Also Schritt2 überspringen wenn ich alle programme gefunden habe?
Malwarebytes: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 15.06.2014
Suchlauf-Zeit: 20:30:41
Logdatei:
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.15.05
Rootkit Datenbank: v2014.06.02.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Moritz
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 318872
Verstrichene Zeit: 10 Min, 13 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1788, Löschen bei Neustart, [cfe388eb98e39d99dac274e506fb7888]
Module: 1
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [c0f230430d6eb5818a120682fd0444bc],
Registrierungsschlüssel: 16
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [cfe388eb98e39d99dac274e506fb7888],
PUP.Optional.WpManager, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Wpm, In Quarantäne, [149e6013ccafdb5be02b1f451ee33fc1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [60526d06d7a48fa76bcef05106fc2fd1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [60526d06d7a48fa76bcef05106fc2fd1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [60526d06d7a48fa76bcef05106fc2fd1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{917CAAE9-DD47-4025-936E-1414F07DF5B8}, In Quarantäne, [60526d06d7a48fa76bcef05106fc2fd1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}, In Quarantäne, [60526d06d7a48fa76bcef05106fc2fd1],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [60526d06d7a48fa76bcef05106fc2fd1],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2589869786-1695837759-112009712-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [60526d06d7a48fa76bcef05106fc2fd1],
PUP.Optional.SupTab.A, HKU\S-1-5-21-2589869786-1695837759-112009712-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [60526d06d7a48fa76bcef05106fc2fd1],
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [b7fb82f1760512240f3bc320c3400cf4],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [466c75fe0576092d65dbe903df24837d],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [6250d59e403b76c02822a142a55ecc34],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2589869786-1695837759-112009712-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [6052591afb809d99bec2754cdc266b95],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2589869786-1695837759-112009712-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [a2101f54304be94d8506ad2a19eaf907],
PUP.Optional.Qone8, HKU\S-1-5-21-2589869786-1695837759-112009712-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [387adf946b1049edca7f499a3ec5c63a],
Registrierungswerte: 3
PUP.Optional.QuickStart.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|quick_start@gmail.com, C:\Users\Moritz\AppData\Roaming\Mozilla\Firefox\Profiles\2gb7rgg1.default\extensions\quick_start@gmail.com, In Quarantäne, [70425a19accf92a4f2a12c89a55d1ce4]
PUP.Optional.WpManager.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WPM|ImagePath, C:\ProgramData\WPM\wprotectmanager.exe -service, In Quarantäne, [6e447af99edd0f2777af00e87f84bc44]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2589869786-1695837759-112009712-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, In Quarantäne, [a2101f54304be94d8506ad2a19eaf907]
Registrierungsdaten: 7
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711&q={searchTerms}),Ersetzt,[4969611207745ed8e46eafc9db29ff01]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711),Ersetzt,[f3bfb4bfa2d9d75ff55ceb8d32d2e818]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[b200cfa4c2b92610d0140077cd37cf31]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711&q={searchTerms}),Ersetzt,[82309bd8cbb079bdd67c730532d213ed]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711),Ersetzt,[cce66e0585f6c274a2af50282dd79769]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[ac06cda64b30df576a7aa1d6e81c3dc3]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-2589869786-1695837759-112009712-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.sweet-page.com/?type=hp&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=hp&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711),Ersetzt,[ac067af9cead181e9bb22d4b35cf01ff]
Ordner: 6
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab, Löschen bei Neustart, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [fbb7e88b6615d363aa7f1b84f012bf41],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [fbb7e88b6615d363aa7f1b84f012bf41],
Dateien: 25
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [cfe388eb98e39d99dac274e506fb7888],
PUP.Optional.Skytech.A, C:\Program Files (x86)\SupTab\DpInterface32.dll, Löschen bei Neustart, [c0f230430d6eb5818a120682fd0444bc],
PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, In Quarantäne, [149e6013ccafdb5be02b1f451ee33fc1],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SupTab.dll, In Quarantäne, [60526d06d7a48fa76bcef05106fc2fd1],
PUP.Optional.Skytech.A, C:\$RECYCLE.BIN\S-1-5-21-2589869786-1695837759-112009712-1002\$RS2M38L\UninstallManager.exe, In Quarantäne, [1c9600738bf035019408f3952fd27e82],
PUP.Optional.Superfish.A, C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, Löschen bei Neustart, [6a48d59e4338bd79a40f6d3b768ca759],
PUP.Optional.Superfish.A, C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, In Quarantäne, [f3bfbeb57b00e254a60d7434a45ebd43],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\install.data, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterface64.dll, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\DpInterfacef32.dll, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\RSHP.exe, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv32.dll, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\SpAPPSv64.dll, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\uninstall.exe, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\img\logo32.ico, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\common.js, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ga.js, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\ie8.js, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery-1.11.0.min.js, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\jquery.autocomplete.js, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\js.js, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\library.js, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.SupTab.A, C:\Program Files (x86)\SupTab\web\js\xagainit.js, In Quarantäne, [6b476f043546bf77de664b730bf74bb5],
PUP.Optional.Babylon.A, C:\Users\Moritz Karls\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={97E8337D-318A-11E2-99C1-685D43F81BF9}", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=48&cc=", "hxxp://search.iminent.com/?appId=8C23518F-7CF9-4B86-8615-966552B59FA0", "hxxp://search.babylon.com/?affID=115038&tt=201112_1849_4712_1&babsrc=HP_ss_cr&mntrId=141c7b8f000000000000685d43f81bf6", "hxxp://www.searchnu.com/406", "hxxp://search.nation.com/?orig=HP&affid=801&cztbid=233971303", "hxxp://search.conduit.com/?CUI=UN33859423212177427&ctid=CT3241949&SearchSource=48", "hxxp://isearch.babylon.com/?affID=115038&tt=201112_1849_4712_1&babsrc=HP_ss_gr2&mntrId=141c7b8f000000000000685d43f81bf6", "hxxp://search.fbdownloader.com/?channel=sfde203fbdgy21", "hxxp://www.sweet-page.com/?type=hp&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711", "hxxp://www.sweet-page.com/?type=hppp&ts=1401036674&from=cor&uid=XXXXXX_", "hxxp://www.sweet-page.com/?type=hppp&ts=1401036776&from=cor&uid=XXXXXX_", "hxxp://www.sweet-page.com/?type=hppp&ts=1401121830&from=cor&uid=XXXXXX_" ],), Ersetzt,[9a184b28156641f5819bbbeb64a0e21e]
PUP.Optional.Babylon.A, C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://home.sweetim.com/?crg=3.1010006.10031&barid={97E8337D-318A-11E2-99C1-685D43F81BF9}", "hxxp://search.softonic.com/MON00016/tb_v1?SearchSource=48&cc=", "hxxp://search.iminent.com/?appId=8C23518F-7CF9-4B86-8615-966552B59FA0", "hxxp://search.babylon.com/?affID=115038&tt=201112_1849_4712_1&babsrc=HP_ss_cr&mntrId=141c7b8f000000000000685d43f81bf6", "hxxp://www.searchnu.com/406", "hxxp://search.nation.com/?orig=HP&affid=801&cztbid=233971303", "hxxp://search.conduit.com/?CUI=UN33859423212177427&ctid=CT3241949&SearchSource=48", "hxxp://isearch.babylon.com/?affID=115038&tt=201112_1849_4712_1&babsrc=HP_ss_gr2&mntrId=141c7b8f000000000000685d43f81bf6", "hxxp://search.fbdownloader.com/?channel=sfde203fbdgy21", "hxxp://www.sweet-page.com/?type=hp&ts=1401036589&from=cor&uid=0XmSATAX32GBXXXXXXXXXXXXXXX_2711", "hxxp://www.sweet-page.com/?type=hppp&ts=1401036674&from=cor&uid=XXXXXX_", "hxxp://www.sweet-page.com/?type=hppp&ts=1401036776&from=cor&uid=XXXXXX_", "hxxp://www.sweet-page.com/?type=hppp&ts=1401121830&from=cor&uid=XXXXXX_" ],), Ersetzt,[7b37b2c1b6c5c96d5ebe8620ad57fa06]
Physische Sektoren: 0
(No malicious items detected)
(end) Der rest kommt gleich |