ich habe jetzt Malware ausgeführt.
Code:
Alles auswählen Aufklappen ATTFilter
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 06.05.17
Scan-Zeit: 13:20
Protokolldatei: Malware.txt
Administrator: Ja
-Softwaredaten-
Version: 3.0.6.1469
Komponentenversion: 1.0.103
Version des Aktualisierungspakets: 1.0.1713
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: MAX1\Lutz
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 667038
Abgelaufene Zeit: 1 Min., 22 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 7
PUP.Optional.WebSteroids, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [5818], [169013],1.0.1713
PUP.Optional.CrossAd, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Virtual Mart, In Quarantäne, [774], [258196],1.0.1713
PUP.Optional.IFEO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SKYPE.EXE, In Quarantäne, [9351], [239345],1.0.1713
PUP.Optional.SmileysWeLove, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\fjbbjfdilbioabojmcplalojlmdngbjl, In Quarantäne, [7412], [243213],1.0.1713
PUP.Optional.IFEO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SKYPE.EXE, In Quarantäne, [9351], [239345],1.0.1713
PUP.Optional.CleanBrowser, HKLM\SOFTWARE\WOW6432NODE\Clean Browser, In Quarantäne, [1497], [236596],1.0.1713
PUP.Optional.Infonaut, HKLM\SOFTWARE\WOW6432NODE\Infonaut_1.10.0.14, In Quarantäne, [12023], [239521],1.0.1713
Registrierungswert: 2
PUP.Optional.IFEO, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SKYPE.EXE|DEBUGGER, In Quarantäne, [9351], [239345],1.0.1713
PUP.Optional.IFEO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\SKYPE.EXE|DEBUGGER, In Quarantäne, [9351], [239345],1.0.1713
Registrierungsdaten: 2
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [14049], [292819],1.0.1713
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DEFAULTSCOPE, Ersetzt, [14049], [292819],1.0.1713
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 21
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\CanvasFramework, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\AppFramework, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\PROGRAM FILES (X86)\Clean Browser, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\CanvasFramework, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\AppFramework, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\framework-ui, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\framework, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\USERS\LUTZ\APPDATA\LOCAL\Clean Browser, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\zo5azs8h.default\jetpack\@C88E6AE462306619BA2DBD89699AE5CBC88E\simple-storage, In Quarantäne, [9191], [175230],1.0.1713
PUP.Optional.CrossAd.Gen, C:\USERS\LUTZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZO5AZS8H.DEFAULT\JETPACK\@C88E6AE462306619BA2DBD89699AE5CBC88E, In Quarantäne, [9191], [175230],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\{B5E5BF6E-89AA-960E-3A7E-B06ECF19AE7E}, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component2, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\USERS\LUTZ\APPDATA\LOCAL\VIRTUAL MART, In Quarantäne, [9335], [301775],1.0.1713
Datei: 48
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\bottom-left.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\bottom-middle.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\bottom-right.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\middle-left.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\middle-right.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\tail-bottom.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\tail-left.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\tail-right.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\tail-top.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\top-left.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\top-middle.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\theme\bubble\top-right.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\context_menu_item_handler.html, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\framework-ui\notification.html, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\button.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\icon100.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\icon128.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\icon32.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\icons\icon48.png, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\background.html, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\config.xml, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Program Files (x86)\Clean Browser\extension_info.json, In Quarantäne, [1425], [176093],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\framework-ui\contentNotification.tmpl, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\framework-ui\contentNotificationStyle.tmpl, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\button.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\icon100.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\icon128.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\icon32.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\icons\icon48.png, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\background.html, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\chrome.manifest, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\extension_info.json, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\firefox\install.rdf, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\icon.ico, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CleanBrowser, C:\Users\Lutz\AppData\Local\Clean Browser\info.xml, In Quarantäne, [1425], [176092],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Roaming\Mozilla\Firefox\Profiles\zo5azs8h.default\jetpack\@C88E6AE462306619BA2DBD89699AE5CBC88E\simple-storage\store.json, In Quarantäne, [9191], [175230],1.0.1713
PUP.Optional.Komodia.WnskRST, C:\WINDOWS\SYSTEM32\ZDENGINE64.DLL.XTH, In Quarantäne, [1293], [106355],1.0.1713
PUP.Optional.CrossAd.Gen, C:\USERS\LUTZ\APPDATA\LOCAL\VIRTUAL MART\COMPONENT\CONFIG.JSON, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\hello.js, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\manifest.json, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\scriptTagContext.js, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\tmp_bg.js, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component\uconfig.json, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\Component2\plugin, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.CrossAd.Gen, C:\Users\Lutz\AppData\Local\Virtual Mart\{B5E5BF6E-89AA-960E-3A7E-B06ECF19AE7E}\c.dat, In Quarantäne, [9335], [301775],1.0.1713
PUP.Optional.FireFoxHijack, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\DEFAULTS\PREF\!C88E6AE462306619BA2DBD89699AE5CBC88E.js, In Quarantäne, [15389], [255361],1.0.1713
PUP.Optional.CrossAd.Gen, C:\USERS\LUTZ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\zo5azs8h.default\EXTENSIONS\@C88E6AE462306619BA2DBD89699AE5CBC88E.xpi, In Quarantäne, [9335], [184242],1.0.1713
PUP.Optional.ASK, C:\WINDOWS\INSTALLER\AF88A6B.MSI, In Quarantäne, [507], [113867],1.0.1713
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end)
hier die Eset Log-Datei.