![]() |
|
Log-Analyse und Auswertung: Windows 7 "beschädigt" nach Bereinigung mit MWB AntimalwareWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Windows 7 "beschädigt" nach Bereinigung mit MWB Antimalware Hallo Leutz, ich habe ein Problem auf dem Notebook eines Bekannten (Win7 HP). Ich sollte das Windows auf Schad- bzw. Nerv-Software überprüfen und das erste Tool meiner Wahl in so einem Fall ist immer Malwarebytes Antimalware - das hat, zumindest als Erst-Reinigungstool, immer gut funktioniert. Nun tauchte aber nach der Bereinigung zum ersten Mal ein Problem auf, das vor der Bereinigung nicht bestand: Der Aufgabenplanungsdienst wollte nicht mehr starten, was sich durch diverse Fehlermeldungen nach dem Neustart sofort bemerkbar machte. Ich habe dann das Protokoll von Malwarebytes Antimalware durchgeschaut, konnte aber nichts Signifikantes entdecken. Erst nach dem Restore aller von Antimalware durchgeführten Änderungen startete der Aufgabenplanungsdienst wieder normal. Nun steh ich etwas auf dem Schlauch - könnt ihr mir helfen? Hier mal das Log von Antimalware: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 11.04.2015 Scan Time: 09:29:22 Logfile: mwb.txt Administrator: Yes Version: 2.00.4.1028 Malware Database: v2015.04.11.01 Rootkit Database: v2015.03.31.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: <Benutzer> Scan Type: Threat Scan Result: Completed Objects Scanned: 399257 Time Elapsed: 14 min, 5 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 1 PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia.exe, 3700, , [143972f9800abe78698b298d4db67f81] Modules: 8 PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMediaCrt.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\freebl3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libnspr4.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplc4.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplds4.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nss3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssutil3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\smime3.dll, , [143972f9800abe78698b298d4db67f81], Registry Keys: 37 PUP.Optional.Ask.A, HKLM\SOFTWARE\CLASSES\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719], PUP.Optional.Ask.A, HKLM\SOFTWARE\CLASSES\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}\INPROCSERVER32, , [8ac375f6b2d852e4b42d2a0e63a0e719], PUP.Optional.Ask.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719], PUP.Optional.Ask.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719], PUP.Optional.Ask.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719], PUP.Optional.Ask.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719], PUP.Optional.Ask.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [8ac375f6b2d852e4b42d2a0e63a0e719], PUP.Optional.InboxToolBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}, , [ff4e1754f6945fd7d19a6ccee91aa060], PUP.Optional.InboxToolBar.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}, , [60ed6209a3e730063740d89c28db28d8], PUP.Optional.MyFreeCodec.A, HKLM\SOFTWARE\WOW6432NODE\Myfree Codec, , [f05d0f5c8406ed49eb1ac68e22e32ed2], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\webssearchesSoftware, , [c08dce9d9ceea393a3bbd13134d0fb05], PUP.Optional.MyFreeCodec.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Myfree Codec, , [bf8e6cff3753c76f1ce8252fa95c728e], PUP.Optional.Wajam.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WajIEnhance, , [79d41c4fcebc87af9353537bbe45e21e], PUP.Optional.Wajam.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WIntEnhance, , [8cc12b407a10999d0f0f8a4054af9070], PUP.Optional.FastStart.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, , [7ad31f4c682292a48ef9b22d946f8f71], PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\webssearches uninstall, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.SecurityUtility.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ColorMedia, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B8D1E62C-5D04-4AB0-A09E-688FF75743EF}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1B0071C9-831E-43DD-9EFE-722D8AEB9E2E}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5217E897-1728-4B11-BC9D-5405AD551BEF}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6073385E-A128-4464-9DFD-C7CF0F39A492}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{81E47395-D310-4064-B963-844C4088AB76}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{83E41C3D-190A-4052-A046-269722F3B4FD}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A62D52D9-1E41-4772-A794-71B9B92AA014}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D1C116A0-DC17-4257-9190-033AE10F90B9}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{ED5B55CA-994B-42B9-93B6-1FD306925967}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FB7F9DF6-2A66-444F-BA5D-2F221F1B1AC8}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1B0071C9-831E-43DD-9EFE-722D8AEB9E2E}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5217E897-1728-4B11-BC9D-5405AD551BEF}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6073385E-A128-4464-9DFD-C7CF0F39A492}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{81E47395-D310-4064-B963-844C4088AB76}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{83E41C3D-190A-4052-A046-269722F3B4FD}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A62D52D9-1E41-4772-A794-71B9B92AA014}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D1C116A0-DC17-4257-9190-033AE10F90B9}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{ED5B55CA-994B-42B9-93B6-1FD306925967}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FB7F9DF6-2A66-444F-BA5D-2F221F1B1AC8}, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B8D1E62C-5D04-4AB0-A09E-688FF75743EF}, , [143972f9800abe78698b298d4db67f81], Registry Values: 6 PUP.Optional.Ask.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{4F524A2D-5350-4500-76A7-7A786E7484D7}, 0, , [8ac375f6b2d852e4b42d2a0e63a0e719] PUP.Optional.Ask.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{4F524A2D-5350-4500-76A7-7A786E7484D7}, 0, , [8ac375f6b2d852e4b42d2a0e63a0e719] PUP.Optional.Ask.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [4efff47738529e98845d38006f944fb1], PUP.Optional.Ask.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\{4F524A2D-5350-4500-76A7-7A786E7484D7}, , [301d02696d1db0861ec3eb4df80bfe02], PUP.Optional.FastStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|faststartff@gmail.com, C:\Users\<Benutzer>\AppData\Roaming\Mozilla\Firefox\Profiles\1ocg63p2.default\extensions\faststartff@gmail.com, , [b09d016a593161d53872231f13f29967] PUP.Optional.FastStart.A, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, , [7ad31f4c682292a48ef9b22d946f8f71] Registry Data: 16 PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Users\<Benutzer>\AppData\Local\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (firefox.exe), Bad: ("C:\Users\<Benutzer>\AppData\Local\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[a2abc5a6f39785b1b2db8b6bef16f50b] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[f9545912503abb7ba7e78e68d82d936d] PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}),,[ca8316553a50f640eb9317dd26df8977] PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[292475f6f39793a3fc8226ce09fc14ec] PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[99b49fcc9bef2c0ac4ba05ef05002fd1] PUP.Optional.WebsSearches, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}),,[0845a2c9563448ee94eaa94bc24356aa] PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[c9848be029616acc9f94b947ed19aa56] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\FIREFOX.EXE\SHELL\OPEN\COMMAND, "C:\Users\<Benutzer>\AppData\Local\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (firefox.exe), Bad: ("C:\Users\<Benutzer>\AppData\Local\Mozilla Firefox\firefox.exe" hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[8bc23536ddadc76f3a53fbfbe124649c] PUP.Optional.WebsSearches.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (iexplore.exe), Bad: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://istart.webssearches.com/?type=sc&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[7bd2b5b6aae041f5107e48ae39ccfb05] PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}),,[77d64f1c6c1e52e47b0341b30afb18e8] PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[6be28be0e0aa51e5ee90b73df70e7888] PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[cc81204b573387afb1cd1bd95ea723dd] PUP.Optional.WebsSearches, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/web/?type=ds&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B&q={searchTerms}),,[7ad3a7c4206a989ed4aa05ef966ff010] PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),,[68e568039cee4de9d36090707a8c2ad6] PUP.Optional.WebsSearches, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[ca83c6a5573341f5c5baed0708fdff01] PUP.Optional.WebsSearches, HKU\S-1-5-21-336442205-827502387-1674173946-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B, Good: (www.google.com), Bad: (hxxp://istart.webssearches.com/?type=hp&ts=1422430161&from=cvs&uid=SamsungXSSDX840XEVOX500GB_S1DHNSAF533144B),,[eb62bbb0d4b687af56293cb817ee0df3] Folders: 4 PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility, , [143972f9800abe78698b298d4db67f81], Files: 57 PUP.Optional.Ask.A, C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport_x64.dll, , [8ac375f6b2d852e4b42d2a0e63a0e719], PUP.Optional.Ask.A, C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ORJ-SPE\Passport.dll, , [8ac375f6b2d852e4b42d2a0e63a0e719], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage, , [103dff6c34566cca62cadaf1e2213ec2], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_istart.webssearches.com_0.localstorage-journal, , [321bf2793357270f56d6edde4cb72fd1], PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMedia.ini, , [73da94d71d6d54e25a32390f56afd62a], PUP.Optional.ColorMedia.A, C:\Windows\System32\ColorMediaOff.ini, , [62eb98d31d6dc076305dc68232d359a7], PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMediaOff.ini, , [252894d788022412a6e7fc4c94715ea2], PUP.Optional.Winsock.Hijack, C:\Windows\SysWOW64\ColorMedia.dll, , [25282d3e305a8aac97a3302110f5de22], PUP.Optional.Winsock.Hijack, C:\Windows\System32\ColorMedia64.dll, , [d37a12596b1f15218fac6ee3fb0a26da], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\458.json, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\MessageBox.xml, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\uninstallDlg2.xml, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\UninstallManager.exe, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\bg.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\bg1.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\bk_shadow.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\button.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\button1.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\checkbox.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\checkbox_select.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\checked.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\close.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\loading_bg.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\loading_light.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\min.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\scrollbar.bmp, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\Thumbs.db, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\unchecked.png, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code1.jpg, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code2.jpg, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code3.jpg, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code4.jpg, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code5.jpg, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\code6.jpg, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.WebsSearches.A, C:\Users\<Benutzer>\AppData\Roaming\webssearches\images\code\Thumbs.db, , [1637f477fd8d65d1aca8494448bb21df], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia.exe, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia.tlb, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMedia64.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ColorMediaCrt.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\freebl3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libnspr4.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplc4.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\libplds4.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nss3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssckbi.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssdbm3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\nssutil3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RfndNSIS.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia.exe, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia.ini, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\RgsBTMedia64.exe, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\smime3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\softokn3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\sqlite3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.SecurityUtility.A, C:\ProgramData\SecurityUtility\ssl3.dll, , [143972f9800abe78698b298d4db67f81], PUP.Optional.QuickStart.A, C:\Users\<Benutzer>\AppData\Roaming\Mozilla\Firefox\Profiles\1ocg63p2.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "chrome://quick_start/content/index.html");), ,[f15cc4a796f47db97dab4ef0ef175ca4] Physical Sectors: 0 (No malicious items detected) (end) |
Themen zu Windows 7 "beschädigt" nach Bereinigung mit MWB Antimalware |
.dll, antimalware, appdata, aufgabenplanungsdienst, browser, detected, diverse, explorer, firefox, helper, ics, iexplore.exe, installmanager.exe, internet, internet explorer, log, malwarebytes, microsoft, mozilla, neustart, notebook, problem, starten, system, system32, win7, windows |