Hier die 3 Logs Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 30.01.2015
Suchlauf-Zeit: 17:48:49
Logdatei: mwam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.30.06
Rootkit Datenbank: v2015.01.14.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Marian Curdt
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 415786
Verstrichene Zeit: 21 Min, 15 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.ZombieNews.A, C:\ProgramData\NtiAgOWstf\dhtDXma.exe, 3096, Löschen bei Neustart, [292831c6bdcc2c0a241e734bda27ae52]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 14
PUP.Optional.ZombieNews.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\dhtDXma, In Quarantäne, [292831c6bdcc2c0a241e734bda27ae52],
PUP.Optional.Vosteran, HKLM\SOFTWARE\CLASSES\APPID\{4CB3598A-82E8-4D1F-983F-061238AE696E}, In Quarantäne, [054cde198504f541e85f658f35cdc040],
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{4CB3598A-82E8-4D1F-983F-061238AE696E}, In Quarantäne, [054cde198504f541e85f658f35cdc040],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1656074084-342888944-3947257893-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [91c0d12628610f271e9e9b5d6e94ad53],
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\Vosteran.TSE6THRBYUUAQKXMEX4ZZYPZH4, In Quarantäne, [d37e3eb94f3a1e18a118cdb2d330ee12],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, In Quarantäne, [59f8b7403653c175249de31de322a35d],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [56fb51a6692094a24f71c13fc243b54b],
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\vosteran.exe, In Quarantäne, [ca87ba3d8aff04325c1212716c97867a],
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\Vosteran.TSE6THRBYUUAQKXMEX4ZZYPZH4, In Quarantäne, [5bf672854f3a34029524245bf90aaf51],
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\vosteran.exe, In Quarantäne, [d77afbfc6b1e989e6608493a5fa401ff],
PUP.Optional.Booster.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{1146AC44-2F03-4431-B4FD-889BC837521F}{cae99edb}, In Quarantäne, [54fdaf4824654ceaca1771315fa4748c],
PUP.Optional.PlumoWeb.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update PlumoWeb, In Quarantäne, [1c356b8c474272c4aebf92038c772fd1],
PUP.Optional.StormWatchApp.A, HKU\S-1-5-21-1656074084-342888944-3947257893-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\StormWatchApp, In Quarantäne, [d180a55294f56bcbb15c5a34dc279070],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-1656074084-342888944-3947257893-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\30935, In Quarantäne, [b79ae611aedbcb6b8e25068d887b659b],
Registrierungswerte: 3
PUP.Optional.Vosteran, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\WSE_Vosteran\\, In Quarantäne, [9ab72fc8fc8dbd79ca77e62184819967]
PUP.Optional.FFToolbar.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|fftoolbar2014@etech.com, C:\Users\Marian Curdt\AppData\Roaming\Mozilla\Firefox\Profiles\mezahl5h.default-1422375678338\extensions\fftoolbar2014@etech.com, In Quarantäne, [133e6f885d2cd85ebf96493814ef18e8]
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1656074084-342888944-3947257893-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, Mysearchdial, In Quarantäne, [470a6b8c5237c67045c3861d8c77a759]
Registrierungsdaten: 3
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422550344&from=obw&uid=ST500DM002-1BD142_Z3T99M3NXXXXZ3T99M3N&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422550344&from=obw&uid=ST500DM002-1BD142_Z3T99M3NXXXXZ3T99M3N&q={searchTerms}),Ersetzt,[1e330ceb1a6fba7ca0fedecfed18ca36]
PUP.Optional.OmigaPlus.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422550344&from=obw&uid=ST500DM002-1BD142_Z3T99M3NXXXXZ3T99M3N&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422550344&from=obw&uid=ST500DM002-1BD142_Z3T99M3NXXXXZ3T99M3N&q={searchTerms}),Ersetzt,[6fe254a3484191a535653578a36258a8]
PUP.Optional.OmigaPlus.A, HKU\S-1-5-21-1656074084-342888944-3947257893-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422550344&from=obw&uid=ST500DM002-1BD142_Z3T99M3NXXXXZ3T99M3N&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://isearch.omiga-plus.com/web/?type=ds&ts=1422550344&from=obw&uid=ST500DM002-1BD142_Z3T99M3NXXXXZ3T99M3N&q={searchTerms}),Ersetzt,[e869896e7316ea4c7736eab528dd13ed]
Ordner: 2
PUP.Optional.ZombieNews.A, C:\Users\Marian Curdt\AppData\Local\ZombieNews, In Quarantäne, [cd843fb8d3b68aac3f3161033ec502fe],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro, In Quarantäne, [4b0650a78ffa2115b402a3c526dd19e7],
Dateien: 16
PUP.Optional.ZombieNews.A, C:\ProgramData\NtiAgOWstf\dhtDXma.exe, Löschen bei Neustart, [292831c6bdcc2c0a241e734bda27ae52],
PUP.Optional.ZombieNews.A, C:\ProgramData\NtiAgOWstf\dat\jLSuBq.exe, Löschen bei Neustart, [272a9661a0e9f93d4af8aa1403fecb35],
PUP.Optional.ZombieNews.A, C:\ProgramData\NtiAgOWstf\dat\oHjStI.exe, Löschen bei Neustart, [480963943257e05687bb26980ff226da],
PUP.Optional.ObjectBrowser.A, C:\Users\Marian Curdt\AppData\Roaming\TXFAZSA.exe, In Quarantäne, [e46dbc3b810803337da19d74b250916f],
PUP.Optional.ObjectBrowser.A, C:\Users\Marian Curdt\AppData\Roaming\WJCWK.exe, In Quarantäne, [044d5e99c0c951e52bf3b65b8f73966a],
PUP.Optional.OutBrowse, C:\Users\Marian Curdt\Downloads\Installation.exe, In Quarantäne, [5af7e017523756e073ce722d43c2cc34],
PUP.Optional.Bundle, C:\Users\Marian Curdt\Downloads\5StarLoops Sound Library__5160_i1452283510_il18653.exe, In Quarantäne, [d87971863c4dd1652ab8df2e13efed13],
PUP.Optional.SmartInstaller, C:\Users\Marian Curdt\Downloads\reFX_Nexus_v2.3.2_Beta_Crack.exe, In Quarantäne, [58f92ccbe8a141f537b0bd2eeb16c33d],
PUP.Optional.Bundle, C:\Users\Marian Curdt\Downloads\5StarLoops Sound Library__5160_i1452296211_il18653.exe, In Quarantäne, [83ce61963c4def47ab374bc27e841ee2],
PUP.Optional.OpenCandy, C:\Users\Marian Curdt\Downloads\DTLite4491-0356.exe, In Quarantäne, [88c91cdbcdbcbd7948d06b67887d32ce],
PUP.Optional.Eguide, C:\Users\Marian Curdt\Downloads\word.exe, In Quarantäne, [0849cb2c5930dd59c65c7ce2d42c7987],
PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\AppPatch64\VCLdr64.dll, In Quarantäne, [3c15886f583174c29f47a60ba55cd927],
PUP.Optional.SearchProtect.A, C:\Windows\AppPatch\nbin\VC32Loader.dll, In Quarantäne, [56fb6493d4b51b1be402fbb66d94f10f],
PUP.Optional.SearchProtect, C:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [bc951add7b0e4aec24a0718f778e01ff],
PUP.Optional.ZombieNews.A, C:\Users\Marian Curdt\AppData\Local\ZombieNews\data2.dat, In Quarantäne, [cd843fb8d3b68aac3f3161033ec502fe],
PUP.Optional.ShopperPro, C:\Program Files\Common Files\ShopperPro\spbici64.dll, In Quarantäne, [4b0650a78ffa2115b402a3c526dd19e7],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
# AdwCleaner v4.109 - Bericht erstellt am 03/02/2015 um 18:09:37
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-02-02.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Marian Curdt - MARIANCURDTPC
# Gestartet von : C:\Users\Marian Curdt\Desktop\AdwCleaner_4.109.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : iSafeKrnlMon
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Windows\System32\log\iSafeKrnlCall.log
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Boost
Schlüssel Gelöscht : HKLM\SOFTWARE\Boost
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v35.0.1 (x86 de)
*************************
AdwCleaner[R0].txt - [5594 octets] - [14/04/2014 18:26:07]
AdwCleaner[R1].txt - [10178 octets] - [14/11/2014 15:34:41]
AdwCleaner[R2].txt - [3683 octets] - [14/11/2014 16:58:18]
AdwCleaner[R3].txt - [25565 octets] - [27/01/2015 13:40:38]
AdwCleaner[R4].txt - [1346 octets] - [29/01/2015 16:57:37]
AdwCleaner[R5].txt - [1627 octets] - [03/02/2015 18:08:27]
AdwCleaner[S0].txt - [5231 octets] - [14/04/2014 18:26:35]
AdwCleaner[S1].txt - [8466 octets] - [14/11/2014 15:36:19]
AdwCleaner[S2].txt - [3311 octets] - [14/11/2014 16:59:33]
AdwCleaner[S3].txt - [22536 octets] - [27/01/2015 13:43:05]
AdwCleaner[S4].txt - [1408 octets] - [29/01/2015 17:00:34]
AdwCleaner[S5].txt - [1504 octets] - [03/02/2015 18:09:37]
########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [1564 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Marian Curdt on 03.02.2015 at 18:13:53,92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update browsesmart
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update wisen wizard
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util wisen wizard
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311281150}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"
~~~ FireFox
Emptied folder: C:\Users\Marian Curdt\AppData\Roaming\mozilla\firefox\profiles\q375034u.default-1422551480209\minidumps [2 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.02.2015 at 18:17:14,89
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |