Johanna15 | 30.11.2014 11:48 | Ich habe alle Arbeitsschritte ausgeführt, hier sind die Logs dazu: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 28.11.2014
Scan Time: 17:29:56
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.11.28.05
Rootkit Database: v2014.11.22.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 8.1
CPU: x64
File System: NTFS
User: Johanna
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 326187
Time Elapsed: 9 min, 31 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 3
PUP.Optional.SmartBar, C:\Windows\Installer\MSIE10E.tmp, Delete-on-Reboot, [30f5d8695f1dec4ac89ce74728d87f81],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIE10E.tmp, Delete-on-Reboot, [30f5d8695f1dec4ac89ce74728d87f81],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIE10E.tmp-\Smartbar.Installer.CustomActions.dll, Delete-on-Reboot, [7da84df43e3e3afc3b29d95554acb14f],
Registry Keys: 9
PUP.Optional.TermTutor.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{6CB99040-7828-4C37-AC01-F15758F43E4D}, Quarantined, [b570ad94522a9e98f24f5b6612f04db3],
PUP.Optional.MySafeProxy.A, HKLM\SOFTWARE\CLASSES\MySafeProxy.MySafeProxy, Quarantined, [8e97330e8af29e98c808dbe59d657d83],
PUP.Optional.MySafeProxy.A, HKLM\SOFTWARE\CLASSES\MySafeProxy.MySafeProxy.1, Quarantined, [d94cbc85e696aa8c448cb0106b9750b0],
PUP.Optional.MySafeProxy.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\MySafeProxy.MySafeProxy, Quarantined, [d94cbc85e696aa8c448cb0106b9750b0],
PUP.Optional.MySafeProxy.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\MySafeProxy.MySafeProxy.1, Quarantined, [d94cbc85e696aa8c448cb0106b9750b0],
PUP.Optional.FocusBase.A, HKLM\SOFTWARE\WOW6432NODE\focusbase, Quarantined, [170ee0613349a0961520773d35cf9b65],
PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD, Quarantined, [95905de485f7a195b67c9db0da292dd3],
PUP.Optional.FocusBase.A, HKU\S-1-5-21-1306114221-2738080776-3084928801-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\focusbase, Quarantined, [53d23b063844999d89adf7bdf50f08f8],
PUP.Optional.FastStart.A, HKU\S-1-5-21-1306114221-2738080776-3084928801-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS, Quarantined, [c461410081fb57dfe0e73814d132c838],
Registry Values: 4
PUP.Optional.TermTutor.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TTNFD|ImagePath, system32\drivers\ttnfd.sys, Quarantined, [95905de485f7a195b67c9db0da292dd3]
PUP.Optional.Gameo.A, HKU\S-1-5-21-1306114221-2738080776-3084928801-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Gameo, C:\Users\Johanna\AppData\Roaming\Gameo\gameo.exe "C:\Users\Johanna\AppData\Roaming\Gameo\gameo.dat" mode:minimized, Quarantined, [1c095be6d1ab72c45566f5bb6b992ad6]
PUP.Optional.PayByAds.A, HKU\S-1-5-21-1306114221-2738080776-3084928801-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Yahoo! Search, C:\Users\Johanna\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.15.4\dsrlte.exe, Quarantined, [1e07073adba10432ce0e2c1a768dca36]
PUP.Optional.FastStart.A, HKU\S-1-5-21-1306114221-2738080776-3084928801-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, faststartff@gmail.com, Quarantined, [c461410081fb57dfe0e73814d132c838]
Registry Data: 2
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[33f25be61d5f4ceae7912534db2a8a76]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Good: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Bad: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Replaced,[8d98ff42097386b0ed8b035614f12ed2]
Folders: 20
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\apps, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\apps\EULA, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\apps\EULA\net.vmn.www.alexa, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\coupons, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\search, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\weather, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.Extutil.A, C:\Users\Johanna\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B, Quarantined, [ab7a370a403cb87ea5d3f63145be5fa1],
PUP.Optional.Managera.A, C:\Users\Johanna\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42, Quarantined, [0e1720212854c76fbcbd77b011f28c74],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\AppFramework, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\CanvasFramework, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\icons, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.MySafeProxy.A, C:\Windows\Temp\XTRM Group Ltd, Quarantined, [879eb48d750769cdd47661d8857e57a9],
PUP.Optional.MySafeProxy.A, C:\Windows\Temp\XTRM Group Ltd\MySafeProxy, Quarantined, [879eb48d750769cdd47661d8857e57a9],
PUP.Optional.MySafeProxy.A, C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.11.0, Quarantined, [879eb48d750769cdd47661d8857e57a9],
PUP.Optional.MySafeProxy.A, C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.11.0\rollback, Quarantined, [879eb48d750769cdd47661d8857e57a9],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com, Quarantined, [58cde061c6b61c1a5e721924af544db3],
Files: 112
PUP.Optional.SmartBar, C:\Windows\Installer\MSIE10E.tmp, Delete-on-Reboot, [30f5d8695f1dec4ac89ce74728d87f81],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIE10E.tmp-\Smartbar.Installer.CustomActions.dll, Delete-on-Reboot, [7da84df43e3e3afc3b29d95554acb14f],
PUP.Optional.Conduit.A, C:\Users\Johanna\AppData\Local\Temp\dlLogic.exe, Quarantined, [db4a69d8ea9259dd00f395ad36ca4eb2],
PUP.Optional.Conduit.A, C:\Users\Johanna\AppData\Local\Temp\dltr.exe, Quarantined, [bb6a340dd7a5a98d1cd8c77bc33d3ac6],
PUP.Optional.GratifyingApps.A, C:\Users\Johanna\AppData\Local\Temp\ins9D9A.tmp.exe, Quarantined, [47dee061601c0432041dfccaf40d6f91],
PUP.Optional.MyPCBackup.A, C:\Users\Johanna\AppData\Local\Temp\BackupSetup.exe, Quarantined, [2ff6a39e7ffd082ec1a4499703fef60a],
PUP.Optional.Conduit.A, C:\Users\Johanna\AppData\Local\Temp\verifier.exe, Quarantined, [ff26b68b3e3e231310e460e2e41ce11f],
PUP.Optional.Conduit.A, C:\Users\Johanna\AppData\Local\Temp\GCVerifier.dll, Quarantined, [43e256eb5e1e89ad8f63330f8d731de3],
PUP.Optional.SmartBar, C:\Users\Johanna\AppData\Local\Temp\MSIA04F.tmp-\Smartbar.Installer.CustomActions.dll, Quarantined, [be6739081e5ee84e40245ad440c038c8],
PUP.Optional.MySafeProxy.A, C:\Users\Johanna\AppData\Local\Temp\D69Btmp\msp-bootstrap.exe, Quarantined, [8d983b06720ac96d128bb02440c1a55b],
PUP.Optional.SearchHijacker.A, C:\Users\Johanna\AppData\Local\Temp\is45637729\3195990_stp\Aug27_sweet-page.exe, Quarantined, [33f299a80d6f6fc71004734738c9817f],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Local\Temp\D683tmp\mystarttb_5.4.1.4_sambamedia.exe, Quarantined, [a87d55ec96e6979fcf521549fa0703fd],
PUP.Optional.SearchProtect.A, C:\Windows\apppatch\apppatch64\SPVCLdr64.dll, Quarantined, [022373cee49852e452d88c1c52af03fd],
PUP.Optional.SmartBar, C:\Windows\Installer\MSIA04F.tmp, Quarantined, [170ee8596b115cdad98b31fd976954ac],
PUP.Optional.SnapDo.A, C:\Windows\Installer\b5786.msi, Delete-on-Reboot, [949182bf68142c0a3146366915ec28d8],
PUP.Optional.Vitruvian.A, C:\Program Files (x86)\Mozilla Firefox\browser\defaults\preferences\!vitruvian-csp.js, Quarantined, [d352142d146800365ebae957e61d2ad6],
PUP.Optional.Vitruvian.A, C:\Program Files (x86)\Mozilla Firefox\defaults\preferences\!vitruvian-csp.js, Quarantined, [a0853809126aee48da3fe858e12229d7],
PUP.Optional.MyStart.A, C:\Users\Johanna\AppData\Local\Temp\mystart-manifest.xml, Quarantined, [8b9ad46dbcc0181e78ebcd7c0af939c7],
PUP.Optional.MyStart.A, C:\Users\Johanna\AppData\Local\Temp\mystart-toolbar.xml, Quarantined, [bc693f027a02eb4b174dc68338cbc838],
PUP.Optional.AppBud.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{e6ca9971-30ed-444a-9489-82fca50b2062}.xpi, Quarantined, [200560e1e69600364fd1bc8f4bb814ec],
PUP.Optional.Proxy.A, C:\Users\Johanna\AppData\Local\proxy.log, Quarantined, [52d33110304cd165a61b70e2d231bf41],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bnbaolfhobbbokdcmfiplbokkokobjgc_0.localstorage, Quarantined, [a77e5de46d0f5bdb1bdce272649fca36],
PUP.Optional.FocusBase.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{2b929fe1-284b-4766-afb9-19b0915b99b0}.xpi, Quarantined, [ec39e55ca1dbb97dac570951bd4621df],
PUP.Optional.MyStartTB.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\mystarttb.xml, Quarantined, [e83d9fa2fe7e68cedf9c691662a1c937],
PUP.Optional.SweetPage.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\sweet-page.xml, Quarantined, [65c07ac75e1e86b01d862188c73df20e],
PUP.Optional.SearchProtect, C:\Windows\apppatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, Quarantined, [1411b28fb2ca79bdb99cc9f039cb6e92],
PUP.Optional.ReMarkable.A, C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage, Quarantined, [8e97350cc4b87bbbaf8c0eac976d6a96],
PUP.Optional.ReMarkable.A, C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.re-markable00.re-markable.net_0.localstorage-journal, Quarantined, [fc2992af1567d5616bd05c5e7c889f61],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\alert.json, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\geodata.xml, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\guid.dat, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\preferences.dat, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\stats.dat, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\uninstallFF.dat, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\version.xml, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\weatherbutton_prefs.xml, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\apps\EULA\net.vmn.www.alexa\AlexaAppEULA.txt, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\coupons\merchants.txt, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\coupons\notifications.dat, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\search\mystarttb-search-history.xml, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\weather\65cb65af5c80b49bae5aeea84ccbf584, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\weather\f402b901d6bccb492c9fcd83d0b74fad, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\weather\forecasts_cache.xml, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.MyStartTB.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\mystarttb\weather\observations_cache.xml, Quarantined, [6fb654ed601c4fe7fd47c84de12250b0],
PUP.Optional.Extutil.A, C:\Users\Johanna\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\bk.js, Quarantined, [ab7a370a403cb87ea5d3f63145be5fa1],
PUP.Optional.Extutil.A, C:\Users\Johanna\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\cs.js, Quarantined, [ab7a370a403cb87ea5d3f63145be5fa1],
PUP.Optional.Extutil.A, C:\Users\Johanna\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\manifest.json, Quarantined, [ab7a370a403cb87ea5d3f63145be5fa1],
PUP.Optional.Managera.A, C:\Users\Johanna\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js, Quarantined, [0e1720212854c76fbcbd77b011f28c74],
PUP.Optional.Managera.A, C:\Users\Johanna\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json, Quarantined, [0e1720212854c76fbcbd77b011f28c74],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\background.html, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\bootstrap.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\chrome.manifest, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\extension_info.json, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\install.rdf, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\AppFramework\appAPI_bg.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\AppFramework\appAPI_browseraction.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\AppFramework\appAPI_common.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\AppFramework\appAPI_content.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\AppFramework\appAPI_settings.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\AppFramework\appAPI_webrequest.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\AppFramework\jquery.min.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\CanvasFramework\canvasscript_engine.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\CanvasFramework\canvas_bg.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\CanvasFramework\md5.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\CanvasFramework\registry.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\CanvasFramework\webrequest.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\backgroundscript_engine.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\base.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\browser.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\chrome_windows.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\console.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\content_proxy.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\framework.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\i18n.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\invoke_async.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\io.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\lang.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\legacy.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\message_target.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\messaging.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\storage.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\timer.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\uninstall.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\userscript_client.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\userscript_engine.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\utils.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework\xhr.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui\browser_button.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui\contentNotification.tmpl, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui\contentNotificationStyle.tmpl, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui\content_notifications.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui\context_menu.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui\framework_api.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui\notifications.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui\options.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\framework-ui\ui_base.js, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\icons\button.png, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\icons\icon100.png, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\icons\icon128.png, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\icons\icon32.png, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.BrowseSafe.A, C:\Users\Johanna\AppData\Roaming\Mozilla\Firefox\Profiles\vyn29is2.default\extensions\{1D10EB57-E111-EA32-C58F-B1EAAEAE1962}\icons\icon48.png, Quarantined, [51d473ce057791a50d63230ab54e13ed],
PUP.Optional.MySafeProxy.A, C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.11.0\AddonINFDE-54203497dc421.exe, Quarantined, [879eb48d750769cdd47661d8857e57a9],
PUP.Optional.MySafeProxy.A, C:\Windows\Temp\XTRM Group Ltd\MySafeProxy\1.0.11.0\updatefile.xml, Quarantined, [879eb48d750769cdd47661d8857e57a9],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com\bootstrap.js, Quarantined, [58cde061c6b61c1a5e721924af544db3],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com\browser.js, Quarantined, [58cde061c6b61c1a5e721924af544db3],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com\browser.xul, Quarantined, [58cde061c6b61c1a5e721924af544db3],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com\chrome.manifest, Quarantined, [58cde061c6b61c1a5e721924af544db3],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com\icon-48.png, Quarantined, [58cde061c6b61c1a5e721924af544db3],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com\icon-64.png, Quarantined, [58cde061c6b61c1a5e721924af544db3],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com\install.rdf, Quarantined, [58cde061c6b61c1a5e721924af544db3],
PUP.Optional.TermTutor.A, C:\Program Files (x86)\Mozilla Firefox\extensions\termtutor@termtutor.com\plugin-api.js, Quarantined, [58cde061c6b61c1a5e721924af544db3],
PUP.Optional.Conduit, C:\Users\Johanna\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "suggest_url": "hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}",), Replaced,[e243e35e99e363d3989de6aa7e875aa6]
Physical Sectors: 0
(No malicious items detected)
(end)
AdwCleaner Logfile: Code:
# AdwCleaner v4.102 - Report created 28/11/2014 at 18:41:13
# Updated 23/11/2014 by Xplode
# Database : 2014-11-27.1 [Live]
# Operating System : Windows 8.1 (64 bits)
# Username : Johanna - JOHANNASPC
# Running from : C:\Users\Johanna\Desktop\AdwCleaner_4.102.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\Program Files (x86)\App Bud
***** [ Scheduled Tasks ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****
***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v31.0 (x86 en-US)
-\\ Google Chrome v37.0.2062.103
-\\ Opera v26.0.1656.24
*************************
AdwCleaner[R0].txt - [35084 octets] - [23/11/2014 17:06:46]
AdwCleaner[R1].txt - [1020 octets] - [28/11/2014 18:39:58]
AdwCleaner[S0].txt - [33073 octets] - [23/11/2014 17:08:12]
AdwCleaner[S1].txt - [898 octets] - [28/11/2014 18:41:13]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [957 octets] ########## --- --- ---
JRT Logfile: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 8.1 x64
Ran by Johanna on 30.11.2014 at 11:34:05,46
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util focusbase
~~~ Files
Successfully deleted: [File] "C:\Windows\wininit.ini"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\pcdr"
Successfully deleted: [Folder] "C:\Users\Johanna\AppData\Roaming\pcdr"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.11.2014 at 11:37:43,89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- --- ---
Außerdem habe ich gestern ein Pop-Up von Avast! bemerkt, in dem eine Anwendung (ich glaube sie hieß irgendwas mit "malware-gen") von Avast! blockiert wurde.
Mit freundlichen Grüßen,
Johanna15 |