thank your for the help.
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2016-10-16
Scan Time: 20:31
Logfile: 2016_10_16_AP_Logs.txt
Administrator: Yes
Version: 2.2.1.1043
Malware Database: v2016.10.16.07
Rootkit Database: v2016.09.26.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: ...
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 315005
Time Elapsed: 12 min, 51 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.Elex, C:\ProgramData\UvConverter\UvConverter.exe, 1960, Delete-on-Reboot, [e9fe4e4b9bff0e28ec1f7487de2608f8]
Modules: 0
(No malicious items detected)
Registry Keys: 2
PUP.Optional.SpyHunter, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ESGSCANNER, Quarantined, [af38f4a5f6a4e155d090eb1c1ce9d927],
PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UVCONVERTER, Quarantined, [e9fe4e4b9bff0e28ec1f7487de2608f8],
Registry Values: 2
PUP.Optional.SpyHunter, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ESGSCANNER|ImagePath, system32\DRIVERS\EsgScanner.sys, Quarantined, [af38f4a5f6a4e155d090eb1c1ce9d927]
PUP.Optional.Elex, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\UVCONVERTER|ImagePath, "C:\ProgramData\UvConverter\UvConverter.exe" {2C8E8C85-942B-451C-8243-97A089265577}, Quarantined, [e9fe4e4b9bff0e28ec1f7487de2608f8]
Registry Data: 6
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "c:\program files (x86)\mozilla firefox\firefox.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385, Good: (firefox.exe), Bad: ("c:\program files (x86)\mozilla firefox\firefox.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385),Replaced,[b532128772281a1cb4a9896b9c687e82]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\GOOGLE CHROME\SHELL\OPEN\COMMAND, "c:\program files (x86)\google\chrome\application\chrome.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385, Good: (Chrome.exe), Bad: ("c:\program files (x86)\google\chrome\application\chrome.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385),Replaced,[27c091084852ba7cd98020d410f4df21]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, "c:\program files\internet explorer\iexplore.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385, Good: (iexplore.exe), Bad: ("c:\program files\internet explorer\iexplore.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385),Replaced,[d80f9108faa0aa8cd18bb73dfc08ed13]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "c:\program files (x86)\mozilla firefox\firefox.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385, Good: (firefox.exe), Bad: ("c:\program files (x86)\mozilla firefox\firefox.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385),Replaced,[eafd44552377dc5afd60995b49bb37c9]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\GOOGLE CHROME\SHELL\OPEN\COMMAND, "c:\program files (x86)\google\chrome\application\chrome.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385, Good: (Chrome.exe), Bad: ("c:\program files (x86)\google\chrome\application\chrome.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385),Replaced,[67803069dbbfb284e27739bb35cf07f9]
PUP.Optional.MyLucky123.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, "c:\program files\internet explorer\iexplore.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385, Good: (iexplore.exe), Bad: ("c:\program files\internet explorer\iexplore.exe" http://www.mylucky123.com/?type=sc&ts=1476185471&z=54eaa1be23f6bae3c90612ag3z3m2qfg6b3wez2mfo&from=che0812&uid=SAMSUNGXMZ7LN256HCHP-000L7_S20HNXAH120385),Replaced,[cd1af4a5eab071c51d3f777dae565aa6]
Folders: 2
PUP.Optional.PriceFountain, C:\Users\...\AppData\Roaming\PriceFountainUpdateVer, Quarantined, [e403a4f5e1b96fc727720db946bc51af],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
Files: 29
PUP.Optional.ProductKeyFinder, C:\Users\...\AppData\Roaming\Skype\My Skype Received Files\produkey-x64.zip, Quarantined, [4c9bb5e4306ae94dea4da1af33ce649c],
PUP.Optional.BundleInstaller, C:\Users\...\Downloads\Adobe-Flash-Player-13091-dp.exe, Quarantined, [d80fa6f3841662d47dd3c787ad537e82],
PUP.Optional.InstallCore, C:\Users\...\Downloads\DAEMON-Tools-Lite-12708-dp.exe, Quarantined, [1ccb3b5e801a69cd477ee308ee1317e9],
PUP.Optional.InstallCore, C:\Users\...\Downloads\pobierz_Windows_movie_maker_V16.4.3528.331.exe, Quarantined, [7077a7f20f8b6cca15b241ead22f4cb4],
PUP.Optional.Linkury, C:\Users\...\AppData\Roaming\md.xml, Quarantined, [549329706e2c52e4c881e40ba360e21e],
PUP.Optional.Linkury, C:\Users\...\AppData\Roaming\noah.dat, Quarantined, [984f8613584281b570da846b689b21df],
PUP.Optional.Linkury, C:\Users\...\AppData\Roaming\inst.lat, Quarantined, [3bac4f4aa8f2270f97994badea19c43c],
PUP.Optional.Linkury.Gen, C:\Users\...\AppData\Roaming\Greenhold.tst, Quarantined, [37b03465f2a8bc7afb00d824a65de51b],
PUP.Optional.Linkury.Gen, C:\Users\...\AppData\Roaming\KeyJaylab.tst, Quarantined, [df08762363370531f2098f6dc24119e7],
PUP.Optional.SpyHunter, C:\Windows\System32\drivers\EsgScanner.sys, Quarantined, [af38f4a5f6a4e155d090eb1c1ce9d927],
PUP.Optional.Elex, C:\ProgramData\UvConverter\UvConverter.exe, Delete-on-Reboot, [e9fe4e4b9bff0e28ec1f7487de2608f8],
PUP.Optional.PriceFountain, C:\Users\...\AppData\Roaming\PriceFountainUpdateVer\config.dat, Quarantined, [e403a4f5e1b96fc727720db946bc51af],
PUP.Optional.PriceFountain, C:\Users\...\AppData\Roaming\PriceFountainUpdateVer\info.dat, Quarantined, [e403a4f5e1b96fc727720db946bc51af],
PUP.Optional.PriceFountain, C:\Users\...\AppData\Roaming\PriceFountainUpdateVer\STTL.DAT, Quarantined, [e403a4f5e1b96fc727720db946bc51af],
PUP.Optional.PriceFountain, C:\Users\...\AppData\Roaming\PriceFountainUpdateVer\TTL.DAT, Quarantined, [e403a4f5e1b96fc727720db946bc51af],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\Rkey.dat, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\allegro.pl .lnk, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\allegro.pl.ico, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\allegro.pl.lnk, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\allegro.pl.smenu.URL, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\allegro.pl.tbar.URL, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\Booking .lnk, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\Booking.ico, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\Booking.lnk, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\Booking.smenu.URL, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\Booking.tbar.URL, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.PriceFountain.Gen, C:\Users\...\AppData\Local\SnobbierEnticement\VigilantnessFlattening.dat, Quarantined, [c126dfbaa5f582b42dabb2e9cf35936d],
PUP.Optional.Linkury.ACMB1, C:\Users\...\AppData\Roaming\Config.xml, Quarantined, [ca1da2f7f1a9d95d792f1e7e867e4eb2],
PUP.Optional.Linkury.ACMB1, C:\Users\...\AppData\Roaming\InstallationConfiguration.xml, Quarantined, [e106e7b2cfcb2f07248565374cb80ef2],
Physical Sectors: 0
(No malicious items detected)
(end)