AnneSommer | 06.04.2014 00:49 | Play Now Radio / Pup.Optional.Conduit eingefangen , AntiVirus Programm nicht mehr aktivierbar Hallo
Ich habe auf den Rechner meiner Eltern am Dienstag versehentlich Play now Radio installiert und unter anderen den Plagegeist Pup.Optional.Conduit
Malbytewire hat bei ersten Suchlauf folgendes gefunden Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 02.04.2014
Scan Time: 17:23:15
Logfile: antiMalware020414.txt
Administrator: Yes
Version: 2.00.0.1000
Malware Database: v2014.04.02.05
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: User
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 297728
Time Elapsed: 6 min, 8 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 3
PUP.Optional.Conduit.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, , [602d94910f6c42f40a502cea0bf69a66],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURREN TVERSION\UNINSTALL\SearchProtect, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.1ClickDownload.A, HKU\S-1-5-21-22194152-1285576544-1255116705-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\1ClickDownload, , [4746d35236452016d8cb2161cd36bf41],
Registry Values: 0
(No malicious items detected)
Registry Data: 3
PUP.Optional.Conduit.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64 Loader.dll, Good: (), Bad: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC6 4Loader.dll),,[fa931e07f289bb7b8dcd080e07fa57a9]
PUP.Optional.Conduit.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|AppInit_DLLs, C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32 Loader.dll, Good: (), Bad: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC3 2Loader.dll),,[8a035dc84a312c0a5a0050c6e31e5aa6]
PUP.Optional.Conduit.A, HKU\S-1-5-21-22194152-1285576544-1255116705-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?gd=&ctid=...F2B36864&SSPV=, Good: (hxxp://www.google.com), Bad: (hxxp://search.conduit.com/?gd=&ctid=...F2B36864&SSPV=),,[4e3f57ce225910261a6e7097af55b14f]
Folders: 18
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, , [038a03220f6c48ee265abad17a892fd1],
Files: 85
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, , [602d94910f6c42f40a502cea0bf69a66],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe, , [9cf1cd58e794be786feb3ed805fcb24e],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe, , [deafa5802952d165ea707b9b8f72857b],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader .dll, , [fa931e07f289bb7b8dcd080e07fa57a9],
PUP.Optional.Conduit.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader .dll, , [8a035dc84a312c0a5a0050c6e31e5aa6],
PUP.Optional.OneClickDownloader.A, C:\$Recycle.Bin\S-1-5-21-22194152-1285576544-1255116705-1001\$R1WPMFW.exe, , [e3aa7aab0774aa8cd44e67cde12032ce],
PUP.Optional.SearchProtect.A, C:\Users\User\AppData\Local\Temp\nsy1643.exe, , [800d79aca5d63ff7f377d15060a1b44c],
PUP.Optional.SearchProtect.A, C:\Users\User\AppData\Local\Temp\nsi1374.exe, , [5a3369bc2c4fa19528428f924fb258a8],
PUP.Optional.SearchProtect.A, C:\Users\User\AppData\Local\Temp\nsn43BB.exe, , [f7969590f18a102662087ca5bd441ae6],
PUP.Optional.SearchProtect.A, C:\Users\User\AppData\Local\Temp\nst469A.exe, , [84091d081566db5bc9a1869be81903fd],
PUP.Optional.Conduit.A, C:\Users\User\AppData\Local\Temp\uttE4A7.tmp.exe, , [632ab07574074aec63333ada936e43bd],
PUP.Optional.Conduit.A, C:\Users\User\AppData\Local\Temp\nsc3E9\SpSetup.ex e, , [e5a825005b20c2740b4f0f0710f13ac6],
PUP.Optional.Conduit.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Prof iles\fy1p8mph.default\searchplugins\conduit-search.xml, , [157836ef4932b77fb11eca958b776799],
PUP.Optional.GoPhoto.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Prof iles\fy1p8mph.default\searchplugins\gophotoit.xml, , [2d60f2330774092d4ab3243bba484bb5],
PUP.Optional.Montiera, C:\Users\User\Desktop\Play Now Radio.lnk, , [bdd0b66f9ae1270f74bd441f9c66827e],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe , , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.css, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.html, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\bubble.js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\bubble\defaults.js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png , , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.p ng, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS .png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall. png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.pn g, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png , , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_che cked.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def .png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js , , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.m in.js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\SPDialogAPI.js , , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults .js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protecti on.css, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protecti on.html, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protecti on.js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaul ts.js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protec tionDS.css, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protec tionDS.html, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protec tionDS.js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.j s, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.c ss, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.h tml, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.j s, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults. js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall .css, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall .html, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall .js, , [038a03220f6c48ee265abad17a892fd1],
PUP.Optional.Conduit.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Prof iles\fy1p8mph.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=MD 67C4DD1-896D-483A-98A2-B7CB0E1E04CD&SearchSource=55&CUI=&UM=5&UP=SP7A83F2 4B-214A-4F43-96CE-DDFCF2B36864&SSPV="), ,[d2bb061fe299fe386ce2ae8deb19db25]
PUP.Optional.Conduit.A, C:\Users\User\AppData\Roaming\Mozilla\Firefox\Prof iles\fy1p8mph.default\prefs.js, Good: (), Bad: (user_pref("browser.newtab.url", "hxxp://search.conduit.com/?gd=&ctid=CT3314958&octid=EB_ORIGINAL_CTID&ISID=MD 67C4DD1-896D-483A-98A2-B7CB0E1E04CD&SearchSource=69&CUI=&SSPV=&Lay=1&UM=5 &UP=SP7A83F24B-214A-4F43-96CE-DDFCF2B36864"), ,[ade0d5501368d1657315fd3e33d11be5]
Physical Sectors: 0
(No malicious items detected)
(end) Seit dem lässt ssich bei meine Eltern AVG Antivirus 2014 nicht mehr aktivieren.
ruft man das Programm auf steht dort die Fehlermeldung "Keine aktive Komponente vorhanden"
Zudem hängen glaube Ich auch die Probleme beim Anspeicher mit Libri Office zusammen. Genauer Wortlaut kann ich erst nachher posten.
Ich poste dann auch einen neueren Malbyteware Bericht.
Anne |