Zitat:
Zitat von
cosinus Nun sieh doch bitte einfach mal im Verlauf vom Windows Defender nach. Ohne diese Infos weiß hier niemand was du da für Zecken drauf hattest!!!
Den habe ich ja gelöscht -> Um diesen Troj usw. zu löschen.
Habe hier Einträge vom AdwcleanerAdwCleaner Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
# AdwCleaner v6.043 - Bericht erstellt am 24/02/2017 um 08:44:34
# Aktualisiert am 27/01/2017 von Malwarebytes
# Datenbank : 2017-02-23.4 [Server]
# Betriebssystem : Windows 10 Home (X64)
# Benutzername : Hakim - DESKTOP-4F9HM6T
# Gestartet von : C:\Users\Hakim\Downloads\adwcleaner_6.043.exe
# Modus: Suchlauf
# Unterstützung : https://www.malwarebytes.com/support
***** [ Dienste ] *****
Dienst Gefunden: 85a5e87b24279a8c7a4b1b8f3aec8803
Dienst Gefunden: a5d6ec7e1363541d98a24436effee449
Dienst Gefunden: NetUtils2016
Dienst Gefunden: NetUtils2016srv
Dienst Gefunden: Lace514
Dienst Gefunden: OtherSearch
***** [ Ordner ] *****
Ordner Gefunden: C:\ProgramData\6ff5d3cb-0c75-1
Ordner Gefunden: C:\ProgramData\6ff5d3cb-5061-0
Ordner Gefunden: C:\ProgramData\Microleaves
Ordner Gefunden: C:\Program Files (x86)\SoftUpgrade
Ordner Gefunden: C:\Windows\SysWoW64\sstmp
***** [ Dateien ] *****
Datei Gefunden: C:\Windows\SysNative\drivers\85a5e87b24279a8c7a4b1b8f3aec8803.sys
Datei Gefunden: C:\Windows\SysNative\drivers\NetUtils2016.sys
Datei Gefunden: C:\Windows\SysNative\drivers\LACE_WPF_X64.SYS
Datei Gefunden: C:\Windows\SysNative\drivers\Lace_wpf_x64.sys
Datei Gefunden: C:\Windows\SysWoW64\NetUtils2016.exe
***** [ DLL ] *****
Keine infizierten DLLs gefunden.
***** [ WMI ] *****
Keine schädlichen Schlüssel gefunden.
***** [ Verknüpfungen ] *****
Keine infizierten Verknüpfungen gefunden.
***** [ Aufgabenplanung ] *****
Aufgabe Gefunden: Jkercult
Aufgabe Gefunden: kH588C9yHa
Aufgabe Gefunden: SoftUpgrade
Aufgabe Gefunden: Traffic Exchange Guardian
Aufgabe Gefunden: Traffic Exchange Updater
Aufgabe Gefunden: Traffic Exchange
Aufgabe Gefunden: Traffic Exchange Guard
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden: HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
Schlüssel Gefunden: HKU\S-1-5-21-4249787852-1634029998-1901347353-1001\Software\Interstat
Schlüssel Gefunden: HKU\S-1-5-21-4249787852-1634029998-1901347353-1001\Software\WajIEnhance
Schlüssel Gefunden: HKU\S-1-5-21-4249787852-1634029998-1901347353-1001\Software\AppDataLow\Software\AppTrailers
Schlüssel Gefunden: HKCU\Software\Interstat
Schlüssel Gefunden: HKCU\Software\WajIEnhance
Schlüssel Gefunden: HKCU\Software\AppDataLow\Software\AppTrailers
Schlüssel Gefunden: HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
Schlüssel Gefunden: HKLM\SOFTWARE\Microleaves
Schlüssel Gefunden: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\11598763487076930564
Schlüssel Gefunden: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A97606DF-0FE1-4390-B0DD-ADA8B303AE61}_is1
Schlüssel Gefunden: [x64] HKCU\Software\Interstat
Schlüssel Gefunden: [x64] HKCU\Software\WajIEnhance
Schlüssel Gefunden: [x64] HKCU\Software\AppDataLow\Software\AppTrailers
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b
Schlüssel Gefunden: [x64] HKLM\SOFTWARE\Microleaves
Schlüssel Gefunden: HKU\S-1-5-21-4249787852-1634029998-1901347353-1001\Software\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gefunden: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Daten Gefunden: HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{cfb16857-7cf3-4aba-b0ed-9c81f0c15e48} [NameServer] - 82.163.142.8,95.211.158.136
Daten Gefunden: [x64] HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{cfb16857-7cf3-4aba-b0ed-9c81f0c15e48} [NameServer] - 82.163.142.8,95.211.158.136
Schlüssel Gefunden: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cmptch.com
Schlüssel Gefunden: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\coupontime.co
Schlüssel Gefunden: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.cmptch.com
Schlüssel Gefunden: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.coupontime00.coupontime.co
Schlüssel Gefunden: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\cmptch.com
Schlüssel Gefunden: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\coupontime.co
Schlüssel Gefunden: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.cmptch.com
Schlüssel Gefunden: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.coupontime
Schlüssel Gefunden: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\cmptch.com
Schlüssel Gefunden: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\coupontime.co
Schlüssel Gefunden: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.cmptch.com
Schlüssel Gefunden: HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.coupontime00.
Schlüssel Gefunden: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cmptch.com
Schlüssel Gefunden: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\coupontime.co
Schlüssel Gefunden: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.cmptch.com
Schlüssel Gefunden: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\static.coupontime00.coupontime.co
Schlüssel Gefunden: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\cmptch.com
Schlüssel Gefunden: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\coupontime.co
Schlüssel Gefunden: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.cmptch.c
Schlüssel Gefunden: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\static.couponti
Schlüssel Gefunden: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\cmptch.com
Schlüssel Gefunden: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\coupontime.co
Schlüssel Gefunden: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.cmptch.com
Schlüssel Gefunden: [x64] HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\static.coupontime0
Wert Gefunden: HKU\S-1-5-21-4249787852-1634029998-1901347353-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Interstat]
Wert Gefunden: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 [AppTrailers]
Wert Gefunden: HKU\S-1-5-21-4249787852-1634029998-1901347353-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [InterStat]
Schlüssel Gefunden: HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E
Schlüssel Gefunden: HKLM\SOFTWARE\CLASSES\APPID\56BF5154-0B48-4ADB-902A-6C8B12E270D9
***** [ Internetbrowser ] *****
Keine schädlichen Elemente in Firefox basierten Browsern gefunden.
Keine schädlichen Elemente in Chrome basierten Browsern gefunden.
*************************
C:\AdwCleaner\AdwCleaner[S0].txt - [8903 Bytes] - [24/02/2017 08:44:34]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [8976 Bytes] ##########
--- --- ---
__________________