program Files (x86)\coolncheaP\coolncheaP.dat, Karantæne, [3c0ce36898f21026ba013877e122966a],
PUP.Optional.OfferApp.A, C:\Program Files (x86)\offeraPp\offeraPp.dat, Karantæne, [82c6c58607837fb7498a555d3ec54bb5],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\installer\ab.test.json, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\installer\tempfile.t, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\language\de.xml, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\language\en.xml, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\language\fr.xml, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\scan_results\aps.scan.quick.results, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\scan_results\aps.scan.results, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\swf\mov01.swf, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.AnyProtect.A, C:\Users\Palle\AppData\Roaming\AnyProtectEx\swf\swfkm.swf, Karantæne, [fe4ae764305a0432b34d3184b44f9d63],
PUP.Optional.Conduit.A, C:\Users\Palle\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences, Godt:)), Bad:) "homepage": "http://search.conduit.com/?gd=&ctid=CT3324774&octid=EB_ORIGINAL_CTID&ISID=&SearchSource=55&CUI=&UM=5&UP=SP0118484C-DF4C-4C7C-86CB-199B081DD2F9&SSPV=",), Erstattet,[1434113a7911f73f56d7d067f90d4bb5]
Fysiske sektorer: 0
(Ingen skadelige varer fundet)
(end)
Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 18:08:25, on 29-03-2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.17416)
Boot mode: Normal
Running processes:
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerWinMonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\Palle\Downloads\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.dk/?gws_rd=cr,ssl&ei=hvvNVKOXHcnWPd-UgMAP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O4 - HKLM\..\Run: [Adobe ARM] "c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_C3D53B47DB75A5BED553A5280CFAD082] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
O8 - Extra context menu item: E&ksportér til Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: S&end til OneNote - res://C:\PROGRA~1\MICROS~1\Office15\ONBttnIE.dll/105
O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Klik for at ringe op - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Klik for at ringe op - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: &Sammenkædede OneNote-noter - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Sammenkædede OneNote-noter - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Windows (R) Win 7 DDK provider - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Tjeneste (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Tjeneste (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Launch Manager Service (LMSvc) - Acer Incorporate - C:\Program Files\Packard Bell\Packard Bell Launch Manager\LMSvc.exe
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Quick Access Service (QASvc) - Acer Incorporate - C:\Program Files\Packard Bell\Packard Bell Quick Access\QASvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: Quick Access RadioMgr Service (RMSvc) - Acer Incorporate - C:\Program Files\Packard Bell\Packard Bell Quick Access\RMSvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 9356 bytes