GMER Logfile: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-03-29 14:39:23
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000034 LITEONIT_LGT-256M6G rev.DG86201 238,47GB
Running: Gmer-19357.exe; Driver: C:\Users\Kristina\AppData\Local\Temp\uxtdipog.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1544] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1544] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1544] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1544] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1544] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffa46141f6a 4 bytes [14, 46, FA, 7F]
.text C:\Program Files\Intel\WiFi\bin\EvtEng.exe[1544] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffa46141f82 4 bytes [14, 46, FA, 7F]
.text C:\WINDOWS\system32\mfevtps.exe[1836] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\system32\mfevtps.exe[1836] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\system32\mfevtps.exe[1836] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\system32\mfevtps.exe[1836] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2072] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2072] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2072] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe[2072] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2300] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2300] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2300] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe[2300] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[2404] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[2404] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[2404] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe[2404] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2752] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2752] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2752] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2752] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\CSP\1.3.336.0\McCSPServiceHost.exe[3144] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\CSP\1.3.336.0\McCSPServiceHost.exe[3144] C:\WINDOWS\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\CSP\1.3.336.0\McCSPServiceHost.exe[3144] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\CSP\1.3.336.0\McCSPServiceHost.exe[3144] C:\WINDOWS\system32\psapi.dll!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[3084] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffa46141f6a 4 bytes [14, 46, FA, 7F]
.text C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe[3084] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffa46141f82 4 bytes [14, 46, FA, 7F]
.text C:\WINDOWS\Explorer.EXE[6012] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\Explorer.EXE[6012] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\Explorer.EXE[6012] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\WINDOWS\Explorer.EXE[6012] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[7060] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[7060] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[7060] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe[7060] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5296] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5296] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5296] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[5296] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[2628] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[2628] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[2628] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[2628] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\iTunes\iTunesHelper.exe[4628] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffa46141f6a 4 bytes [14, 46, FA, 7F]
.text C:\Program Files\iTunes\iTunesHelper.exe[4628] C:\WINDOWS\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffa46141f82 4 bytes [14, 46, FA, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[5116] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffa4f8d169a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[5116] C:\WINDOWS\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffa4f8d16a2 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[5116] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffa4f8d181a 4 bytes [8D, 4F, FA, 7F]
.text C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe[5116] C:\WINDOWS\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffa4f8d1832 4 bytes [8D, 4F, FA, 7F]
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [5032:6620] fffff96000988b90
---- Processes - GMER 2.1 ----
Library C:\ProgramData\LenovoTransition\Server\x64\Windows7.SensorAndLocation.dll (*** suspicious ***) @ C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [2220] (FILE NOT FOUND) 000000c1f9aa0000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- --- --- --- Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.03.2015
Suchlauf-Zeit: 10:55:15
Logdatei: suchlauf.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.03.29.03
Rootkit Datenbank: v2015.03.26.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Kristina
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 363784
Verstrichene Zeit: 7 Min, 11 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, 4208, , [2e192823f7933cfa3298e5d44db4d030]
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 6
PUP.Optional.SearchProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, , [2e192823f7933cfa3298e5d44db4d030],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3852607773-491357534-3998752114-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, , [f94e9bb0f793da5ca2432506c53edb25],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SearchProtect, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, , [9fa880cbe5a5ca6c20dfc08201047888],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT, , [02454efd3357c274a448a0461ae9d927],
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD, , [1e29bf8c1377d066890a1ac642c1748c],
Registrierungswerte: 4
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\SEARCHPROTECT|InstallDir, C:\PROGRA~2\SearchProtect, , [02454efd3357c274a448a0461ae9d927]
PUP.Optional.SearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\SPPD|ImagePath, \??\C:\WINDOWS\system32\drivers\SPPD.sys, , [1e29bf8c1377d066890a1ac642c1748c]
PUP.Optional.Trovi.A, HKU\S-1-5-21-3852607773-491357534-3998752114-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|URL, hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=ME1446586-EA9A-48E7-AFA7-5A46E98FB637&SearchSource=58&CUI=&UM=8&UP=SP37B1D47F-64B6-4F94-9C27-280E242A1A11&q={searchTerms}&SSPV=, , [9bac0546cbbf5adc5737a0ae45c01de3]
PUP.Optional.Trovi.A, HKU\S-1-5-21-3852607773-491357534-3998752114-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|DisplayName, Trovi, , [aa9dae9d3c4e78be335bca84e61fe818]
Registrierungsdaten: 2
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll),,[95b21833fa90082e7c4ec8f14bb6b749]
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll, Gut: (), Schlecht: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll),,[8cbbc5863b4fa690bb0fc9f08081c13f]
Ordner: 25
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\SearchProtect, , [7ec995b6fe8cd066ec35b6d82fd46799],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\SearchProtect\SearchProtect, , [7ec995b6fe8cd066ec35b6d82fd46799],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\SearchProtect\SearchProtect\rep, , [7ec995b6fe8cd066ec35b6d82fd46799],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\SearchProtect\SearchProtect\STG, , [7ec995b6fe8cd066ec35b6d82fd46799],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\SearchProtect\UI, , [7ec995b6fe8cd066ec35b6d82fd46799],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\SearchProtect\UI\rep, , [7ec995b6fe8cd066ec35b6d82fd46799],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\avaavxvyex, , [b4933d0e9feb68cee9a3a60b798af709],
Dateien: 106
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, , [2e192823f7933cfa3298e5d44db4d030],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, , [bd8aa8a32a6095a17d4df7c239c8ed13],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, , [22250d3e9af020168743e1d85ba67987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64Loader.dll, , [95b21833fa90082e7c4ec8f14bb6b749],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32Loader.dll, , [8cbbc5863b4fa690bb0fc9f08081c13f],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\avaavxvyex\pbqrmvbub, , [80c7a0ab26647fb755753386d829ce32],
PUP.Optional.SearchProtect.A, C:\Windows\apppatch\apppatch64\VCLdr64.dll, , [9fa8a3a8503af343e5e5b00959a8758b],
PUP.Optional.SearchProtect.A, C:\Windows\apppatch\nbin\VC32Loader.dll, , [f0572a211377ed493892f2c7bc45ff01],
PUP.Optional.VisualDiscovery.A, C:\Windows\System32\VisualDiscoveryOff.ini, , [cc7b63e8fd8dbb7b787c2e87c340b64a],
PUP.Optional.VisualDiscovery.A, C:\Windows\SysWOW64\VisualDiscoveryOff.ini, , [2b1c4dfe45459b9b84707144e51e8080],
PUP.Optional.VisualDiscovery.A, C:\Windows\SysWOW64\VisualDiscovery.ini, , [ef58d7743c4edc5a1cd9199ca261837d],
PUP.Optional.Trovi.A, C:\Users\Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\2rdgd1bv.default\searchplugins\trovi.xml, , [3c0bd378e6a4cc6a705f6553f60dc43c],
PUP.Optional.SearchProtect.A, C:\Windows\System32\Tasks\avaavxvyex, , [96b14a01b3d7a78f8a02f2cbac57e21e],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\CRASH_REPORT_P1428_T392_D2015_03_02_T19_54_51.txt, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPtool.dll, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\sptool.dll_1427049411243, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.pun, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\cfi.bin, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\edk.bin, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\pni.bin, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\trn.bin, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\RN32.dll, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPtool64.exe, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC32.dll, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\VC64.dll, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.css, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.html, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\defaults.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def-grey.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-dia.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\SP_DialogBG.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\DialogAPI.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js, , [1b2c99b23258979f1f357cad996c7987],
PUP.Optional.SearchProtect, C:\Windows\apppatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, , [bd8aa7a461297eb8ba49d46f986d758b],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, , [7ec995b6fe8cd066ec35b6d82fd46799],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, , [7ec995b6fe8cd066ec35b6d82fd46799],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, , [7ec995b6fe8cd066ec35b6d82fd46799],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\avaavxvyex\bahvxfk, , [b4933d0e9feb68cee9a3a60b798af709],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\avaavxvyex\mkfvxfk, , [b4933d0e9feb68cee9a3a60b798af709],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\avaavxvyex\pvpqbjobmlpfqlovvawq, , [b4933d0e9feb68cee9a3a60b798af709],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\avaavxvyex\qokvxfk, , [b4933d0e9feb68cee9a3a60b798af709],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\avaavxvyex\rfobmlpfqlovvawq, , [b4933d0e9feb68cee9a3a60b798af709],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\avaavxvyex\rpboobmlpfqlovvawq, , [b4933d0e9feb68cee9a3a60b798af709],
PUP.Optional.SearchProtect.A, C:\Users\Kristina\AppData\Local\avaavxvyex\ycfvxfk, , [b4933d0e9feb68cee9a3a60b798af709],
PUP.Optional.Trovi.A, C:\Users\Kristina\AppData\Roaming\Mozilla\Firefox\Profiles\2rdgd1bv.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=ME1446586-EA9A-48E7-AFA7-5A46E98FB637&SearchSource=69&CUI=&SSPV=&Lay=1&UM=8&UP=SP37B1D47F-64B6-4F94-9C27-280E242A1A11");), ,[53f4a8a31f6b53e3e97e77c08c7a5ca4]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Der Virenscan liefert keine Befunde! |