Kaspersky und Eset hat nichts gefunden
Malware bytes Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 04.12.17
Scan-Zeit: 15:58
Protokolldatei: 8c995eec-d903-11e7-a556-901b0ee1e12f.json
Administrator: Ja
-Softwaredaten-
Version: 3.3.1.2183
Komponentenversion: 1.0.236
Version des Aktualisierungspakets: 1.0.3406
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 15063.726)
CPU: x64
Dateisystem: NTFS
Benutzer: PC20140721\Mitarbeiter
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Ergebnis: Abgeschlossen
Gescannte Objekte: 398334
Erkannte Bedrohungen: 20
In die Quarantäne verschobene Bedrohungen: 20
Abgelaufene Zeit: 3 Min., 12 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 6
PUP.Optional.Widdit, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [11275], [244962],1.0.3406
PUP.Optional.Widdit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [11275], [244962],1.0.3406
PUP.Optional.Widdit, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}, In Quarantäne, [11275], [244962],1.0.3406
PUP.Optional.Widdit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}, In Quarantäne, [11275], [244962],1.0.3406
PUP.Optional.Widdit, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}, In Quarantäne, [11275], [244962],1.0.3406
PUP.Optional.ASK, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{D984AD72-CB3E-4074-984C-B831B3B4CDAA}, In Quarantäne, [471], [258454],1.0.3406
Registrierungswert: 13
PUP.Optional.Widdit, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|SUGGESTIONSURL_JSON, In Quarantäne, [11275], [244962],1.0.3406
PUP.Optional.Widdit, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|SUGGESTIONSURL_JSON, In Quarantäne, [11275], [244962],1.0.3406
PUP.Optional.Widdit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|SUGGESTIONSURL_JSON, In Quarantäne, [11275], [244965],1.0.3406
PUP.Optional.Widdit, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|SUGGESTIONSURL_JSON, In Quarantäne, [11275], [244965],1.0.3406
PUP.Optional.CertifiedTB, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TOPRESULTURLFALLBACK, In Quarantäne, [7537], [182839],1.0.3406
PUP.Optional.CertifiedTB, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, [7537], [182839],1.0.3406
PUP.Optional.CertifiedTB, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|TOPRESULTURLFALLBACK, In Quarantäne, [7537], [182839],1.0.3406
PUP.Optional.CertifiedTB, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|URL, In Quarantäne, [7537], [182839],1.0.3406
PUP.Optional.ASK, HKU\S-1-5-21-2585236328-3202722475-102761346-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{D984AD72-CB3E-4074-984C-B831B3B4CDAA}|URL, In Quarantäne, [471], [258454],1.0.3406
PUP.Optional.CertifiedTB, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TOPRESULTURLFALLBACK, In Quarantäne, [7537], [182840],1.0.3406
PUP.Optional.CertifiedTB, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, In Quarantäne, [7537], [182840],1.0.3406
PUP.Optional.CertifiedTB, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|TOPRESULTURLFALLBACK, In Quarantäne, [7537], [182840],1.0.3406
PUP.Optional.CertifiedTB, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{afdbddaa-5d3f-42ee-b79c-185a7020515b}|URL, In Quarantäne, [7537], [182840],1.0.3406
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Datei: 1
PUP.Optional.BundleInstaller, C:\USERS\MITARBEITER\DOWNLOADS\VLC-2.1.3-WIN32.EXE, In Quarantäne, [19], [425688],1.0.3406
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
(end) ADW Code:
# AdwCleaner 7.0.4.0 - Logfile created on Wed Nov 29 16:44:49 2017
# Updated on 2017/27/10 by Malwarebytes
# Running on Windows 10 Pro (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support
***** [ Services ] *****
No malicious services deleted.
***** [ Folders ] *****
Deleted: C:\SoloApp
Deleted: C:\Users\Mitarbeiter\AppData\Local\Downloaded Installations\{DAD82379-C684-4D04-83D5-2B9934A9C362}
Deleted: C:\SoftwareUpdater
***** [ Files ] *****
No malicious files deleted.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks deleted.
***** [ Registry ] *****
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\watch4.de
Deleted: [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.watch4.de
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Search|Search Bar [http:\\search.certified-toolbar.com?si=66920&tid=6787&ver=6.4&ts=1380492000000.000008&tguid=66920-6787-1395510948643-129258-b5678&st=chrome&q=]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Search|Search Bar [http:\\search.certified-toolbar.com?si=66920&tid=6787&ver=6.4&ts=1380492000000.000008&tguid=66920-6787-1395510948643-129258-b5678&st=chrome&q=]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Search|Search Page [http:\\search.certified-toolbar.com?si=66920&tid=6787&ver=6.4&ts=1380492000000.000008&tguid=66920-6787-1395510948643-129258-b5678&st=chrome&q=]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Search|Search Page [http:\\search.certified-toolbar.com?si=66920&tid=6787&ver=6.4&ts=1380492000000.000008&tguid=66920-6787-1395510948643-129258-b5678&st=chrome&q=]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\SearchUrl|(Default) [http:\\search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=5.7&ts=1391554800000.000000&tguid=66920-6787-1395510948643-129258-b5678&q=%s]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\SearchUrl|(Default) [http:\\search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=5.7&ts=1391554800000.000000&tguid=66920-6787-1395510948643-129258-b5678&q=%s]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\SearchURI| [http:\\search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=6.4&ts=1380492000000.000008&tguid=66920-6787-1395510948643-129258-b5678&q=%s]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\SearchURI| [http:\\search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=6.4&ts=1380492000000.000008&tguid=66920-6787-1395510948643-129258-b5678&q=%s]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\SearchURI|(Default) [http:\\search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=5.7&ts=1391554800000.000000&tguid=66920-6787-1395510948643-129258-b5678&q=%s]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\SearchURI|(Default) [http:\\search.certified-toolbar.com?si=66920&st=bs&tid=6787&ver=5.7&ts=1391554800000.000000&tguid=66920-6787-1395510948643-129258-b5678&q=%s]
Deleted: [Key] - HKU\S-1-5-21-2585236328-3202722475-102761346-1000\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{A25E7121-3DD8-41B3-855B-756C5BC45449}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\chip 1-click download service
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries deleted.
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries deleted.
*************************
::Tracing keys deleted
::Winsock settings cleared
::IE policies deleted
::Chrome policies deleted
::Additional Actions: 0
*************************
C:/AdwCleaner/AdwCleaner[S0].txt - [4082 B] - [2017/11/29 16:44:28]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ########## |