| Nussbrot | 31.03.2014 13:50 | Ja also gestern ging das ganze System ein (kam nur mehr schwarzer Bildschirm das wars selbst im abgesicherten Modus ging gar nichts mehr....) musste Ihn neu aufsetzten leider da ich wirklich nicht in der Lage war was zu öffnen oder generell irgendwas zu tun.... hab mir Malwarebytes aber gleich mal runtergeladen (läuft gerade) und er hat bereits jetzt haufenweiße Sachen gefunden. Werde dir natürlich den Log sofort senden und dann auf deine weiteren Anweisungen warten. :) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 31.03.2014
Scan Time: 14:47:51
Logfile: log mw.txt
Administrator: Yes
Version: 2.00.0.1000
Malware Database: v2014.03.31.04
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7
CPU: x64
File System: NTFS
User: Fred
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 262881
Time Elapsed: 12 min, 24 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 2
PUP.Optional.Conduit.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, , [c30d98718dee53e3868e57bff30e06fa],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SearchProtect, , [b41ccc3db3c8e353989b7e0a63a02bd5],
Registry Values: 0
(No malicious items detected)
Registry Data: 3
PUP.Optional.Conduit.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll C:\Windows\system32\nvinitx.dll, Good: (), Bad: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll),,[844c4ebbdba04ee829eb9e780cf531cf]
PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll C:\Windows\SysWOW64\nvinit.dll, Good: (), Bad: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll),,[28a827e26516ef47c64e42d48a77d22e]
PUP.Optional.Conduit.A, HKU\S-1-5-21-2642864222-190109230-1055298897-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?gd=&ctid=CT3324760&octid=EB_ORIGINAL_CTID&ISID=MBB4E9A61-84DD-43E2-80D8-E247D3964CCB&SearchSource=55&CUI=&UM=2&UP=SPD1042488-760D-4E2D-B11D-E199CFFD7782&SSPV=, Good: (hxxp://www.google.com), Bad: (hxxp://search.conduit.com/?gd=&ctid=CT3324760&octid=EB_ORIGINAL_CTID&ISID=MBB4E9A61-84DD-43E2-80D8-E247D3964CCB&SearchSource=55&CUI=&UM=2&UP=SPD1042488-760D-4E2D-B11D-E199CFFD7782&SSPV=),,[12bed831e19a5ed803a51ee5da2ace32]
Folders: 18
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, , [b41ccc3db3c8e353989b7e0a63a02bd5],
Files: 85
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll, , [844c4ebbdba04ee829eb9e780cf531cf],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll, , [28a827e26516ef47c64e42d48a77d22e],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, , [c30d98718dee53e3868e57bff30e06fa],
PUP.Optional.SearchProtect.A, C:\Users\Fred\AppData\Local\Temp\nsf28F9.exe, , [517feb1e0b7066d0d054829f1de419e7],
PUP.Optional.SearchProtect.A, C:\Users\Fred\AppData\Local\Temp\nsk256F.exe, , [c50b14f55d1ea29468bc988961a04bb5],
PUP.Optional.SearchProtect.A, C:\Users\Fred\AppData\Local\Temp\nsk4DFB.exe, , [4d8347c2512acb6bc2627fa22ed36a96],
PUP.Optional.SearchProtect.A, C:\Users\Fred\AppData\Local\Temp\nsk5240.exe, , [ddf311f8accfca6cba6a4dd4d32e3ec2],
PUP.Optional.SearchProtect.A, C:\Users\Fred\AppData\Local\Temp\nsp21E5.exe, , [2ea257b2aecd0d29869ee33e21e024dc],
PUP.Optional.Conduit, C:\Users\Fred\AppData\Local\Temp\verifier.exe, , [bc141fea83f8b87eb19ef0b65da6fb05],
PUP.Optional.SearchProtect.A, C:\Users\Fred\AppData\Local\Temp\nsp48EB.exe, , [9c3455b4176473c3da4a140d9d64dd23],
PUP.Optional.Conduit, C:\Users\Fred\AppData\Local\Temp\embededstub.exe, , [913f9c6d7dfe95a191be12940003a858],
PUP.Optional.Conduit.A, C:\Users\Fred\AppData\Local\Temp\nsaFD45\SpSetup.exe, , [d4fc3bce63184ceaf02471a543bebc44],
PUP.Optional.Softonic.A, C:\Users\Fred\Downloads\SoftonicDownloader_fuer_smite.exe, , [a8283dcc83f8be78776070a778897c84],
PUP.Optional.Conduit.A, C:\Users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\oy2w8tgb.default\searchplugins\conduit-search.xml, , [02ce84855f1c5bdba1dfbe9e15ed6799],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js, , [b41ccc3db3c8e353989b7e0a63a02bd5],
PUP.Optional.Conduit.A, C:\Users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\oy2w8tgb.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?gd=&ctid=CT3324760&octid=EB_ORIGINAL_CTID&ISID=MBB4E9A61-84DD-43E2-80D8-E247D3964CCB&SearchSource=55&CUI=&UM=2&UP=SPD1042488-760D-4E2D-B11D-E199CFFD7782&SSPV=");), ,[b9174bbe5526b28450d1e750c3416d93]
Physical Sectors: 0
(No malicious items detected)
(end) |