GMER: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2015-06-10 20:40:10
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\0000002d ST1000LM014-1EJ164 rev.SM14 931,51GB
Running: Gmer-19357.exe; Driver: C:\Users\Smigel\AppData\Local\Temp\kxrdqaod.sys
---- Threads - GMER 2.1 ----
Thread C:\WINDOWS\system32\csrss.exe [724:748] fffff960008a02d0
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:2952] 00000000001615f6
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:4012] 00000000000ce6a0
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:4028] 00000000000d3720
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:2140] 0000000000129750
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:6932] 0000000000131b40
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:4088] 0000000000131d10
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:9840] 0000000000131b40
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:8508] 0000000000131d10
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:9784] 0000000000131b40
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:9864] 0000000000131d10
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:6996] 0000000000131b40
Thread C:\WINDOWS\SYSTEM32\ntdll.dll [2948:3884] 0000000000131d10
---- Processes - GMER 2.1 ----
Library C:\Users\Smigel\AppData\Local\Pokki\Engine\libPokki.dll (*** suspicious ***) @ C:\Users\Smigel\AppData\Local\Pokki\Engine\HostAppService.exe [7584] (Chromium/The Chromium Authors)(2015-03-19 17:19:00) 00000000571d0000
Library C:\Users\Smigel\AppData\Local\Pokki\Engine\icudt.dll (*** suspicious ***) @ C:\Users\Smigel\AppData\Local\Pokki\Engine\HostAppService.exe [7584] (ICU Data DLL/The ICU Project)(2015-01-04 04:06:14) 000000005b670000
Library C:\Users\Smigel\AppData\Local\Pokki\Engine\libPokki.dll (*** suspicious ***) @ C:\Users\Smigel\AppData\Local\Pokki\Engine\HostAppService.exe [8184] (Chromium/The Chromium Authors)(2015-03-19 17:19:00) 00000000571d0000
Library C:\Users\Smigel\AppData\Local\Pokki\Engine\icudt.dll (*** suspicious ***) @ C:\Users\Smigel\AppData\Local\Pokki\Engine\HostAppService.exe [8184] (ICU Data DLL/The ICU Project)(2015-01-04 04:06:14) 000000005b670000
Library C:\Users\Smigel\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll (*** suspicious ***) @ C:\Users\Smigel\AppData\Local\Pokki\Engine\HostAppService.exe [8184](2015-01-04 04:06:14) 000000005a2d0000
Library C:\Users\Smigel\AppData\Local\Pokki\Engine\avcodec-54.dll (*** suspicious ***) @ C:\Users\Smigel\AppData\Local\Pokki\Engine\HostAppService.exe [8184](2015-01-04 04:06:14) 0000000050be0000
Library C:\Users\Smigel\AppData\Local\Pokki\Engine\avutil-51.dll (*** suspicious ***) @ C:\Users\Smigel\AppData\Local\Pokki\Engine\HostAppService.exe [8184](2015-01-04 04:06:14) 000000005a2a0000
Library C:\Users\Smigel\AppData\Local\Pokki\Engine\avformat-54.dll (*** suspicious ***) @ C:\Users\Smigel\AppData\Local\Pokki\Engine\HostAppService.exe [8184](2015-01-04 04:06:14) 0000000050ba0000
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ----
Malwarebytes Anti-Malware Mittwoch morgen (noch vor den System-Scans oben): Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.06.2015
Suchlauf-Zeit: 07:07:25
Logdatei: 150610_MBAM_Scan.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.09.06
Rootkit Datenbank: v2015.06.02.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Smigel
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 429067
Verstrichene Zeit: 18 Min, 56 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 7
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugincontainer.exe, 2292, , [604ae0d8a5e5ea4c7a2fe88f41c545bb]
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\3\Plugin.exe, 3452, , [199107b1d5b51a1c61487ff847bfe719]
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\3\Plugin.exe, 152, , [199107b1d5b51a1c61487ff847bfe719]
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\2\Plugin.exe, 10668, , [a901e2d62367bd79d2d7ef8831d539c7]
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\5\Plugin.exe, 12108, , [109a9127f298d75f39702d4a16f04eb2]
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Common Files\68f7eaff-0da4-47f4-8262-425ca2a087dd\updater.exe, 7880, , [b7f3b00857330333f2b798df36d0ec14]
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\8\Plugin.exe, 6592, , [eebc8e2af496a88e5f4a0d6a10f6b44c]
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 24
PUP.Optional.CrazyScore.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Service Mgr CrazyScore, , [604ae0d8a5e5ea4c7a2fe88f41c545bb],
PUP.Optional.CrazyScore.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update Mgr CrazyScore, , [b7f3b00857330333f2b798df36d0ec14],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{f439aa7e-a2a0-4635-99a2-164180e848ca}, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{f439aa7e-a2a0-4635-99a2-164180e848ca}, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{31d48cad-f6d9-411a-a0c9-c1f051511a86}, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B81A3063-CE6C-4F9A-AEBD-5DDD0EA805A0}, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B81A3063-CE6C-4F9A-AEBD-5DDD0EA805A0}, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{B81A3063-CE6C-4F9A-AEBD-5DDD0EA805A0}, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{31d48cad-f6d9-411a-a0c9-c1f051511a86}, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{31d48cad-f6d9-411a-a0c9-c1f051511a86}, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{F439AA7E-A2A0-4635-99A2-164180E848CA}, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Crazy Score, , [2684595f47439c9af7b2fc7b61a5f808],
PUP.Optional.Dregol.C, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Run_Dregol, , [6941e1d73555ba7c41c9cea96e98b24e],
PUP.Optional.Dregol.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\ihokndmjeombjojnfkmapfnjeghjohim, , [c0ea4d6babdfd85efa23599855ae03fd],
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [a307deda15750b2b33c13745dd2843bd],
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\mystartsearchSoftware, , [2e7c09af84061e189ce6aa59cf355ba5],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, , [77338830503aaa8cbe1e87e7aa5b5aa6],
PUP.Optional.Dregol.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ihokndmjeombjojnfkmapfnjeghjohim, , [a5052a8e2d5dd26468b5c52cc73c31cf],
PUP.Optional.WindowsMangerProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\WindowsMangerProtect, , [cbdfa5132c5e3006311e2adca85c7987],
PUP.Optional.Dregol.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\run_dregol, , [34764a6e454575c1140e8a673cc7817f],
PUP.Optional.Dregol.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\ihokndmjeombjojnfkmapfnjeghjohim, , [3f6ba018fe8cba7c031b4da4df24eb15],
PUP.Optional.Dregol.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, , [01a92197305aee4841b2b3c950b53fc1],
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E32EADDD-AF11-11E4-8268-C45444832470}, , [8327a3150f7bce68737819d343c0b848],
PUP.Optional.ProductSetup.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\PRODUCTSETUP, , [2f7b78405f2b73c3734e1276808509f7],
Registrierungswerte: 17
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_ir_15_24&cd=2XzuyEtN2Y1L1Qzu0CyEyDyEyEyEzztAtByEyBtD0CyE0AtCtN0D0Tzu0StCtByDyDtN1L2XzutAtFtCtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByCyBzyyE0AtDyCtGyCyDyD0EtG0DyE0DyBtGtCtAzzzytGtC0E0FyEtAtCyEyB0A0C0CyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyDzz0A0EyEzztBtG0E0E0DzztGyEyDtC0DtGzyzyzyzytGzz0C0EzzyDzz0CyDtC0F0Ezz2QtN0A0LzutBtN1B2Z1V1T1S1NzuzztCtB&cr=1460318945&ir=, , [a307deda15750b2b33c13745dd2843bd]
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_ir_15_24&cd=2XzuyEtN2Y1L1Qzu0CyEyDyEyEyEzztAtByEyBtD0CyE0AtCtN0D0Tzu0StCtByDyDtN1L2XzutAtFtCtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByCyBzyyE0AtDyCtGyCyDyD0EtG0DyE0DyBtGtCtAzzzytGtC0E0FyEtAtCyEyB0A0C0CyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyDzz0A0EyEzztBtG0E0E0DzztGyEyDtC0DtGzyzyzyzytGzz0C0EzzyDzz0CyDtC0F0Ezz2QtN0A0LzutBtN1B2Z1V1T1S1NzuzztCtB&cr=1460318945&ir=, , [4763f0c83f4bdd59d2225b21f0152ed2]
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|FaviconPath, C:\Users\Smigel\AppData\LocalLow\Microsoft\Internet Explorer\Services\Run_Dregol.ico, , [15951d9bf397ef47787c92eaab5a6997]
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, Dregol, , [74362b8df199a19511e30379ad58728e]
PUP.Optional.Dregol.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|DisplayName, Dregol, , [d2d89b1df99196a0e70ddba12bda6f91]
PUP.Optional.Dregol.C, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\Run_Dregol\\, , [e1c909afbcce65d1ca6ecb214ab956aa]
PUP.Optional.QuickSearch.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_searchff@gmail.com, C:\Users\Smigel\AppData\Roaming\Mozilla\Firefox\Profiles\4qsfzn18.default-1426112488545\extensions\quick_searchff@gmail.com, , [9911b701b4d6d660543ed814db28ed13]
PUP.Optional.Dregol.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_ir_15_24&cd=2XzuyEtN2Y1L1Qzu0CyEyDyEyEyEzztAtByEyBtD0CyE0AtCtN0D0Tzu0StCtByDyDtN1L2XzutAtFtCtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByCyBzyyE0AtDyCtGyCyDyD0EtG0DyE0DyBtGtCtAzzzytGtC0E0FyEtAtCyEyB0A0C0CyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyDzz0A0EyEzztBtG0E0E0DzztGyEyDtC0DtGzyzyzyzytGzz0C0EzzyDzz0CyDtC0F0Ezz2QtN0A0LzutBtN1B2Z1V1T1S1NzuzztCtB&cr=1460318945&ir=, , [01a92197305aee4841b2b3c950b53fc1]
PUP.Optional.Dregol.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, hxxp://www.dregol.com/results.php?f=4&q={searchTerms}&a=drg_ir_15_24&cd=2XzuyEtN2Y1L1Qzu0CyEyDyEyEyEzztAtByEyBtD0CyE0AtCtN0D0Tzu0StCtByDyDtN1L2XzutAtFtCtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByCyBzyyE0AtDyCtGyCyDyD0EtG0DyE0DyBtGtCtAzzzytGtC0E0FyEtAtCyEyB0A0C0CyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyDzz0A0EyEzztBtG0E0E0DzztGyEyDtC0DtGzyzyzyzytGzz0C0EzzyDzz0CyDtC0F0Ezz2QtN0A0LzutBtN1B2Z1V1T1S1NzuzztCtB&cr=1460318945&ir=, , [1f8beace9ded5ed881720f6dbb4a1be5]
PUP.Optional.Dregol.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|FaviconPath, C:\Users\Smigel\AppData\LocalLow\Microsoft\Internet Explorer\Services\Run_Dregol.ico, , [b9f17840d7b3092d896acdaf7e878779]
PUP.Optional.Dregol.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, Dregol, , [f0ba3c7c2b5fa294b93a6c1009fc6898]
PUP.Optional.Dregol.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|DisplayName, Dregol, , [eac0f4c41e6c33036291dba10401c937]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E32EADDD-AF11-11E4-8268-C45444832470}|FaviconURL, hxxp://homepage-web.com/favicon.ico, , [8327a3150f7bce68737819d343c0b848]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E32EADDD-AF11-11E4-8268-C45444832470}|FaviconURLFallback, hxxp://homepage-web.com/favicon.ico, , [7436397f96f4d3632cbfa5471fe4f20e]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E32EADDD-AF11-11E4-8268-C45444832470}|TopResultURL, hxxp://search.homepage-web.com/?src=omnibox&partner=acer&q={searchTerms}, , [95154a6e2e5c93a354978b6156ad1fe1]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E32EADDD-AF11-11E4-8268-C45444832470}|URL, hxxp://search.homepage-web.com/?src=omnibox&partner=acer&q={searchTerms}, , [6e3ceccc0f7bef473fac6884fd06f40c]
PUP.Optional.ProductSetup.A, HKU\S-1-5-21-2344713175-4130731840-4258726450-1001\SOFTWARE\PRODUCTSETUP|tb, , [2f7b78405f2b73c3734e1276808509f7],
Registrierungsdaten: 2
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1430425496&from=cor&uid=ST1000LM014-1EJ164_W381ZDPWXXXXW381ZDPW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1430425496&from=cor&uid=ST1000LM014-1EJ164_W381ZDPWXXXXW381ZDPW&q={searchTerms}),,[bceeb0084f3b8fa7f3ee5bd4f90de020]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1430425496&from=cor&uid=ST1000LM014-1EJ164_W381ZDPWXXXXW381ZDPW&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1430425496&from=cor&uid=ST1000LM014-1EJ164_W381ZDPWXXXXW381ZDPW&q={searchTerms}),,[a604ad0b94f66dc905dc81ae6f9721df]
Ordner: 21
PUP.Optional.UpdateProc.A, C:\Users\Smigel\AppData\Roaming\Run_dregol\UpdateProc, , [575313a52f5b5cdacd86dca94eb7f40c],
PUP.Optional.UpdateProc.A, C:\Users\Smigel\AppData\Roaming\Run_dregol, , [575313a52f5b5cdacd86dca94eb7f40c],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, , [9a107b3db1d91323563759714fb4cd33],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, , [9a107b3db1d91323563759714fb4cd33],
PUP.Optional.Dregol.A, C:\Program Files (x86)\Run_Dregol, , [d7d3892f0189102620342db820e38b75],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugincontainer, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\2, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\2bak, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\3, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\3bak, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\5, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\8, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Common Files\68f7eaff-0da4-47f4-8262-425ca2a087dd, , [c2e8dade2565f1454232db0d1be8d22e],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Common Files\68f7eaff-0da4-47f4-8262-425ca2a087dd\updater, , [c2e8dade2565f1454232db0d1be8d22e],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Crazy Score, , [9f0b586094f69e9802733badd23143bd],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Crazy Score\Extensions, , [9f0b586094f69e9802733badd23143bd],
PUP.Optional.CrazyScore.A, C:\Users\Smigel\AppData\Local\Temp\Crazy Score, , [57539c1c771338fe87effcecf211d030],
PUP.Optional.CrazyScore.A, C:\Users\Smigel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kknfkgbilaemfjcjjfgemgcgbajbgadd\1.0.5637.26466_0, , [44661a9e4c3e74c21dedc3b711f5a55b],
PUP.Optional.CrazyScore.A, C:\Users\Smigel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kknfkgbilaemfjcjjfgemgcgbajbgadd, , [44661a9e4c3e74c21dedc3b711f5a55b],
Dateien: 49
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugincontainer.exe, , [604ae0d8a5e5ea4c7a2fe88f41c545bb],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\3\Plugin.exe, , [199107b1d5b51a1c61487ff847bfe719],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\2\Plugin.exe, , [a901e2d62367bd79d2d7ef8831d539c7],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\5\Plugin.exe, , [109a9127f298d75f39702d4a16f04eb2],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Common Files\68f7eaff-0da4-47f4-8262-425ca2a087dd\updater.exe, , [b7f3b00857330333f2b798df36d0ec14],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\8\Plugin.exe, , [eebc8e2af496a88e5f4a0d6a10f6b44c],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Crazy Score\Extensions\f439aa7e-a2a0-4635-99a2-164180e848ca.dll, , [31792e8ae8a2b87e4d554d1505fe37c9],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugincontainer.bak, , [d5d5f6c28ffbb97d4b5eeb8ced19659b],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\2bak\Plugin.exe, , [abff05b34347e3536049b8bf8680d12f],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\plugins\3bak\Plugin.exe, , [b7f3b107c6c41a1cfdac53242cda3dc3],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Crazy Score\Uninstaller.exe, , [2684595f47439c9af7b2fc7b61a5f808],
PUP.Optional.Dregol.C, C:\Program Files (x86)\Run_Dregol\uninstall.exe, , [6941e1d73555ba7c41c9cea96e98b24e],
PUP.Optional.InstallCore.C, C:\Users\Smigel\AppData\Local\Temp\cd12c26ee0d3673b97d6f2ea3eb34eb8.exe, , [dfcb8f29cbbfee48ff437eddd929af51],
PUP.Optional.InstallCore.A, C:\Users\Smigel\AppData\Local\Temp\2qO8y9dZ.exe.part, , [01a905b3a8e2e84e9616c1a737cb5ea2],
PUP.Optional.OpenCandy, C:\Users\Smigel\AppData\Local\Temp\ocpB9FA.tmp\ocpB9FB.tmp, , [1b8f843498f28fa75796f171fe08c739],
PUP.Optional.CheckOffer, C:\Users\Smigel\AppData\Local\Temp\nscCAEB.tmp\nsPage_LoadOffer.dll, , [525808b03a50be789fc9451e08fade22],
PUP.Optional.CheckOffer, C:\Users\Smigel\AppData\Local\Temp\nso13EB.tmp\nsCBHTML5.dll, , [baf068507e0c9e9897d1560d0bf7c838],
PUP.Optional.Installcore, C:\Users\Smigel\Downloads\flvplayer.exe, , [76348632a9e13600af67b94741c58b75],
PUP.Optional.InstallCore.SID.A, C:\Users\Smigel\Downloads\installer_avast_free_antivirus_German.exe, , [bbef427683073cfa0db8cfa8de283ec2],
PUP.Optional.InstallCore.A, C:\Users\Smigel\Downloads\FileZilla_3.10.2_win32-setup.exe, , [1f8b1b9dfc8e37ff8626b0b838ca8977],
PUP.Optional.Dregol.C, C:\Users\Smigel\AppData\LocalLow\Microsoft\Internet Explorer\Services\Run_Dregol.ico, , [06a49a1e08822b0b52dcffedb74c956b],
PUP.Optional.Dregol.C, C:\Users\Smigel\AppData\Local\Chromium\Application\Dregol.ico, , [f0ba7147aae0b2843205e70549babb45],
PUP.Optional.Dregol.C, C:\Users\Smigel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Dregol (2).lnk, , [6d3de3d53258c0769752d7159271ce32],
PUP.Optional.Dregol.C, C:\Users\Smigel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Dregol.lnk, , [03a7dcdcc2c8b3833dacfaf21be859a7],
PUP.Optional.Dregol.C, C:\Users\Smigel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ihokndmjeombjojnfkmapfnjeghjohim_0.localstorage, , [565412a62f5b0e282dcf15d751b2d828],
PUP.Optional.Dregol.A, C:\Windows\System32\Tasks\Run_dregol, , [3f6b1f99fc8ea19549d6955c7b8821df],
PUP.Optional.Dregol.A, C:\Windows\Tasks\Run_dregol.job, , [6446dcdcd8b2dd59968a747ddc27b14f],
PUP.Optional.Dregol.A, C:\Users\Smigel\AppData\Roaming\Mozilla\Firefox\Profiles\4qsfzn18.default-1426112488545\searchplugins\dregol.xml, , [4466c4f45436b87e130e0ee3ea1921df],
PUP.Optional.Dregol.A, C:\Users\Smigel\Desktop\Dregol.lnk, , [decc78407713aa8cd65221d044bf7b85],
PUP.Optional.MyStartSearch.A, C:\Users\Smigel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage, , [fdad48703456f73f599010eb6c97f30d],
PUP.Optional.MyStartSearch.A, C:\Users\Smigel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.mystartsearch.com_0.localstorage-journal, , [a2085167b7d325112cbd807b0bf84db3],
PUP.Optional.UpdateProc.A, C:\Users\Smigel\AppData\Roaming\Run_dregol\UpdateProc\bkup.dat, , [575313a52f5b5cdacd86dca94eb7f40c],
PUP.Optional.UpdateProc.A, C:\Users\Smigel\AppData\Roaming\Run_dregol\UpdateProc\config.dat, , [575313a52f5b5cdacd86dca94eb7f40c],
PUP.Optional.UpdateProc.A, C:\Users\Smigel\AppData\Roaming\Run_dregol\UpdateProc\info.dat, , [575313a52f5b5cdacd86dca94eb7f40c],
PUP.Optional.UpdateProc.A, C:\Users\Smigel\AppData\Roaming\Run_dregol\UpdateProc\UpdateTask.exe, , [575313a52f5b5cdacd86dca94eb7f40c],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, , [9a107b3db1d91323563759714fb4cd33],
PUP.Optional.Dregol.A, C:\Program Files (x86)\Run_Dregol\config.dat, , [d7d3892f0189102620342db820e38b75],
PUP.Optional.Dregol.A, C:\Program Files (x86)\Run_Dregol\Sqlite3.dll, , [d7d3892f0189102620342db820e38b75],
PUP.Optional.Dregol.A, C:\Program Files (x86)\Run_Dregol\uninst.dat, , [d7d3892f0189102620342db820e38b75],
PUP.Optional.CrazyScore.A, C:\ProgramData\68f7eaff-0da4-47f4-8262-425ca2a087dd\temp, , [4763eccc56342016c9aa9652b84b12ee],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Common Files\68f7eaff-0da4-47f4-8262-425ca2a087dd\updater.bak, , [c2e8dade2565f1454232db0d1be8d22e],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Crazy Score\7za.exe, , [9f0b586094f69e9802733badd23143bd],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Crazy Score\Extensions\kknfkgbilaemfjcjjfgemgcgbajbgadd.crx, , [9f0b586094f69e9802733badd23143bd],
PUP.Optional.CrazyScore.A, C:\Program Files (x86)\Crazy Score\Extensions\{0d68400f-30b4-459a-94ed-bd57e329ed5d}.xpi, , [9f0b586094f69e9802733badd23143bd],
PUP.Optional.CrazyScore.A, C:\Users\Smigel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kknfkgbilaemfjcjjfgemgcgbajbgadd\1.0.5637.26466_0\manifest.json, , [44661a9e4c3e74c21dedc3b711f5a55b],
PUP.Optional.CrazyScore.A, C:\Users\Smigel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kknfkgbilaemfjcjjfgemgcgbajbgadd\1.0.5637.26466_0\background.js, , [44661a9e4c3e74c21dedc3b711f5a55b],
PUP.Optional.CrazyScore.A, C:\Users\Smigel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kknfkgbilaemfjcjjfgemgcgbajbgadd\1.0.5637.26466_0\content.js, , [44661a9e4c3e74c21dedc3b711f5a55b],
PUP.Optional.CrazyScore.A, C:\Users\Smigel\AppData\Local\Google\Chrome\User Data\Default\Extensions\kknfkgbilaemfjcjjfgemgcgbajbgadd\1.0.5637.26466_0\icon.png, , [44661a9e4c3e74c21dedc3b711f5a55b],
PUP.Optional.Dregol.A, C:\Users\Smigel\AppData\Roaming\Mozilla\Firefox\Profiles\4qsfzn18.default-1426112488545\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.dregol.com/?f=1&a=drg_ir_15_24&cd=2XzuyEtN2Y1L1Qzu0CyEyDyEyEyEzztAtByEyBtD0CyE0AtCtN0D0Tzu0StCtByDyDtN1L2XzutAtFtCtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByCyBzyyE0AtDyCtGyCyDyD0EtG0DyE0DyBtGtCtAzzzytGtC0E0FyEtAtCyEyB0A0C0CyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyDzz0A0EyEzztBtG0E0E0DzztGyEyDtC0DtGzyzyzyzytGzz0C0EzzyDzz0CyDtC0F0Ezz2QtN0A0LzutBtN1B2Z1V1T1S1NzuzztCtB&cr=1460318945&ir=");), ,[81297345602a43f3690b5426ec1a9e62]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Malwarebytes Antimalware Mittwoch Abend (nach den System-Scans und nach Abschalten der Add-Ons): Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.06.2015
Suchlauf-Zeit: 21:12:20
Logdatei: 150610_MBAM_Scan_abends.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.10.05
Rootkit Datenbank: v2015.06.02.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Smigel
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 428477
Verstrichene Zeit: 21 Min, 31 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 0
(Keine schädliche Elemente gefunden)
Dateien: 1
PUP.Optional.Dregol.A, C:\Users\Smigel\AppData\Roaming\Mozilla\Firefox\Profiles\4qsfzn18.default-1426112488545\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.dregol.com/?f=1&a=drg_ir_15_24&cd=2XzuyEtN2Y1L1Qzu0CyEyDyEyEyEzztAtByEyBtD0CyE0AtCtN0D0Tzu0StCtByDyDtN1L2XzutAtFtCtCtFtAtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StByCyBzyyE0AtDyCtGyCyDyD0EtG0DyE0DyBtGtCtAzzzytGtC0E0FyEtAtCyEyB0A0C0CyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0DyDzz0A0EyEzztBtG0E0E0DzztGyEyDtC0DtGzyzyzyzytGzz0C0EzzyDzz0CyDtC0F0Ezz2QtN0A0LzutBtN1B2Z1V1T1S1NzuzztCtB&cr=1460318945&ir=");), Ersetzt,[9875a51483079d997a312a511bebf30d]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) |