Fenomeen schreef:
Hier posten mag ook, dat heeft als voordeel dat anderen mee kunnen kijken.
# AdwCleaner v6.047 - Logfile created 25/05/2017 at 01:31:12
# Updated on 19/05/2017 by Malwarebytes
# Database : 2017-05-23.1 [Server]
# Operating System : Windows 10 Pro (X64)
# Username : asus - DESKTOP-E520PGM
# Running from : C:\Users\asus\Downloads\adwcleaner_6.047.exe
# Mode: Scan
# Support :
https://www.malwarebytes.com/support" onclick="window.open(this.href);return false;
***** [ Services ] *****
Service Found: rtop
Service Found: ByteFenceService
***** [ Folders ] *****
Folder Found: C:\Users\asus\AppData\Local\PRO_PC_Cleaner
Folder Found: C:\Users\asus\AppData\Roaming\PRO PC Cleaner
Folder Found: C:\Users\asus\AppData\Roaming\System Monitor
Folder Found: C:\Users\asus\AppData\Roaming\PC Purifier
Folder Found: C:\Users\asus\Documents\PROPCCleaner
Folder Found: C:\Program Files\ByteFence
Folder Found: C:\Program Files\DriverSetupUtility
Folder Found: C:\ProgramData\ByteFence
Folder Found: C:\ProgramData\DriverSetupUtility
Folder Found: C:\ProgramData\Application Data\ByteFence
Folder Found: C:\ProgramData\Application Data\DriverSetupUtility
Folder Found: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ByteFence Anti-Malware
Folder Found: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCPurifier
Folder Found: C:\Program Files (x86)\PCPurifier
Folder Found: C:\Users\asus\AppData\Roaming\System Monitor
***** [ Files ] *****
File Found: C:\Users\asus\Downloads\ReimageRepair.exe
File Found: C:\Users\asus\AppData\Roaming\Mozilla\Firefox\Profiles\7is6nz7f.default\searchplugins\palikan.xml
***** [ DLL ] *****
No malicious DLLs found.
***** [ WMI ] *****
No malicious keys found.
***** [ Shortcuts ] *****
No infected shortcut found.
***** [ Scheduled Tasks ] *****
Task Found: RunAtStartup
Task Found: ByteFence
Task Found: ByteFence Scan
***** [ Registry ] *****
Key Found: HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\ByteFenceService
Key Found: [x64] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\ByteFenceService
Key Found: HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
Key Found: HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
Key Found: HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
Key Found: HKU\S-1-5-21-2595908697-2543972565-3071100823-1001\Software\ByteFence
Key Found: HKU\S-1-5-21-2595908697-2543972565-3071100823-1001\Software\CoinisRevShare
Key Found: HKU\S-1-5-21-2595908697-2543972565-3071100823-1001\Software\PRODUCTSETUP
Key Found: HKU\S-1-5-21-2595908697-2543972565-3071100823-1001\Software\csastats
Key Found: HKU\S-1-5-21-2595908697-2543972565-3071100823-1001\Software\System Monitor
Key Found: HKU\S-1-5-21-2595908697-2543972565-3071100823-1001\Software\PC Purifier
Key Found: HKCU\Software\ByteFence
Key Found: HKCU\Software\CoinisRevShare
Key Found: HKCU\Software\PRODUCTSETUP
Key Found: HKCU\Software\csastats
Key Found: HKCU\Software\System Monitor
Key Found: HKCU\Software\PC Purifier
Key Found: HKLM\SOFTWARE\ByteFence
Key Found: HKLM\SOFTWARE\Jawego
Key Found: HKLM\SOFTWARE\System Monitor
Key Found: HKLM\SOFTWARE\PC Purifier
Key Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ByteFence
Key Found: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCPurifier_is1
Key Found: [x64] HKCU\Software\ByteFence
Key Found: [x64] HKCU\Software\CoinisRevShare
Key Found: [x64] HKCU\Software\PRODUCTSETUP
Key Found: [x64] HKCU\Software\csastats
Key Found: [x64] HKCU\Software\System Monitor
Key Found: [x64] HKCU\Software\PC Purifier
Key Found: [x64] HKLM\SOFTWARE\ByteFence
Key Found: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}
Key Found: HKLM\SOFTWARE\Classes\Installer\Features\A38C15B2D5649AE4C9CDE19DE50DA96C
Key Found: HKLM\SOFTWARE\Classes\Installer\Products\A38C15B2D5649AE4C9CDE19DE50DA96C
Key Found: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A38C15B2D5649AE4C9CDE19DE50DA96C
Key Found: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A38C15B2D5649AE4C9CDE19DE50DA96C
Key Found: [x64] HKLM\SOFTWARE\Classes\Installer\Features\A38C15B2D5649AE4C9CDE19DE50DA96C
Key Found: [x64] HKLM\SOFTWARE\Classes\Installer\Products\A38C15B2D5649AE4C9CDE19DE50DA96C
Data Found: HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://
www.palikan.com/?f=1&a=plk_coinisre_17_ ... 2XzutAtFtB" onclick="window.open(this.href);return false;
Data Found: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://
www.palikan.com/?f=1&a=plk_coinisre_17_ ... 1L2XzutAtF" onclick="window.open(this.href);return false;
Key Found: HKU\S-1-5-21-2595908697-2543972565-3071100823-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Data Found: HKU\S-1-5-21-2595908697-2543972565-3071100823-1001\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] -
Key Found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Data Found: HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] -
Key Found: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Data Found: HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] -
Key Found: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Data Found: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] -
Key Found: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Data Found: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] -
Key Found: HKLM\SOFTWARE\Classes\Directory\shell\ByteFence Folder Scan
Key Found: HKLM\SOFTWARE\Classes\*\shell\ByteFence File Scan
***** [ Web browsers ] *****
Firefox pref Found: [C:\Users\asus\AppData\Roaming\Mozilla\Firefox\Profiles\7is6nz7f.default\prefs.js] - "browser.search.defaultenginename" - "Palikan"
Firefox pref Found: [C:\Users\asus\AppData\Roaming\Mozilla\Firefox\Profiles\7is6nz7f.default\prefs.js] - "browser.search.hiddenOneOffs" - "Yahoo,Amazon.com,Bing,DuckDuckGo,Google Default,Palikan,พจนานุกรม ลองดู,วิกิพีเดี
Firefox pref Found: [C:\Users\asus\AppData\Roaming\Mozilla\Firefox\Profiles\7is6nz7f.default\prefs.js] - "browser.search.selectedEngine" - "Palikan"
Chrome pref Found: [C:\Users\asus\AppData\Local\Chromium\User Data\Default\Web data] - palikan
Chrome pref Found: [C:\Users\asus\AppData\Local\Chromium\User Data\Default\Secure Preferences] - hxxp://
www.palikan.com/?f=7&a=plk_coinisre_17_ ... u0StCzytBt" onclick="window.open(this.href);return false;
Chrome pref Found: [C:\Users\asus\AppData\Local\Chromium\User Data\Default\Secure Preferences ] - hxxp://
www.palikan.com/?f=1&a=plk_coinisre_17_ ... zu0StCzytB" onclick="window.open(this.href);return false;
[!] You may need to disable the Chrome synchronization from your Google account in order to fully remove the malicious preferences. Please consult this Google help:
https://support.google.com/chrome/answer/3097271?hl=en" onclick="window.open(this.href);return false; [!]
*************************
C:\AdwCleaner\AdwCleaner[S0].txt - [7423 Bytes] - [25/05/2017 01:31:12]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7496 Bytes] ##########