Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=8d506792c2ffd947b92a83799e2ec84c
# engine=21722
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-12-27 05:46:54
# local_time=2014-12-27 06:46:54 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1='Avira Desktop'
# compatibility_mode=1810 16777213 100 99 75233 2885014 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 3471010 33610708 0 0
# scanned=270257
# found=58
# cleaned=0
# scan_time=7832
sh=DAE2639AAAA26430AC99886FF89C6C77FE2A24B0 ft=1 fh=d992cfe235e31eef vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\1c397cd3-39c3-46f8-81e1-9b182093dd7c-2.exe.vir"
sh=29183325739E1DB0140DC15C6F9ECCEA3F22E5EB ft=1 fh=5454e758d8d8a577 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\1c397cd3-39c3-46f8-81e1-9b182093dd7c-3.exe.vir"
sh=6F0F33779DC770B73F88114AA4330D51F8417037 ft=1 fh=d6bf14c7656c38d1 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\1c397cd3-39c3-46f8-81e1-9b182093dd7c-4.exe.vir"
sh=3F69A226D576942C40C54AB976F4E39476FFEB48 ft=1 fh=0f103f96d18a1205 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\1c397cd3-39c3-46f8-81e1-9b182093dd7c-5.exe.vir"
sh=36FE849CCCD7A5133705B8BEACD0C59F02F2F8F0 ft=1 fh=fe052409539a1397 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\1c397cd3-39c3-46f8-81e1-9b182093dd7c-6.exe.vir"
sh=650E4A348FD166708271B5886A4410B96801A822 ft=1 fh=659667b74c1969c0 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\1c397cd3-39c3-46f8-81e1-9b182093dd7c-64.exe.vir"
sh=769B8166D1AD2C5C36412A65110ED162F2720BA9 ft=1 fh=73bbd85f34170665 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\1c397cd3-39c3-46f8-81e1-9b182093dd7c-7.exe.vir"
sh=A98BA0A97044B22A00A92EF440EC13E89E30B1DE ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\1c397cd3-39c3-46f8-81e1-9b182093dd7c.xpi.vir"
sh=3BCA3EE0A106D6273C98F03A5A996DA142248A5D ft=1 fh=ce549066543feeb9 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\5f96a2ea-0f12-4d00-97db-f5176d671f01.dll.vir"
sh=9F5F0E59C4F9098725373FC2581AEC87C6203A4F ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\6fcfdeda-b174-49d3-81bd-714121e015be.crx.vir"
sh=5838229347285DED8B1F1081121973EFA9100095 ft=1 fh=8004da7cf9de57c4 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\6fcfdeda-b174-49d3-81bd-714121e015be.dll.vir"
sh=A9B99465C2AE2246E369DF171DFA0B6A11B043EE ft=1 fh=0be759b2d8c73138 vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\CinemaP-1.4cV24.12-bg.exe.vir"
sh=2BB3F59E57426FBB48A92FB8F571B4B8459961F3 ft=1 fh=c188e6a7a59e1ee9 vn="Variante von Win32/Toolbar.CrossRider.BA evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\CinemaP-1.4cV24.12-bho.dll.vir"
sh=F13D58040AD6BDD1B0761D865C91D724CB3AA8A8 ft=1 fh=a92b023455c92247 vn="Variante von Win64/Toolbar.Crossrider.J evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\CinemaP-1.4cV24.12-bho64.dll.vir"
sh=769B8166D1AD2C5C36412A65110ED162F2720BA9 ft=1 fh=73bbd85f34170665 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\CinemaP-1.4cV24.12-codedownloader.exe.vir"
sh=657BCA12C140B9561138EDE6A3CAA551A00B2A85 ft=1 fh=42b6d95cbbbdb4d4 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\Uninstall.exe.vir"
sh=68893336B278838B0F4A494CED2A89E7884807AD ft=1 fh=6e99032a58561308 vn="Win32/Packed.VMDetector.I evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\CinemaP-1.4cV24.12\utils.exe.vir"
sh=4681113E2FCA874DDB2F3FA52A04753A8789FA91 ft=1 fh=c71c00113a97adaf vn="Variante von Win32/Adware.MultiPlug.DX Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\DeltaFix\DeltaFix.dll.vir"
sh=4DA86CA42305C59333E4C0AC43D54D54D2588F19 ft=1 fh=fbb7033199a19f35 vn="Variante von Win32/AdWare.EoRezo.AU Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\mbot_de_372\mybestofferstoday_widget.exe.vir"
sh=AAA623029121715DD514658EB72C344C182CE5D4 ft=1 fh=2063f527e15bc225 vn="Variante von MSIL/MyPCBackup.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\BackupStackUI.dll.vir"
sh=BAFC87AA0D99C347EA00A77BB09CE78915DF75E5 ft=1 fh=edcb43f436e617cd vn="MSIL/MyPCBackup.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\MyPC Backup\MyPC Backup.exe.vir"
sh=31D0B125962639ACC9DF9F39782A3207099DD924 ft=1 fh=ca95fc211bc2fbc3 vn="Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialApp.dll.vir"
sh=6857BD88EA938B705EFC3FD46D5C91D2C1B3EDE9 ft=1 fh=a2f65d85debd6839 vn="Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialEng.dll.vir"
sh=7ABB587B2A0D80E1EC4B2F1E8BB0E2C194FBB4A0 ft=1 fh=9074270edfd38722 vn="Variante von Win32/Toolbar.Montiera.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialsrv.exe.vir"
sh=3407FB00757C71D9CB28AEC2EC7855FF5D3A6609 ft=1 fh=67364266c19decdd vn="Variante von Win32/Toolbar.Montiera.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\mysearchdialTlbr.dll.vir"
sh=89DC63472DE94DF3F12DBAE15B7EBE6C04263369 ft=1 fh=7fb9e45e0079471d vn="Variante von Win32/Toolbar.Escort.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Mysearchdial\1.8.29.0\bh\mysearchdial.dll.vir"
sh=F3E870FD4836424683C4F476C03AC08964CC5EF7 ft=1 fh=a0c6b0b29c310285 vn="Variante von Win32/Speedchecker.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\pc speed up\PCSUSD.exe.vir"
sh=53F226B3D1D3828304E40C6C7A50667ADF23B42A ft=1 fh=e1ea10a5e9416a5c vn="Win32/Thinknice.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface32.dll.vir"
sh=0CB68F399D491465198E3E86F1D2923A211614E7 ft=1 fh=021f675753f993f2 vn="Win64/Thinknice.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\DpInterface64.dll.vir"
sh=86EA851108D635D9ED47C01E86899845DFDA3EC7 ft=1 fh=90733a3b10b3e858 vn="Variante von Win32/Thinknice.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\HpUI.exe.vir"
sh=12EBF6FC8AD543662053CA101C2D5DA175137EB2 ft=1 fh=c71c00119e5c1a87 vn="Win32/Thinknice.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader32.exe.vir"
sh=8F0ABE23DDA3F9DC04497B1A4F455AF8CE9D45B8 ft=1 fh=787e176d56997de7 vn="Win64/Thinknice.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\Loader64.exe.vir"
sh=A8E3A9E6972C6F8B253EA0E1837AEEBF0A07B187 ft=1 fh=e2a5b168a3934371 vn="Variante von Win32/Thinknice.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\RSHP.exe.vir"
sh=30E2FB1C671B2808D2E80518D793575965AF2416 ft=1 fh=d06e6f3f3f60e357 vn="Variante von Win32/Thinknice.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect32.dll.vir"
sh=AC11914CC02E023E2EF06A80DEE1701419A5473A ft=1 fh=4cb2d0bd10147652 vn="Win64/Thinknice.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SearchProtect64.dll.vir"
sh=36F969E522FD53A189312D946C430EFD02D5A982 ft=1 fh=5d022c015afe1524 vn="Variante von Win32/ELEX.AV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupIePluginServiceUpdate.exe.vir"
sh=D037F58CF4B36F3B437FAA0D9500720445B27D65 ft=1 fh=b07c7921935b766c vn="Win32/Thinknice.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\SupTab.dll.vir"
sh=4139F95644E13A650D4827C943BCC9F2F0F6AA93 ft=1 fh=3b96e1736604b8bc vn="Win32/Thinknice.E evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\uninstall.exe.vir"
sh=79C9BD304C93AB8FD0544108656A899993DB14EF ft=1 fh=e6f80544d6e8089f vn="Variante von Win32/Thinknice.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\WindowsSupportDll32.dll.vir"
sh=96B85214CD9E4FF85AC6144E7EF3DDF9E0F215E6 ft=1 fh=098a6735f96a550a vn="Variante von Win32/Thinknice.F evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SupTab\WindowsSupportDll64.dll.vir"
sh=36F969E522FD53A189312D946C430EFD02D5A982 ft=1 fh=5d022c015afe1524 vn="Variante von Win32/ELEX.AV evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\IePluginServices\PluginService.exe.vir"
sh=F0DB92E27FF763CDC3002BB2B7320F9F3478224F ft=1 fh=c71c0011edb12146 vn="Variante von Win32/ELEX.BC evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe.vir"
sh=5C4097D02CDC6FD6DFD7B8BA77ACC3C234C09A8D ft=1 fh=399e1cf445ad15d2 vn="Variante von Win32/Adware.EoRezo.AJ Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Ich\AppData\Local\mbot_de_372\upmbot_de_372.exe.vir"
sh=1C615B43E780FB434AA3F923C6195A1BBBF34C9C ft=0 fh=0000000000000000 vn="Variante von Win32/Speedchecker.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Ich\AppData\Local\Microsoft\Silverlight\OutOfBrowser\Speedchecker.PCSpeedUp\application.xap.vir"
sh=9DF082563DF6D7EA7B9F176C3A4AE1F35F1DA289 ft=0 fh=0000000000000000 vn="JS/Toolbar.Crossrider.B evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\s9d7ok7u.default\Extensions\23fb8bb3-ac21-4230-bbfa-49b94968bc63@gmail.com\extensionData\plugins\91.js.vir"
sh=BF7D98300AB8713C5549F587B74DED8CFB641671 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\s9d7ok7u.default\Extensions\R@LPeyY.net\content\bg.js.vir"
sh=CCC8E06C61B3FE3DA721783C3AE7908A91C29F08 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\s9d7ok7u.default\Extensions\YS8G7x70@g.edu\content\bg.js.vir"
sh=1305DE2BFA54D0A13AFA7E1DC139B3B9AE262A56 ft=1 fh=87358e7751ff4371 vn="Variante von Win32/DealPly.S evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Ich\AppData\Roaming\Mysearchdial\UpdateProc\UpdateTask.exe.vir"
sh=BF1BB92E7F48C564B774815B9390DFA478AD483C ft=1 fh=0c47f480955462d2 vn="Variante von Win32/Agent.WGA Trojaner" ac=I fn="C:\AdwCleaner\Quarantine\C\Windows\rcore.exe.vir"
sh=3BCA3EE0A106D6273C98F03A5A996DA142248A5D ft=1 fh=ce549066543feeb9 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\AGEIA Technologies\db698c94-f0f9-4cbe-95bb-3e7396d3dbb7.dll"
sh=3BCA3EE0A106D6273C98F03A5A996DA142248A5D ft=1 fh=ce549066543feeb9 vn="Variante von Win32/Toolbar.CrossRider.BM evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\db698c94-f0f9-4cbe-95bb-3e7396d3dbb7\1d9f3a80-cfda-47cf-8df3-4585f92c1445.dll"
sh=E5A3C100D2D0FD94482783AF2B2FF94CDFC9923F ft=1 fh=a0ddd0619a504a2e vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Program Files (x86)\FreeTime\FormatFactory\FFModules\Package\BaiDu\hao123inst.exe"
sh=8298F0AC7ADC718113BA8B16ECC59FF875257AF9 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\ProgramData\fcfkciaojmeemnpdfhehfchkaaicjecd\u4S.js"
sh=8298F0AC7ADC718113BA8B16ECC59FF875257AF9 ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Users\All Users\fcfkciaojmeemnpdfhehfchkaaicjecd\u4S.js"
sh=269804CDDCA51C686928A382B2BB862F33F3306D ft=0 fh=0000000000000000 vn="JS/Kryptik.ATB Trojaner" ac=I fn="C:\Users\Ich\AppData\Local\Comodo\Dragon\User Data\Default\Extensions\ojkcdipcgfaekbeaelaapakgnjflfglf\203\S3wZ.js"
sh=E3C3C648F3783E1918A71EE73561B6DFD9E0C6FF ft=1 fh=031add60de2b5a8f vn="Variante von Win32/Hao123.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Ich\Downloads\FFSetup3.5.0.0.exe"
sh=E49E7983A54BCE4742A4E8EEC476721EB2B1AB8B ft=1 fh=e30d9656bea1fae6 vn="Variante von Win32/Amonetize.CK evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Ich\Downloads\Menu__6629_i1430423469_il467025.exe"
sh=E49E7983A54BCE4742A4E8EEC476721EB2B1AB8B ft=1 fh=e30d9656bea1fae6 vn="Variante von Win32/Amonetize.CK evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Ich\Downloads\Menu__6629_i1430428382_il467025.exe" Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 27.12.2014 16:09:53, SYSTEM, KRISTIAN, Protection, Malware Protection, Starting,
Protection, 27.12.2014 16:09:53, SYSTEM, KRISTIAN, Protection, Malware Protection, Started,
Protection, 27.12.2014 16:09:53, SYSTEM, KRISTIAN, Protection, Malicious Website Protection, Starting,
Protection, 27.12.2014 16:09:54, SYSTEM, KRISTIAN, Protection, Malicious Website Protection, Started,
Update, 27.12.2014 16:09:57, SYSTEM, KRISTIAN, Manual, Rootkit Database, 2014.11.18.1, 2014.12.23.2,
Update, 27.12.2014 16:09:57, SYSTEM, KRISTIAN, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 27.12.2014 16:10:17, SYSTEM, KRISTIAN, Manual, Malware Database, 2014.11.20.6, 2014.12.27.4,
Protection, 27.12.2014 16:10:17, SYSTEM, KRISTIAN, Protection, Refresh, Starting,
Protection, 27.12.2014 16:10:17, SYSTEM, KRISTIAN, Protection, Malicious Website Protection, Stopping,
Protection, 27.12.2014 16:10:17, SYSTEM, KRISTIAN, Protection, Malicious Website Protection, Stopped,
Protection, 27.12.2014 16:10:20, SYSTEM, KRISTIAN, Protection, Refresh, Success,
Protection, 27.12.2014 16:10:20, SYSTEM, KRISTIAN, Protection, Malicious Website Protection, Starting,
Protection, 27.12.2014 16:10:21, SYSTEM, KRISTIAN, Protection, Malicious Website Protection, Started,
Protection, 27.12.2014 16:25:10, SYSTEM, KRISTIAN, Protection, Malware Protection, Starting,
Protection, 27.12.2014 16:25:11, SYSTEM, KRISTIAN, Protection, Malware Protection, Started,
Protection, 27.12.2014 16:25:11, SYSTEM, KRISTIAN, Protection, Malicious Website Protection, Starting,
Protection, 27.12.2014 16:26:14, SYSTEM, KRISTIAN, Protection, Malicious Website Protection, Started,
(end) Da |