![]() |
Logfile Analyse: Probleme mit Avast und Microsoft visual C++ Hallo Leute, habe ein Problemt mit Microsoft visual c++, die meldung kam schon öfters, weiß aber nicht woran es liegt. Danach wollte ich mein Virenprogramm (Avast) öffnen doch dies hat auch nicht geklappt, da folgende Meldung kam: dieses programm wurde durch eine gruppenrichtlinie blockiert. habe mir jetzt das programm malewarebytes - anti maleware runtergeladen, wobei momentan 178 detected objects. Soll ich hier gleich mal einen Logfile posten? Mfg Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 26.05.2014 Scan Time: 14:34:14 Logfile: LOG.txt Administrator: Yes Version: 2.00.2.1012 Malware Database: v2014.05.26.01 Rootkit Database: v2014.05.21.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Self-protection: Disabled OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: Alexander Köhn Scan Type: Threat Scan Result: Completed Objects Scanned: 461489 Time Elapsed: 23 min, 20 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled Processes: 0 (No malicious items detected) Modules: 0 (No malicious items detected) Registry Keys: 32 PUP.Optional.PriceGong.A, HKLM\SOFTWARE\CLASSES\APPID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}, , [c5346ce90e6da294963341efe31fff01], PUP.Optional.PriceGong.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}, , [c5346ce90e6da294963341efe31fff01], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, , [48b1a4b157247eb8526a8cd7fa08ce32], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, , [48b1a4b157247eb8526a8cd7fa08ce32], PUP.Optional.HomePageProtector.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{336D0C35-8A85-403A-B9D2-65C292C39087}, , [fdfcbd98fb80c571b5c750ddb44e9769], PUP.Optional.HomePageProtector.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{336D0C35-8A85-403A-B9D2-65C292C39087}, , [fdfcbd98fb80c571b5c750ddb44e9769], PUP.Optional.HomePageProtector.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{336D0C35-8A85-403A-B9D2-65C292C39087}, , [fdfcbd98fb80c571b5c750ddb44e9769], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, , [21d8f95c770457df40c2ce96fa08847c], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, , [a0590b4a15663501de252c38fc06649c], PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\Incredibar.IncredibarHlpr, , [b148a4b13d3eb87e7a70a5c0a959f10f], PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\Incredibar.IncredibarHlpr.1, , [50a9f2633d3eb680a248362f9270c739], PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Incredibar.IncredibarHlpr, , [50a9f2633d3eb680a248362f9270c739], PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Incredibar.IncredibarHlpr.1, , [50a9f2633d3eb680a248362f9270c739], PUP.Optional.PriceGong.A, HKLM\SOFTWARE\CLASSES\APPID\PriceGongIE.DLL, , [c33672e30d6e7abca1a5b7f2719137c9], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, , [0ced1d38f883b383397e2073e51de51b], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, , [c831a6afd0ab57dfabf40b9c56ace020], PUP.Optional.PriceGong.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\PriceGongIE.DLL, , [5b9e3d18fa81d16599add1d85ba722de], PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\niapdbllcanepiiimjjndipklodoedlc, , [47b25ef7cbb0c6708047404e5ea405fb], PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, , [9a5fb79e17640d29d85903a18e74e719], PUP.Optional.BabylonToolBar.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BabylonToolbar, , [5a9f0d48007b56e087e001bfde258d73], PUP.Optional.DataMngr.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr, , [31c81045f4876cca4f42299323e0ce32], PUP.Optional.DataMngr.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, , [a950460f7efd290d028eb00c36cdb44c], PUP.Optional.PriceGong.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [ae4b0550bfbc2c0a66a9b7eafd05fa06], PUP.Optional.Babylon.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BABSOLUTION\Updater, , [56a382d3a7d4082eb1e65c61a16236ca], PUP.Optional.Conduit.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\FF, , [9465b79e9be0290d56e37052b0530000], PUP.Optional.Softonic.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [b14822338fec1d1981c10c892bd7f60a], PUP.Optional.Iminent.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, , [c336abaa2c4fc76f425e1a8d1be7639d], PUP.Optional.PriceGong.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [6c8d73e2502bfd393cd33a67828049b7], PUP.Optional.Incredibar.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INCREDIBAR.COM\incredibar, , [02f7074e512a8bab785febaa7f8317e9], PUP.Optional.Iminent, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}, , [8a6fd382f58631055534567c798a817f], PUP.Optional.Softonic.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, , [5f9a2134f487db5bfc46deb70cf68b75], PUP.Optional.PriceGong.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, , [fbfebe977cff45f19a756e3314eeb749], Registry Values: 4 PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, , [fdfcbd98fb80c571b5c750ddb44e9769] PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, , [fdfcbd98fb80c571b5c750ddb44e9769] PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, , [4eab0550fe7da3936418fe2ff2103cc4], PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, , [0fea1e37fb8087af710bea4380824ab6], Registry Data: 0 (No malicious items detected) Folders: 28 PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator, , [4dace5703c3fac8a1c68482e43bf5fa1], PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator\Datas, , [4dace5703c3fac8a1c68482e43bf5fa1], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\98D158B8DC40499C9F44E1CBC714831E, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.Iminent.A, C:\Users\Alexander Köhn\AppData\Local\Temp\Iminent, , [ea0f9fb6df9c211505cd3046fa080df3], PUP.Optional.Iminent.A, C:\Users\Alexander Köhn\AppData\Local\Temp\Iminent\Log, , [ea0f9fb6df9c211505cd3046fa080df3], PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Local\Temp\mt_ffx\Delta, , [f603b99c8bf03600c80e294dc240ec14], PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Local\Temp\mt_ffx\Delta\delta, , [f603b99c8bf03600c80e294dc240ec14], PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.10.0, , [f603b99c8bf03600c80e294dc240ec14], PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Local\Temp\mt_ffx\Delta\delta\1.8.21.5, , [f603b99c8bf03600c80e294dc240ec14], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\chrome, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\components, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\META-INF, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\searchplugin, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\CT2682599, , [758465f0205bcb6b64cc631429d9ec14], PUP.Optional.PriceGong.A, C:\Program Files (x86)\PriceGong, , [659413429fdcac8ad147e39851b14db3], PUP.Optional.PriceGong.A, C:\Program Files (x86)\PriceGong\2.5.1, , [659413429fdcac8ad147e39851b14db3], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong, , [1ddc74e1e09bc27494e8ed90c33fac54], PUP.Optional.Incredibar.A, C:\Users\Alexander Köhn\AppData\Local\Temp\mt_ffx\Incredibar.com, , [49b060f593e86ec800ddb0cfc83a26da], PUP.Optional.Incredibar.A, C:\Users\Alexander Köhn\AppData\Local\Temp\mt_ffx\Incredibar.com\incredibar, , [49b060f593e86ec800ddb0cfc83a26da], PUP.Optional.Incredibar.A, C:\Users\Alexander Köhn\AppData\Local\Temp\mt_ffx\Incredibar.com\incredibar\1.5.11.14, , [49b060f593e86ec800ddb0cfc83a26da], PUP.Optional.Yontoo.A, C:\Program Files (x86)\Yontoo Layers, , [59a0d77e7dfe93a3a132790d6d9507f9], Files: 117 PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\DeltaTB.exe, , [a554f461225992a49965dd2ac1407d83], PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\DeltaTB.exe, , [b445d48143383303b74750b76d94718f], PUP.Tool, C:\Windows\SysWOW64\cmdow.exe, , [1bde8bcafb806acc77ed526653ae4ab6], PUP.Optional.Somoto.A, C:\Users\Alexander Köhn\AppData\Local\Temp\nskF616.tmp, , [40b9fd5825563204fa739a7e70910000], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Local\Temp\2dcd1d63cb45e6613582211c3d5f4b23.exe, , [609971e48eeded49ad1d12699a6ad42c], Malware.Packer.FFS, C:\Users\Alexander Köhn\AppData\Local\Temp\jpUFgAIy.zip.part, , [d02974e1f6853105332959d916eb6c94], PUP.Optional.Vittalia, C:\Users\Alexander Köhn\AppData\Local\Temp\instloffer.exe, , [0dec57fe8fec14228cab1b700df4956b], PUP.Optional.OptimizePro.A, C:\Users\Alexander Köhn\AppData\Local\Temp\OptimizerPro.exe, , [4eab87ce42395fd763d063bb35cb39c7], Adware.Yontoo, C:\Users\Alexander Köhn\AppData\Local\Temp\YontooIEClient.dll, , [db1e7adbc6b52a0cfc84ff0bf30de11f], Trojan.RotBrow.A, C:\Users\Alexander Köhn\AppData\Local\Temp\che3C06.tmp, , [25d41045ef8c9f97f1e9c4b68f7252ae], PUP.Optional.Babylon.A, C:\Users\Alexander Köhn\AppData\Local\Temp\081E03EB-BAB0-7891-A167-6A3C94D9919F\Latest\BExternal.dll, , [3fbaa0b59fdc082ec91af52db05021df], Trojan.RotBrowse, C:\Users\Alexander Köhn\AppData\Local\Temp\081E03EB-BAB0-7891-A167-6A3C94D9919F\Latest\ccp.exe, , [20d986cfdd9e3bfb5835c88254b007f9], PUP.Optional.Babylon.A, C:\Users\Alexander Köhn\AppData\Local\Temp\081E03EB-BAB0-7891-A167-6A3C94D9919F\Latest\CrxInstaller.dll, , [c3361f368cef0135268973a66d9431cf], PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Local\Temp\081E03EB-BAB0-7891-A167-6A3C94D9919F\Latest\MyBabylonTB.exe, , [45b41f36087382b4354d2d43af526b95], PUP.Optional.Babylon.A, C:\Users\Alexander Köhn\AppData\Local\Temp\081E03EB-BAB0-7891-A167-6A3C94D9919F\Latest\Setup.exe, , [fdfc3c19e695a98d5f9bcb40d52cd729], PUP.Optional.FaceMoods.A, C:\Users\Alexander Köhn\AppData\Local\Temp\is233770471\facemoods.exe, , [a950d085502b122466df334f83819d63], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\bus6D3\CrxUpdater_d.exe, , [21d8fd58641774c2cd2abd63976d6c94], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\bus780C\CrxUpdater_d.exe, , [dc1d0253ec8f82b42bcc140cc044e818], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\bus91E2\CrxUpdater_d.exe, , [54a5d580b1ca4ee813e4839d8c782ad6], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\bus9368\CrxUpdater_d.exe, , [ad4c5afbcfac9b9b9b5c2000d62eab55], Trojan.RotBrowse, C:\Users\Alexander Köhn\AppData\Local\Temp\6EDC727B-BAB0-7891-8E9C-7BA85BC10BDA\Latest\ccp.exe, , [0fea1d383447e94d127b1b2ffb0913ed], PUP.Optional.Babylon.A, C:\Users\Alexander Köhn\AppData\Local\Temp\6EDC727B-BAB0-7891-8E9C-7BA85BC10BDA\Latest\CrxInstaller.dum, , [ed0c74e190ebac8a2887f82128d9cc34], PUP.Optional.Delta, C:\Users\Alexander Köhn\AppData\Local\Temp\6EDC727B-BAB0-7891-8E9C-7BA85BC10BDA\Latest\MyDeltaTB.exe, , [6099cb8a3d3e999d6c3031d817ea9868], PUP.Optional.Babylon.A, C:\Users\Alexander Köhn\AppData\Local\Temp\6EDC727B-BAB0-7891-8E9C-7BA85BC10BDA\Latest\Setup.exe, , [9f5af85d2556e254d1611707f30d39c7], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busAD9C\CrxUpdater_d.exe, , [33c6e76eb9c21125da1de23eb3517987], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busAEC5\CrxUpdater_d.exe, , [3ebb045180fbb87e8e6969b7f80c0df3], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busB23E\CrxUpdater_d.exe, , [a554480d46352d09e116829e966e29d7], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busB74D\CrxUpdater_d.exe, , [8d6c1d38c6b5360032c52df360a4c838], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busBC2D\CrxUpdater_d.exe, , [cd2c93c25b2051e5a75009171de7cd33], PUP.Optional.BabSolution.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busBD26\BUSolution.dll, , [04f54213a4d7a294bc3fc646d62b758b], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busC4A5\CrxUpdater_d.exe, , [8475de77e6951f171fd83ee2d82c03fd], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\bus973F\CrxUpdater_d.exe, , [1edb4114374495a1e512f22e5ea608f8], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\bus9A99\CrxUpdater_d.exe, , [f0090b4a205b8caa7f78ad7322e21ae6], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\bus9B93\CrxUpdater_d.exe, , [40b9361fd5a6ad8957a032ee43c1e61a], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\bus9E03\CrxUpdater_d.exe, , [f30699bc106bbf7749aecb55db296997], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\bus9E51\CrxUpdater_d.exe, , [f6039cb98fec37ffcb2c5fc1b54ff907], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busA025\CrxUpdater_d.exe, , [15e42332e19a053107f021ff5ba9cc34], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busA469\CrxUpdater_d.exe, , [8c6d9abb2b504fe7d91e1f01ae565da3], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busA736\CrxUpdater_d.exe, , [a356ea6b17643bfb2fc869b741c351af], PUP.Optional.CRX.A, C:\Users\Alexander Köhn\AppData\Local\Temp\busA90A\CrxUpdater_d.exe, , [92672134f48711257780120e798bdd23], Trojan.Agent.CK, C:\Users\Alexander Köhn\Downloads\xf-adsk64.7z, , [71883223ea91102695fbf8288b77ef11], Adware.Linkular, C:\Users\Alexander Köhn\AppData\Local\DownloadGuide\Offers\Lollipop.exe, , [eb0e77de4c2f95a1d2bd4637db2905fb], PUP.Optional.BProtector.A, C:\Users\Alexander Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\5hnuazp5.default\bProtector_extensions.sqlite, , [b44534211665e0563575594256ac8f71], PUP.Optional.BProtector.A, C:\Users\Alexander Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\83ukwqst.default-1365006940133\bProtector_extensions.sqlite, , [88712d280c6f30063179bae1649ee818], PUP.Optional.BProtector.A, C:\Users\Alexander Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\r1h21jwe.default-1365005557058\bProtector_extensions.sqlite, , [f306ef66ccaf44f24d5d316a11f18b75], PUP.Optional.BProtector.A, C:\Users\Monika Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\h6zsoedp.default\bprotector_extensions.sqlite, , [f80189cc2754a88e7c2ef5a6e61c41bf], PUP.Optional.BProtector.A, C:\Users\Monika Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\h6zsoedp.default\bprotector_prefs.js, , [92675203d1aab87ee1ca4853a45eaa56], PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator\Datas\globalcache.dat, , [4dace5703c3fac8a1c68482e43bf5fa1], PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator\Datas\user.dat, , [4dace5703c3fac8a1c68482e43bf5fa1], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\5472.ico, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\EBB77268-338F-4C6A-8590-AD88FED26F4A, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\OCBrowserHelper_1.0.6.125.exe, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\98D158B8DC40499C9F44E1CBC714831E\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\2877.ico, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\AVG Toolbar Installer.exe, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\AVG_Toolbar_CB_ALL_p2v0.exe, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\EBB77268-338F-4C6A-8590-AD88FED26F4A, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\OCBrowserHelper_1.0.3.85.dll, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\5472.ico, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\EBB77268-338F-4C6A-8590-AD88FED26F4A, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\OCBrowserHelper_1.0.5.112.dll, , [966314415c1f37ffd9e0ee883bc77b85], PUP.Optional.Iminent.A, C:\Users\Alexander Köhn\AppData\Local\Temp\Iminent\IMinentToolbarInstallerFF.exe, , [ea0f9fb6df9c211505cd3046fa080df3], PUP.Optional.Iminent.A, C:\Users\Alexander Köhn\AppData\Local\Temp\Iminent\Log\Iminent.MSI.log, , [ea0f9fb6df9c211505cd3046fa080df3], PUP.Optional.Iminent.A, C:\Users\Alexander Köhn\AppData\Local\Temp\Iminent\Log\IMinentToolbar.msi.log, , [ea0f9fb6df9c211505cd3046fa080df3], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\chrome.manifest, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\install.rdf, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\version.txt, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\chrome\dvdvideosofttb.jar, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\components\ConduitAutoCompleteSearch.js, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\components\ConduitAutoCompleteSearch.xpt, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\components\RadioWMPCore.xpt, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\components\RadioWMPCoreGecko19.dll, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\components\RadioWMPCoreGecko5.dll, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\components\RadioWMPCoreGecko6.dll, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults\alertSettingsComponent.xml, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults\appContextMenu.xml, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults\engineContextMenu.xml, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults\engineSettings.json, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults\fbAlert.js, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults\getAppsContextMenu.xml, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults\postAppsContextMenu.xml, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults\toolbarContextMenu.xml, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\defaults\unsharedAppsContextMenu.xml, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\META-INF\manifest.mf, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\META-INF\zigbert.rsa, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\META-INF\zigbert.sf, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\Chat.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\DataStructures.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\EBEncryption.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\ExternalLibraryLoader.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\HTTP.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\IO.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\Log.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\MainSingleton.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\MD5.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\Notifications.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\ObserversAndEvents.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\Prefs.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\SearchProtector.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\SearchSuggestIO.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\String.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\TEAEncryption.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\Timer.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\Twitter.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\URL.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\Windows.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\modules\XML.jsm, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\ct2269050\searchplugin\conduit.xml, , [34c562f3413aed499c942b4ca161be42], PUP.Optional.Conduit.A, C:\Users\Alexander Köhn\AppData\Local\Temp\CT2682599\ddt.csf, , [758465f0205bcb6b64cc631429d9ec14], PUP.Optional.PriceGong.A, C:\Program Files (x86)\PriceGong\uninst.exe, , [659413429fdcac8ad147e39851b14db3], PUP.Optional.PriceGong.A, C:\Program Files (x86)\PriceGong\2.5.1\PriceGong.crx, , [659413429fdcac8ad147e39851b14db3], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Contact Us.lnk, , [1ddc74e1e09bc27494e8ed90c33fac54], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Help.lnk, , [1ddc74e1e09bc27494e8ed90c33fac54], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Homepage.lnk, , [1ddc74e1e09bc27494e8ed90c33fac54], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\Uninstall PriceGong.lnk, , [1ddc74e1e09bc27494e8ed90c33fac54], PUP.Optional.Yontoo.A, C:\Program Files (x86)\Yontoo Layers\YontooIEClient.dll, , [59a0d77e7dfe93a3a132790d6d9507f9], PUP.Optional.Delta.A, C:\Users\Monika Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\h6zsoedp.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "hxxp://www.delta-search.com/?babsrc=NT_ss&mntrId=76F76C626D981801&affID=121562&tl=gbn192982&tsp=4924");), ,[b247074ec7b4cf6755aaed97b84c6a96] Physical Sectors: 0 (No malicious items detected) (end) |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02 --- --- --- FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-05-2014 02 |
hi, Scan mit Combofix
|
Hallo, erstmal vielen Dank für deine Hilfe! Wie kann ich Avast deaktivieren wenn die ganze Zeit beim Öffnen folgende Meldung kommt: Dieses Programm wurde durch eine Gruppenrichtlinie blockiert. Weiter Informationen erhalten sie vom Systemadministrator. Ich selbst bin Administrator, deinstallieren kann ich ebenfalls nicht. MfG |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: HKLM Group Policy restriction on software: C:\Program Files\AVAST Software <====== ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Jetzt sollte es gehen ;) |
Hallo, so wie es aussieht hat es geklappt: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 25-05-2014 02 Ran by Alexander Köhn at 2014-05-28 14:11:16 Run:1 Running from C:\Users\Alexander Köhn\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM Group Policy restriction on software: C:\Program Files\AVAST Software <====== ATTENTION ***************** HKLM => Group Policy Restriction on software restored successfully. ==== End of Fixlog ==== |
dann jetzt Combofix :) |
Danke dafür, dass du immer so schnell antwortest und hilfst :) Combofix Logfile: Code: ComboFix 14-05-27.02 - Alexander Köhn 29.05.2014 20:14:43.1.4 - x64 |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Suchlauf Datum: 31.05.2014 Suchlauf-Zeit: 00:08:06 Logdatei: Malewarebytes.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.05.30.10 Rootkit Datenbank: v2014.05.21.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Alexander Köhn Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 464170 Verstrichene Zeit: 15 Min, 52 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 30 PUP.Optional.PriceGong.A, HKLM\SOFTWARE\CLASSES\APPID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}, In Quarantäne, [0a88461139426acc807b11224db59b65], PUP.Optional.PriceGong.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}, In Quarantäne, [0a88461139426acc807b11224db59b65], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [7b174b0ce39877bf5a943b2bc33fc838], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [7b174b0ce39877bf5a943b2bc33fc838], PUP.Optional.HomePageProtector.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{336D0C35-8A85-403A-B9D2-65C292C39087}, In Quarantäne, [bdd5c7904f2c2d092f7fd25e8280fa06], PUP.Optional.HomePageProtector.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{336D0C35-8A85-403A-B9D2-65C292C39087}, In Quarantäne, [bdd5c7904f2c2d092f7fd25e8280fa06], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [2c66e0776c0fee486dc73d2a60a211ef], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [c0d25007aad143f38da8e186e9199d63], PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\Incredibar.IncredibarHlpr, In Quarantäne, [177b72e548332f07ca526801d929c838], PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\Incredibar.IncredibarHlpr.1, In Quarantäne, [f79bc3941f5c6cca9d7fa3c60101748c], PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Incredibar.IncredibarHlpr, In Quarantäne, [f79bc3941f5c6cca9d7fa3c60101748c], PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Incredibar.IncredibarHlpr.1, In Quarantäne, [f79bc3941f5c6cca9d7fa3c60101748c], PUP.Optional.PriceGong.A, HKLM\SOFTWARE\CLASSES\APPID\PriceGongIE.DLL, In Quarantäne, [781a292eaecd53e33f573d714db5b14f], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [4c4657007dfe94a27198e1b8659dea16], PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, In Quarantäne, [157d74e30576ab8bbd1719747a88ed13], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [a9e9db7ceb902e0842ad58544ab87888], PUP.Optional.PriceGong.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\PriceGongIE.DLL, In Quarantäne, [deb4ef68d8a3e6502472f8b6c73bfe02], PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\niapdbllcanepiiimjjndipklodoedlc, In Quarantäne, [563cbe99d4a7c6704bce40548a78f10f], PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, In Quarantäne, [b0e2a1b6413a8caafa8702a7828012ee], PUP.Optional.BabylonToolBar.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BabylonToolbar, In Quarantäne, [068cc592f487d95d6255dde8fa09a65a], PUP.Optional.DataMngr.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, In Quarantäne, [ade53e19324944f29b45279aca39d12f], PUP.Optional.PriceGong.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [8111c790562539fd352bfbabfd05b44c], PUP.Optional.Conduit.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\FF, In Quarantäne, [038f88cf83f82511b7d2f6d1c241f10f], PUP.Optional.Softonic.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [2d652235d3a82a0c9301ebaff30fe61a], PUP.Optional.Iminent.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, In Quarantäne, [c3cfd186790289ad965a199337cbab55], PUP.Optional.PriceGong.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [563cdd7a750662d43030129450b22ed2], PUP.Optional.Incredibar.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INCREDIBAR.COM\incredibar, In Quarantäne, [c6ccb1a6fb80102666c38219c939f40c], PUP.Optional.Iminent, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}, In Quarantäne, [4c46cf88106b86b00ecbc116c93a42be], PUP.Optional.Softonic.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [454d2e294c2f58deb4e0108a22e0a55b], PUP.Optional.PriceGong.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [9bf73d1a4d2eda5c223eeabcf90959a7], Registrierungswerte: 4 PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [bdd5c7904f2c2d092f7fd25e8280fa06] PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [bdd5c7904f2c2d092f7fd25e8280fa06] PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [078bf95e1368a690b7f7d55b44be41bf], PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [e9a95bfc5b2087af2a8439f746bc9f61], Registrierungsdaten: 0 (No malicious items detected) Ordner: 9 PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator, In Quarantäne, [96fc96c1285334028b2d91e87290fc04], PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator\Datas, In Quarantäne, [96fc96c1285334028b2d91e87290fc04], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\98D158B8DC40499C9F44E1CBC714831E, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.Yontoo.A, C:\Program Files (x86)\Yontoo Layers, In Quarantäne, [8a0896c10279c175ce392e5c61a1c937], Dateien: 30 PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\DeltaTB.exe, In Quarantäne, [c3cfc7907308d85ec2d5c642c43dc33d], PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\DeltaTB.exe, In Quarantäne, [dab8c691e299c571cccbff099b6643bd], PUP.Tool, C:\Windows\SysWOW64\cmdow.exe, In Quarantäne, [484a96c18bf0a195886dbefca75ad32d], Trojan.Agent.CK, C:\Users\Alexander Köhn\Downloads\xf-adsk64.7z, In Quarantäne, [038f9dbab9c21f1764bd2df635cd4db3], Adware.Linkular, C:\Users\Alexander Köhn\AppData\Local\DownloadGuide\Offers\Lollipop.exe, In Quarantäne, [662c65f2562569cdd3ba493b41c335cb], PUP.Optional.BProtector.A, C:\Users\Alexander Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\5hnuazp5.default\bProtector_extensions.sqlite, In Quarantäne, [9cf62334fd7e45f1ac503e62b84a9070], PUP.Optional.BProtector.A, C:\Users\Alexander Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\83ukwqst.default-1365006940133\bProtector_extensions.sqlite, In Quarantäne, [0a88183f215a78be59a3ced27989a35d], PUP.Optional.BProtector.A, C:\Users\Alexander Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\r1h21jwe.default-1365005557058\bProtector_extensions.sqlite, In Quarantäne, [95fd7fd8ccaf6bcb0def861aa161fd03], PUP.Optional.BProtector.A, C:\Users\Monika Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\h6zsoedp.default\bprotector_extensions.sqlite, In Quarantäne, [7f139bbc1d5e2610fdff168a0002e11f], PUP.Optional.BProtector.A, C:\Users\Monika Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\h6zsoedp.default\bprotector_prefs.js, In Quarantäne, [a4ee3621b1ca280eaf4e3070010146ba], PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator\Datas\globalcache.dat, In Quarantäne, [96fc96c1285334028b2d91e87290fc04], PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator\Datas\user.dat, In Quarantäne, [96fc96c1285334028b2d91e87290fc04], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\5472.ico, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\OCBrowserHelper_1.0.6.125.exe, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\98D158B8DC40499C9F44E1CBC714831E\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\2877.ico, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\AVG Toolbar Installer.exe, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\AVG_Toolbar_CB_ALL_p2v0.exe, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\OCBrowserHelper_1.0.3.85.dll, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\5472.ico, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\OCBrowserHelper_1.0.5.112.dll, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Contact Us.lnk, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Help.lnk, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Homepage.lnk, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\Uninstall PriceGong.lnk, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.Yontoo.A, C:\Program Files (x86)\Yontoo Layers\YontooIEClient.dll, In Quarantäne, [8a0896c10279c175ce392e5c61a1c937], PUP.Optional.Delta.A, C:\Users\Monika Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\h6zsoedp.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.delta-search.com/?babsrc=NT_ss&mntrId=76F76C626D981801&affID=121562&tl=gbn192982&tsp=4924");), Ersetzt,[5e343b1c1566d4620c0f177510f4f10f] Physische Sektoren: 0 (No malicious items detected) (end) -------------------------------------------------------------------------------AdwCleaner Logfile: Code: # AdwCleaner v3.211 - Bericht erstellt am 31/05/2014 um 00:37:01 --------------------------------------------------------------------------------JRT Logfile: Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ------------------------------------------------------------------------------- FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02 |
Malwarebytes Anti-Malware Malwarebytes | Free Anti-Malware & Internet Security Software Suchlauf Datum: 31.05.2014 Suchlauf-Zeit: 00:08:06 Logdatei: Malewarebytes.txt Administrator: Ja Version: 2.00.2.1012 Malware Datenbank: v2014.05.30.10 Rootkit Datenbank: v2014.05.21.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: Alexander Köhn Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 464170 Verstrichene Zeit: 15 Min, 52 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 30 PUP.Optional.PriceGong.A, HKLM\SOFTWARE\CLASSES\APPID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}, In Quarantäne, [0a88461139426acc807b11224db59b65], PUP.Optional.PriceGong.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{835315FC-1BF6-4CA9-80CD-F6C158D40692}, In Quarantäne, [0a88461139426acc807b11224db59b65], PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [7b174b0ce39877bf5a943b2bc33fc838], PUP.Optional.Delta.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [7b174b0ce39877bf5a943b2bc33fc838], PUP.Optional.HomePageProtector.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{336D0C35-8A85-403A-B9D2-65C292C39087}, In Quarantäne, [bdd5c7904f2c2d092f7fd25e8280fa06], PUP.Optional.HomePageProtector.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{336D0C35-8A85-403A-B9D2-65C292C39087}, In Quarantäne, [bdd5c7904f2c2d092f7fd25e8280fa06], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{68B81CCD-A80C-4060-8947-5AE69ED01199}, In Quarantäne, [2c66e0776c0fee486dc73d2a60a211ef], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{E6B969FB-6D33-48d2-9061-8BBD4899EB08}, In Quarantäne, [c0d25007aad143f38da8e186e9199d63], PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\Incredibar.IncredibarHlpr, In Quarantäne, [177b72e548332f07ca526801d929c838], PUP.Optional.Incredibar, HKLM\SOFTWARE\CLASSES\Incredibar.IncredibarHlpr.1, In Quarantäne, [f79bc3941f5c6cca9d7fa3c60101748c], PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Incredibar.IncredibarHlpr, In Quarantäne, [f79bc3941f5c6cca9d7fa3c60101748c], PUP.Optional.Incredibar, HKLM\SOFTWARE\WOW6432NODE\CLASSES\Incredibar.IncredibarHlpr.1, In Quarantäne, [f79bc3941f5c6cca9d7fa3c60101748c], PUP.Optional.PriceGong.A, HKLM\SOFTWARE\CLASSES\APPID\PriceGongIE.DLL, In Quarantäne, [781a292eaecd53e33f573d714db5b14f], PUP.Optional.Incredibar.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\dlnembnfbcpjnepmfjmngjenhhajpdfd, In Quarantäne, [4c4657007dfe94a27198e1b8659dea16], PUP.Optional.DataMangr.A, HKLM\SOFTWARE\WOW6432NODE\DataMngr, In Quarantäne, [157d74e30576ab8bbd1719747a88ed13], PUP.Optional.Iminent.A, HKLM\SOFTWARE\WOW6432NODE\Iminent, In Quarantäne, [a9e9db7ceb902e0842ad58544ab87888], PUP.Optional.PriceGong.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\PriceGongIE.DLL, In Quarantäne, [deb4ef68d8a3e6502472f8b6c73bfe02], PUP.Optional.Yontoo.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\niapdbllcanepiiimjjndipklodoedlc, In Quarantäne, [563cbe99d4a7c6704bce40548a78f10f], PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, In Quarantäne, [b0e2a1b6413a8caafa8702a7828012ee], PUP.Optional.BabylonToolBar.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\BabylonToolbar, In Quarantäne, [068cc592f487d95d6255dde8fa09a65a], PUP.Optional.DataMngr.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, In Quarantäne, [ade53e19324944f29b45279aca39d12f], PUP.Optional.PriceGong.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [8111c790562539fd352bfbabfd05b44c], PUP.Optional.Conduit.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\CONDUIT\FF, In Quarantäne, [038f88cf83f82511b7d2f6d1c241f10f], PUP.Optional.Softonic.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [2d652235d3a82a0c9301ebaff30fe61a], PUP.Optional.Iminent.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Iminent, In Quarantäne, [c3cfd186790289ad965a199337cbab55], PUP.Optional.PriceGong.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [563cdd7a750662d43030129450b22ed2], PUP.Optional.Incredibar.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INCREDIBAR.COM\incredibar, In Quarantäne, [c6ccb1a6fb80102666c38219c939f40c], PUP.Optional.Iminent, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BFFED5CA-8BDF-47CC-AED0-23F4E6D77732}, In Quarantäne, [4c46cf88106b86b00ecbc116c93a42be], PUP.Optional.Softonic.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [454d2e294c2f58deb4e0108a22e0a55b], PUP.Optional.PriceGong.A, HKU\S-1-5-21-3395596779-1063543225-171022050-1004-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\PriceGong, In Quarantäne, [9bf73d1a4d2eda5c223eeabcf90959a7], Registrierungswerte: 4 PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [bdd5c7904f2c2d092f7fd25e8280fa06] PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\Web Assistant\Firefox, In Quarantäne, [bdd5c7904f2c2d092f7fd25e8280fa06] PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [078bf95e1368a690b7f7d55b44be41bf], PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [e9a95bfc5b2087af2a8439f746bc9f61], Registrierungsdaten: 0 (No malicious items detected) Ordner: 9 PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator, In Quarantäne, [96fc96c1285334028b2d91e87290fc04], PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator\Datas, In Quarantäne, [96fc96c1285334028b2d91e87290fc04], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\98D158B8DC40499C9F44E1CBC714831E, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.Yontoo.A, C:\Program Files (x86)\Yontoo Layers, In Quarantäne, [8a0896c10279c175ce392e5c61a1c937], Dateien: 30 PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\DeltaTB.exe, In Quarantäne, [c3cfc7907308d85ec2d5c642c43dc33d], PUP.Optional.Delta.A, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\DeltaTB.exe, In Quarantäne, [dab8c691e299c571cccbff099b6643bd], PUP.Tool, C:\Windows\SysWOW64\cmdow.exe, In Quarantäne, [484a96c18bf0a195886dbefca75ad32d], Trojan.Agent.CK, C:\Users\Alexander Köhn\Downloads\xf-adsk64.7z, In Quarantäne, [038f9dbab9c21f1764bd2df635cd4db3], Adware.Linkular, C:\Users\Alexander Köhn\AppData\Local\DownloadGuide\Offers\Lollipop.exe, In Quarantäne, [662c65f2562569cdd3ba493b41c335cb], PUP.Optional.BProtector.A, C:\Users\Alexander Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\5hnuazp5.default\bProtector_extensions.sqlite, In Quarantäne, [9cf62334fd7e45f1ac503e62b84a9070], PUP.Optional.BProtector.A, C:\Users\Alexander Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\83ukwqst.default-1365006940133\bProtector_extensions.sqlite, In Quarantäne, [0a88183f215a78be59a3ced27989a35d], PUP.Optional.BProtector.A, C:\Users\Alexander Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\r1h21jwe.default-1365005557058\bProtector_extensions.sqlite, In Quarantäne, [95fd7fd8ccaf6bcb0def861aa161fd03], PUP.Optional.BProtector.A, C:\Users\Monika Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\h6zsoedp.default\bprotector_extensions.sqlite, In Quarantäne, [7f139bbc1d5e2610fdff168a0002e11f], PUP.Optional.BProtector.A, C:\Users\Monika Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\h6zsoedp.default\bprotector_prefs.js, In Quarantäne, [a4ee3621b1ca280eaf4e3070010146ba], PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator\Datas\globalcache.dat, In Quarantäne, [96fc96c1285334028b2d91e87290fc04], PUP.Optional.Iminent.A, C:\Users\Monika Köhn\AppData\Roaming\Iminent\Mediator\Datas\user.dat, In Quarantäne, [96fc96c1285334028b2d91e87290fc04], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\5472.ico, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\63EA737ADD4A4D829C6BB56B0527104D\OCBrowserHelper_1.0.6.125.exe, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\98D158B8DC40499C9F44E1CBC714831E\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\2877.ico, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\AVG Toolbar Installer.exe, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\AVG_Toolbar_CB_ALL_p2v0.exe, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\A217A4CDF9154A72B65E7B5B3639896C\OCBrowserHelper_1.0.3.85.dll, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\5472.ico, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\EBB77268-338F-4C6A-8590-AD88FED26F4A, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.OpenCandy, C:\Users\Alexander Köhn\AppData\Roaming\OpenCandy\E4A2D42015394264B0571170255DABF8\OCBrowserHelper_1.0.5.112.dll, In Quarantäne, [eda5aaad7605092d03ea384111f1a45c], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Contact Us.lnk, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Help.lnk, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\PriceGong Homepage.lnk, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.PriceGong.A, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PriceGong\Uninstall PriceGong.lnk, In Quarantäne, [b4de82d57308290db9f75a269270cc34], PUP.Optional.Yontoo.A, C:\Program Files (x86)\Yontoo Layers\YontooIEClient.dll, In Quarantäne, [8a0896c10279c175ce392e5c61a1c937], PUP.Optional.Delta.A, C:\Users\Monika Köhn\AppData\Roaming\Mozilla\Firefox\Profiles\h6zsoedp.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.delta-search.com/?babsrc=NT_ss&mntrId=76F76C626D981801&affID=121562&tl=gbn192982&tsp=4924");), Ersetzt,[5e343b1c1566d4620c0f177510f4f10f] Physische Sektoren: 0 (No malicious items detected) (end) -------------------------------------------------------------------------------AdwCleaner Logfile: Code: # AdwCleaner v3.211 - Bericht erstellt am 31/05/2014 um 00:37:01 -------------------------------------------------------------------------------- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x64 Ran by Alexander K”hn on 31.05.2014 at 0:43:50,05 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\DisplayName Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-1B20_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-1B20_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-1B20_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\YontooSetup-DropDownDeals-SilentInstaller-1B20_RASMANCS ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{02EEDD34-F787-4718-9207-AE2FD3B1C1BC} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{045F206E-51D0-4F63-85C3-EDEF932819F5} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{061F09B0-73B2-4577-A4D5-A08040492CC2} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{08232570-1CB0-46B4-AA7A-14F0706E160F} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{08A1EA4F-40A0-496B-AE05-7B55A3E3EC27} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{10CB203D-FBD1-45FF-ABDF-93AD1492233B} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{15D51F47-F0A3-49F8-AF45-D9B8E7112C15} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{1654F121-3792-4386-9FE5-C5D27E9BBC42} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{1AB2B53E-F9D0-4553-8D92-DF941C8E2DD8} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{2194C45A-65B8-4445-B315-6ECE8600DA85} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{271A950E-6283-4A1A-9138-706250A41F0B} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{27809FD6-1820-4F10-B38F-4AAE323069D4} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{28CCE20B-5A79-4CE9-9083-90D1060B2D8D} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{2C621AFD-C990-49D7-AA7E-1CF8B68FA120} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{2CCB32E7-19D8-4668-AB90-549C60A6358F} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{3120E2D5-1EDB-427B-9437-8546ABAE49A5} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{31259D06-36C0-40F1-BC83-09DC4B0524F6} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{3D7F631A-B01B-4115-91E2-4E1247A7B971} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{440CFEA9-5AD3-447A-AC32-862521CD0A6A} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{44203B25-3B8F-4E62-9867-65338D552939} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{45D913A9-60A9-4948-957D-4CE68509C439} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{4CF0D874-CF08-4919-B539-FFC2D0A370B6} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{4D0D989F-0E30-49AB-BBDE-651371646825} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{50A4A425-1366-455D-B99B-FFDA211BC01B} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{5168CDEB-53D8-42C0-BD31-8DCCC65997D0} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{52B90712-25B2-4141-A9AE-5AC2BD058053} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{560AADDD-F726-4E9F-AA0C-6ECCC3C15C1D} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{5B8D7009-CA3C-481A-83B5-5F8C1333EA9F} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{5DEB90EF-0C65-4EB6-AA8D-9B04DE8C98CB} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{649A1A6C-0A5B-477C-A46C-657201B54CED} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{671D653C-F98B-4D61-BB88-ADAC1B5AC19F} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{6B4CFA2D-734B-42C8-9261-21BBDC13F626} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{798348FE-BF77-4667-B0EA-D26946210AB1} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{7ECB275F-D746-4A97-AE57-2B181E602196} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{858F1016-93EE-4E69-8008-7073ADAFBA55} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{8AD7D8B1-4DE3-4C04-A4C7-8346FB5ACD7B} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{910A8702-6527-4144-9F3F-48326404BB76} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{923388EC-3086-4AF4-A9D0-652D6023858B} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{953893F6-A7F0-4C1D-987E-E53A8F84EF27} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{9A898861-9D1C-486A-AB1D-22CA32FF822C} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{9CDD8B75-1659-4FBF-86A1-0541E109A8EF} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{9D58F509-B0C8-411F-97ED-B28F9A8A95C9} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{9F3C8532-835A-472D-919A-10C0E354A7E6} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{A1D5732D-E98B-44DF-9019-A038C5895FD8} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{A45C993C-05DB-4FB4-BE71-AEB721ECB035} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{A536C1AE-7482-4904-806E-5E3AF82149FE} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{A6214281-B36A-4A83-AD8A-6EBE637C558D} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{A6690FEF-DFD3-48A6-9EA9-A8BD6AEA657F} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{A8CDFA6A-C68B-4148-8114-441B565BE75D} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{A9BAAD5D-5503-4BEC-B410-504E708ED357} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{AB85AB3A-A75A-4615-A495-90EBCDD0C375} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{AF4E30E3-B2D3-4D84-BBDA-2BBF8BBE5B0C} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{B7A8BF1F-B7C6-46E8-BB2A-6ED7105CE6B4} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{B8A4E05E-E592-40E6-B7A0-E2CD27392CB8} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{BB5D7C8F-7E12-410C-948D-824846104CB9} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{C01D4A7C-35FB-48EA-A0CE-CE1C59A5EACE} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{CF2BCAF2-8294-4123-A038-7E66CE7ACB58} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{D0CF024D-C79F-4AC0-B2AC-51670AFCE490} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{D8833FDA-79F5-4DA9-9BB3-F67B96DC23F3} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{DB169C09-B7BC-4053-A7FD-44A9B8753CB5} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{DC61CF4D-4CD7-4ED4-8C4C-017A6426F53A} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{DEA75AF5-BA0E-40DA-A9F9-BB3887AC2E92} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{DEE5967B-0868-4327-90B5-D9024D70BDA7} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{E523277C-2A5B-48A4-89AF-F65BAF07F495} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{E7BDC9A7-099D-410F-A4CC-F20FECE833D2} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{F6B41E2E-A1D6-407F-9633-7E6A02F749BE} Successfully deleted: [Empty Folder] C:\Users\Alexander K”hn\appdata\local\{F9792605-5B55-454A-8673-4CC142002D56} ~~~ FireFox Successfully deleted: [File] C:\user.js Emptied folder: C:\Users\Alexander K”hn\AppData\Roaming\mozilla\firefox\profiles\4pd2tv65.default\minidumps [75 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 31.05.2014 at 0:51:33,15 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ------------------------------------------------------------------------------- FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02 |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7587 # api_version=3.0.2 # EOSSerial=897d06e0d280eb4e980c458d909b4b1d # engine=18492 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-31 06:42:32 # local_time=2014-05-31 08:42:32 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='avast! Antivirus' # compatibility_mode=783 16777213 100 97 75358 16854692 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 69906 153191602 0 0 # scanned=426526 # found=17 # cleaned=0 # scan_time=12432 sh=C887157C0193E8F13A4BAA4CCEE2FB4BA05CBB0A ft=1 fh=14d925a6106a41f1 vn="OSX/ChatZum.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\chatzum_nt.exe.vir" sh=3792F19D1860B40EB871C041019ED62A427CF00C ft=1 fh=e3e940ab43810265 vn="Variante von Win32/Adware.Yontoo.B Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll.vir" sh=E0814D0F17EE1122F6D3507DC676030F8E1CC133 ft=1 fh=0e0f46db8e6ee8c4 vn="Win32/Toolbar.Babylon.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Alexander Köhn\AppData\Roaming\BabSolution\Shared\BabMaint.exe.vir" sh=F314612E37E07A0A901EBA3601C90301D1575431 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip Wurm" ac=I fn="C:\ProgramData\Spybot - Search & Destroy\Recovery\ToolbarFacemood82.zip" sh=FA80A25D2F574A3F55E11150B12BC8DEB9319930 ft=0 fh=0000000000000000 vn="Win32/PriceGong.B evtl. unerwünschte Anwendung" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\PriceGong\2.5.1\PriceGong.crx.vir" sh=1701BD331400ECAC309FA5B793481CCE87FF93CC ft=1 fh=bc4ada3794bb9b2e vn="möglicherweise unbekannter Virus NewHeur_PE Virus" ac=I fn="C:\Stormblade\launcher.exe" sh=16C8B78109D7950E3494FB3265325B9CAE5B87B6 ft=1 fh=2478213aaf05656c vn="möglicherweise unbekannter Virus NewHeur_PE Virus" ac=I fn="C:\Stormblade\updater.exe" sh=72E201D9A583F4BC5AFA6A06726E3FFC3ADE42E8 ft=0 fh=0000000000000000 vn="SWF/Exploit.Agent.GD Trojaner" ac=I fn="C:\Users\Alexander Köhn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2FFYFPA1\T7Kn7-3pbi6FyaRxFYUuFcCi8-dCL_2yfOErWeZ651oVgi-XzRPuVlDmX5BLDtgovK2HAQ==[1].htm" sh=1701BD331400ECAC309FA5B793481CCE87FF93CC ft=1 fh=bc4ada3794bb9b2e vn="möglicherweise unbekannter Virus NewHeur_PE Virus" ac=I fn="C:\Users\Alexander Köhn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9Y4E8D9M\launchery[1].exe" sh=16C8B78109D7950E3494FB3265325B9CAE5B87B6 ft=1 fh=2478213aaf05656c vn="möglicherweise unbekannter Virus NewHeur_PE Virus" ac=I fn="C:\Users\Alexander Köhn\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X8458VLS\updater[1].exe" sh=F21B6E995891CC98BF3653B857B58FD2056D563C ft=0 fh=0000000000000000 vn="Variante von Java/Agent.DM Trojaner" ac=I fn="C:\Users\Alexander Köhn\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36\72503264-15619aaa" sh=48A87DD935CC71B7794F3C00C968BF81DAFFEAE8 ft=1 fh=1b6cc5f5e86bcc03 vn="Variante von MSIL/DownloadGuide.E evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Alexander Köhn\Downloads\fru-21368671-setup-Downloader.exe" sh=E3961046CCB602F8816AF73EA57B4450CF921522 ft=1 fh=2481223e329888d9 vn="Variante von Win32/DownloadSponsor.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Alexander Köhn\Downloads\Recuva - CHIP-Downloader.exe" sh=2C07EEB8E9FDCFE9A36AE38163EB3F2BE2833A85 ft=1 fh=31688d338c420f89 vn="möglicherweise unbekannter Virus NewHeur_PE Virus" ac=I fn="C:\Users\Alexander Köhn\Downloads\sblauncher.exe" sh=F314612E37E07A0A901EBA3601C90301D1575431 ft=0 fh=0000000000000000 vn="Win32/Bagle.gen.zip Wurm" ac=I fn="C:\Users\All Users\Spybot - Search & Destroy\Recovery\ToolbarFacemood82.zip" sh=8EEC2F3EC9E824FC4D7E561C8C22B1A5C4546640 ft=1 fh=89f68a07f7f8a43c vn="Variante von Win32/Toolbar.Perion.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\update[1]" sh=8EEC2F3EC9E824FC4D7E561C8C22B1A5C4546640 ft=1 fh=89f68a07f7f8a43c vn="Variante von Win32/Toolbar.Perion.G evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA\update[1]" Results of screen317's Security Check version 0.99.83 Windows 7 Service Pack 1 x64 (UAC is disabled!) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java(TM) 6 Update 22 Java 7 Update 55 Adobe Flash Player 13.0.0.214 Adobe Reader XI Mozilla Firefox (29.0.1) ````````Process Check: objlist.exe by Laurent```````` AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02 |
Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop. Schließe nun alle offenen Programme und trenne Dich von dem Internet. Doppelklick auf die TFC.exe und drücke auf Start. Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen. Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 14:58 Uhr. |
Copyright ©2000-2025, Trojaner-Board