dieWaldfee | 30.03.2022 16:45 | Da bin ich wieder,
die SAntivirus Software konnte ich deinstalieren.
War etwas mühsig.
Hier die Logs:
MBAM Code:
Malwarebytes
www.malwarebytes.com
-Protokolldetails-
Scan-Datum: 30.03.22
Scan-Zeit: 17:15
Protokolldatei: 44db0ffa-b03c-11ec-843b-90fba62e7847.json
-Softwaredaten-
Version: 4.5.7.186
Komponentenversion: 1.0.1645
Version des Aktualisierungspakets: 1.0.53050
Lizenz: Testversion
-Systemdaten-
Betriebssystem: Windows 10 (Build 19044.1586)
CPU: x64
Dateisystem: NTFS
Benutzer: DESKTOP-M55NR5E\CaRo
-Scan-Übersicht-
Scan-Typ: Bedrohungs-Scan
Scan gestartet von: Manuell
Ergebnis: Abgeschlossen
Gescannte Objekte: 309622
Erkannte Bedrohungen: 28
In die Quarantäne verschobene Bedrohungen: 28
Abgelaufene Zeit: 12 Min., 25 Sek.
-Scan-Optionen-
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Erkennung
PUM: Erkennung
-Scan-Details-
Prozess: 0
(keine bösartigen Elemente erkannt)
Modul: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 7
PUP.Optional.WebDiscoverBrowser, HKLM\SOFTWARE\WOW6432NODE\WebDiscoverBrowser, In Quarantäne, 1730, 253915, 1.0.53050, , ame, , ,
PUP.Optional.Segurazo, HKLM\SOFTWARE\MICROSOFT\TRACING\SAntivirusService_RASAPI32, In Quarantäne, 637, 783947, 1.0.53050, , ame, , ,
PUP.Optional.Segurazo, HKLM\SOFTWARE\MICROSOFT\TRACING\SAntivirusService_RASMANCS, In Quarantäne, 637, 783947, 1.0.53050, , ame, , ,
PUP.Optional.WebDiscoverBrowser, HKU\S-1-5-21-3782980037-867170684-2201072163-1001\SOFTWARE\WebDiscoverBrowser, In Quarantäne, 1730, 253912, 1.0.53050, , ame, , ,
PUP.Optional.Segurazo, HKLM\SOFTWARE\MICROSOFT\WINDOWS\SAntivirus, In Quarantäne, 637, 783948, 1.0.53050, , ame, , ,
PUP.Optional.WebDiscoverBrowser, HKLM\SOFTWARE\WebDiscoverBrowser, In Quarantäne, 1730, 253915, 1.0.53050, , ame, , ,
PUP.Optional.Segurazo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\SAntivirus, In Quarantäne, 637, 783948, 1.0.53050, , ame, , ,
Registrierungswert: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Daten-Stream: 0
(keine bösartigen Elemente erkannt)
Ordner: 4
PUP.Optional.Segurazo, C:\PROGRAMDATA\SEGURAZO, In Quarantäne, 637, 788616, 1.0.53050, , ame, , ,
PUP.Optional.Segurazo, C:\USERS\CARO\APPDATA\ROAMING\SEGURAZOCLIENT, In Quarantäne, 637, 788617, 1.0.53050, , ame, , ,
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove, In Quarantäne, 951, 542290, , , , , ,
PUP.Optional.WinYahoo.TskLnk, C:\USERS\CARO\APPDATA\LOCAL\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}, In Quarantäne, 951, 542290, 1.0.53050, , ame, , ,
Datei: 17
PUP.Optional.WinYahoo.TskLnk, C:\USERS\CARO\APPDATA\LOCAL\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HOWTOREMOVE\HOWTOREMOVE.HTML, In Quarantäne, 951, 542290, 1.0.53050, , ame, , 92A56BD431B8EC678C73844C916017CA, 47BFA64B49B9ABF0C2DCA4F400E0137E1C29211CE6ED4196EDE1560149D13FF2
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\chromium-min.jpg, In Quarantäne, 951, 542290, , , , , 63BC75E5CF5CBA301C0A333A493C1E6C, AECF7E9F8EA60035CF8E255B99ADDBC4739C357BC9773273B682B06073AE2BBC
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\control panel-min-min.JPG, In Quarantäne, 951, 542290, , , , , D3317C08A7FD5C68AF7607B56365D7EF, E0DF11EDFC606871F3FA3E825D0A346D895CF2246372E1919F3F6B6F823855EA
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\down.png, In Quarantäne, 951, 542290, , , , , BD28C167E200A3B28D65FAD11067F767, 782AEE35F1473A0818E85C7888276AB1A92A2C6650420A6914C11D4A87017959
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\ff menu.JPG, In Quarantäne, 951, 542290, , , , , 0ACF64A62398FD3E28C0F776E080E02E, A7E228427AFE421EE317EECF714464E5ED346B2032C98F4076B01EB61D92F11F
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\ff search engine-min.png, In Quarantäne, 951, 542290, , , , , 98167327578F423AD62775F9C0DA1C08, 95E4B167F0173DB00F6BCDDE9864CC2E5DDED171506F8AB8E7B9F7863D913680
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\hp-min ff.png, In Quarantäne, 951, 542290, , , , , AFE6FD269F10B4FB4055028CE2E0F70C, F0403DEBED00E906EE26EFE1463A63347D5B7CD6EB60BB38AE0E3C3460F71693
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\hp-min ie.png, In Quarantäne, 951, 542290, , , , , C76F780F7CDEDA6D63A72E00719EAE53, 0A53A6F7C61B73B40061A401ED4C5D1E520C1D1DEC270617C5C25C8EE64A95C6
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\search engine.gif, In Quarantäne, 951, 542290, , , , , D2665D24334093AFB3D3E64E22346AC4, E5CA26785BDB836C3C234A67E991BF1C70D4E87CAA75EC43747619E64DECAA57
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\setup pages.gif, In Quarantäne, 951, 542290, , , , , D8957AB88B51AC3D91DB06AC96369BE4, 6BB5388E49AAB90AB7C85A736EAABDEB9A78CDCCA4D7A4138B00DBC1C657C8D5
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\sp-min.png, In Quarantäne, 951, 542290, , , , , C4A8846B0AAC9BEF78F6A001514ECFF5, 4E9A05BDB43137235913F0BBB1F21C35DF34E62D33F2A4F4FC9C0F15FA1346E3
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\start-min.jpg, In Quarantäne, 951, 542290, , , , , 7A52610FBA6935C9ACF2A2F38CA86F6A, 677001B0CFD9F6C824E422C5EBBC5C042ABB0CF156990064DD3170CF6F3379C8
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\HowToRemove\up.png, In Quarantäne, 951, 542290, , , , , 45B1D3F523A38E29419DC26AE6BDD253, 892E25F7363B1C4EFA5FFACD5F4CDADD01833F49EF5CEF335676D84DA871EBA0
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\conenonit, In Quarantäne, 951, 542290, , , , , CB619777338C3D254EFD0FB35C96BAD4, 8A58EC58C4E2512F7B9395CB9B404E33F3CA9EDD796ECD5DAB602570994BD88E
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\netasira, In Quarantäne, 951, 542290, , , , , 347C70F7CF3B8CFC56D75441B1CEF563, EE0A9451F853121EF60D029DC56896A199D966CCC7495299B95A83867EBF8A71
PUP.Optional.WinYahoo.TskLnk, C:\Users\CaRo\AppData\Local\{654A5316-41E2-3FAE-2C7A-1A460812E6DE}\uninstp.dat, In Quarantäne, 951, 542290, , , , , 2D9FD31BFF6F490A5DB07C932FCECC64, 9D62EE3A1C89461DCF0225449365A7E4B4A3B6A1F55E6E21B2348ED4ABDA5244
PUP.Optional.WinZipDriverUpdater, C:\1106326C-4FDA-4773-AD13-067E8F3FA936.EXE, In Quarantäne, 1758, 484645, 1.0.53050, , ame, , 00A34216BC54A715BD8A3B7427522D40, 0598520007A4C3EF9D3E34DF19129EAACC1B8C96DFB80A29BA62E0CE254743CA
Physischer Sektor: 0
(keine bösartigen Elemente erkannt)
WMI: 0
(keine bösartigen Elemente erkannt)
(end) ADW Code:
# -------------------------------
# Malwarebytes AdwCleaner 8.3.1.0
# -------------------------------
# Build: 11-18-2021
# Database: 2022-03-15.3 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-30-2022
# Duration: 00:00:12
# OS: Windows 10 Pro
# Cleaned: 12
# Failed: 0
***** [ Services ] *****
No malicious services cleaned.
***** [ Folders ] *****
Deleted C:\Program Files (x86)\Chromium
Deleted C:\Program Files (x86)\Segurazo
***** [ Files ] *****
No malicious files cleaned.
***** [ DLL ] *****
No malicious DLLs cleaned.
***** [ WMI ] *****
No malicious WMI cleaned.
***** [ Shortcuts ] *****
No malicious shortcuts cleaned.
***** [ Tasks ] *****
No malicious tasks cleaned.
***** [ Registry ] *****
Deleted HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.exe
Deleted HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.vshost.exe
Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.exe
Deleted HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.vshost.exe
Deleted HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.exe
Deleted HKLM\Software\Wow6432Node\\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|santivirusclient.vshost.exe
Deleted HKLM\System\CurrentControlSet\Services\EventLog\Application\SAntivirusSvc
Deleted HKLM\System\Setup\FirstBoot\Services\SANTIVIRUSKD
Deleted HKLM\System\Setup\FirstBoot\Services\SAntivirusIC
Deleted HKLM\System\Setup\FirstBoot\Services\SAntivirusSvc
***** [ Chromium (and derivatives) ] *****
No malicious Chromium entries cleaned.
***** [ Chromium URLs ] *****
No malicious Chromium URLs cleaned.
***** [ Firefox (and derivatives) ] *****
No malicious Firefox entries cleaned.
***** [ Firefox URLs ] *****
No malicious Firefox URLs cleaned.
***** [ Hosts File Entries ] *****
No malicious hosts file entries cleaned.
***** [ Preinstalled Software ] *****
No Preinstalled Software cleaned.
*************************
[+] Delete Tracing Keys
[+] Reset Winsock
*************************
AdwCleaner[S00].txt - [2725 octets] - [30/03/2022 17:39:03]
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ########## Das System fühlt sich nun auch schon deutlich flotter an. :pfeiff:
edit: eben hat er mir dann doch wieder eine Defender Meldung von einem "defendertemperingscore" gebracht. |