Eigentlich hab ich nichts gegen XML. Ist halt von MBAM voreingestellt... Wie man an die TXT kommt muss man halt wissen, nä! ;-)
Code:
Alles auswählen Aufklappen ATTFilter
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 15.12.2016
Suchlaufzeit: 14:41
Protokolldatei: mbam3.txt
Administrator: Nein
Version: 2.2.1.1043
Malware-Datenbank: v2016.12.15.11
Rootkit-Datenbank: v2016.11.20.01
Lizenz: Kostenlose Version
Malware-Schutz: Deaktiviert
Schutz vor bösartigen Websites: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Josef (Sicher)
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 206365
Abgelaufene Zeit: 7 Min., 26 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 3
PUP.Optional.CornerSunshine, HKLM\SOFTWARE\CLIENTS\Corner Sunshine, , [d9ce36b1e6b49c9a8644c44836ca1ee2],
PUP.Optional.OffersOlymp, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\bbiilhoacmmppcmcogfmaailncbelbgn, , [07a00add346682b4ef295a3ceb1558a8],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [94131ccb772365d1cdf3c7c833cfb54b],
Registrierungswerte: 2
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f[b0f716d1afeba98dbc5f73a97b859f61]D1%26b[b0f716d1afeba98dbc5f73a97b859f61]DIE%26cc[b0f716d1afeba98dbc5f73a97b859f61]Dde%26pa[b0f716d1afeba98dbc5f73a97b859f61]DWincy%26cd[b0f716d1afeba98dbc5f73a97b859f61]D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr[b0f716d1afeba98dbc5f73a97b859f61]D958721771%26a[b0f716d1afeba98dbc5f73a97b859f61]Dwbf_beri_16_35%26os_ver[b0f716d1afeba98dbc5f73a97b859f61]D6.1%26os[b0f716d1afeba98dbc5f73a97b859f61]DWindowsB7BProfessional, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://de.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f[94131ccb772365d1cdf3c7c833cfb54b]D4%26b[94131ccb772365d1cdf3c7c833cfb54b]DIE%26cc[94131ccb772365d1cdf3c7c833cfb54b]Dde%26pa[94131ccb772365d1cdf3c7c833cfb54b]DWincy%26cd[94131ccb772365d1cdf3c7c833cfb54b]D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr[94131ccb772365d1cdf3c7c833cfb54b]D958721771%26a[94131ccb772365d1cdf3c7c833cfb54b]Dwbf_beri_16_35%26os_ver[94131ccb772365d1cdf3c7c833cfb54b]D6.1%26os[94131ccb772365d1cdf3c7c833cfb54b]DWindowsB7BProfessional&p={searchTerms}, %4, %5
Registrierungsdaten: 1
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=fSchlecht: (https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr%3D958721771%26a%3Dwbf_beri_16_35%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),,[2c7bdb0c7f1b16201c76656f649f8d73]D1%26bSchlecht: (https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr%3D958721771%26a%3Dwbf_beri_16_35%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),,[2c7bdb0c7f1b16201c76656f649f8d73]DIE%26ccSchlecht: (https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr%3D958721771%26a%3Dwbf_beri_16_35%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),,[2c7bdb0c7f1b16201c76656f649f8d73]Dde%26paSchlecht: (https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr%3D958721771%26a%3Dwbf_beri_16_35%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),,[2c7bdb0c7f1b16201c76656f649f8d73]DWincy%26cdSchlecht: (https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr%3D958721771%26a%3Dwbf_beri_16_35%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),,[2c7bdb0c7f1b16201c76656f649f8d73]D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26crSchlecht: (https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr%3D958721771%26a%3Dwbf_beri_16_35%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),,[2c7bdb0c7f1b16201c76656f649f8d73]D958721771%26aSchlecht: (https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr%3D958721771%26a%3Dwbf_beri_16_35%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),,[2c7bdb0c7f1b16201c76656f649f8d73]Dwbf_beri_16_35%26os_verSchlecht: (https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr%3D958721771%26a%3Dwbf_beri_16_35%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),,[2c7bdb0c7f1b16201c76656f649f8d73]D6.1%26osSchlecht: (https://de.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_beri_16_35¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dde%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutDtDtC0FtCyCtDzyyD0FtD0DyEtDtDyCtN0D0Tzu0StCyBtDyEtN1L2XzutAtFtByEtFyCtFzytN1L1Czu1TtN1L1G1B1V1N2Y1L1Qzu2SyBtC0Czz0CyEzz0FtGyEyC0E0BtG0AtDtAyDtGyDyDyC0FtG0EzzzyyEyE0B0CyEyD0E0Ezz2QtN1M1F1B2Z1V1N2Y1L1Qzu2StDtD0C0C0CyD0ByDtGtB0E0FyCtGyE0C0D0CtGzyyB0EtDtG0BtAzytB0A0DtCyD0AtBtAtD2QtN0A0LzutB%26cr%3D958721771%26a%3Dwbf_beri_16_35%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),,[2c7bdb0c7f1b16201c76656f649f8d73]DWindowsGut: (www.google.com)B7Gut: (www.google.com)BProfessional, %4, %5
Ordner: 1
PUP.Optional.OffersOlymp, C:\Program Files\Offers Olymp, , [e9be25c2782258deebde4452df21d52b],
Dateien: 2
PUP.Optional.WinYahoo, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk, , [64439e4938626ec8c48e3639f40f11ef],
PUP.Optional.OffersOlymp, C:\Program Files\Offers Olymp\bbiilhoacmmppcmcogfmaailncbelbgn.crx, , [e9be25c2782258deebde4452df21d52b],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end)