doublepack | 30.04.2015 20:12 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 30.04.2015
Suchlauf-Zeit: 20:34:53
Logdatei: scan log.txt
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.04.30.05
Rootkit Datenbank: v2015.04.21.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Luke
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 386632
Verstrichene Zeit: 24 Min, 4 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 3
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430316511-E311-B039-F8A963069189\snsi9750.tmp, 2212, Löschen bei Neustart, [d5e829493b4ff73f942a83d929dc07f9]
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425005-E311-B039-F8A963069189\cnsm3B9A.tmp, 2184, Löschen bei Neustart, [dce150220e7c46f025998fcd0203619f]
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425019-E311-B039-F8A963069189\snsi72D4.tmp, 2904, Löschen bei Neustart, [615cbdb5f298340201bd520a09fcc43c]
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 15
PUP.Optional.MetalMaker.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{d1ed8ab0-4dff-42de-95da-49e0537b3612}, In Quarantäne, [c8f57ef4e4a606302eed99eef80bb14f],
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rurifuqe, In Quarantäne, [d5e829493b4ff73f942a83d929dc07f9],
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\poxuqire, In Quarantäne, [dce150220e7c46f025998fcd0203619f],
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\xikejyre, In Quarantäne, [615cbdb5f298340201bd520a09fcc43c],
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\ARENAHD, In Quarantäne, [8d304a28dcae102623e23d2365a031cf],
PUP.Optional.PCTuner.C, HKLM\SOFTWARE\HIGHDEFACTION, In Quarantäne, [f7c6a7cbbad00f270f021c4433d214ec],
PUP.Optional.Infonaut.A, HKLM\SOFTWARE\WOW6432NODE\Infonaut_1.10.0.14, In Quarantäne, [6b5220528802181e56da7753e221827e],
PUP.Optional.CrossRider.C, HKLM\SOFTWARE\WOW6432NODE\APPDATALOW\SOFTWARE\Crossrider, In Quarantäne, [6a530f63216942f4c95a4980d62d8080],
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\WOW6432NODE\ARENAHD, In Quarantäne, [8835f87af991bb7b0401c39d1de89967],
PUP.Optional.PCTuner.C, HKLM\SOFTWARE\WOW6432NODE\HIGHDEFACTION, In Quarantäne, [704d1959f7936ec80c05f07021e4d32d],
PUP.Optional.Infonaut.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\INSVC_1.10.0.14, In Quarantäne, [99240b67038785b1c26d6a602ad99d63],
PUP.Optional.Shopperz.A, HKU\S-1-5-19\SOFTWARE\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}, In Quarantäne, [ad107ef4b2d838fe85ce824d6a9948b8],
PUP.Optional.Shopperz.A, HKU\S-1-5-20\SOFTWARE\{4E7638A1-6962-4e44-A6B9-F40E84FD6D09}, In Quarantäne, [4d700b67b3d7231365ee5c7316ede719],
PUP.Optional.CinemaPlus.C, HKU\S-1-5-21-2833233637-2508301349-1291184669-1001\SOFTWARE\ARENAHD, In Quarantäne, [3b82beb48703f2449c6861ffde278e72],
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\oursurfing uninstall, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
Registrierungswerte: 29
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\ARENAHD|value, 1, In Quarantäne, [8d304a28dcae102623e23d2365a031cf]
PUP.Optional.PCTuner.C, HKLM\SOFTWARE\HIGHDEFACTION|value, 1, In Quarantäne, [f7c6a7cbbad00f270f021c4433d214ec]
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, oursurfing, In Quarantäne, [6657aac84545270fc872c0a0f60f6c94]
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.oursurfing.com/web/?type=ds&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&q={searchTerms}, In Quarantäne, [3588e9892c5e270f5bdf0e5240c5b24e]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|shopperz, C:\Program Files\shopperz\wrex.exe, In Quarantäne, [c0fdd2a06921b97d386f4298f90ab848]
PUP.Optional.Shopperz.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|shopperz64, C:\Program Files\shopperz\wrex64.exe, In Quarantäne, [0eaff0829bef8da91f898a50956e6a96]
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\REGISTEREDAPPLICATIONS|Crossbrowse, Software\Clients\StartMenuInternet\Crossbrowse\Capabilities, In Quarantäne, [d0ed11618efc7bbb0008afb11de81be5]
PUP.Optional.CinemaPlus.C, HKLM\SOFTWARE\WOW6432NODE\ARENAHD|value, 1, In Quarantäne, [8835f87af991bb7b0401c39d1de89967]
PUP.Optional.PCTuner.C, HKLM\SOFTWARE\WOW6432NODE\HIGHDEFACTION|value, 1, In Quarantäne, [704d1959f7936ec80c05f07021e4d32d]
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, oursurfing, In Quarantäne, [3b825220b2d882b452e8c0a0877eb749]
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.oursurfing.com/web/?type=ds&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&q={searchTerms}, In Quarantäne, [c6f71e545733340215256bf5b253a15f]
PUP.Optional.MBot.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|mbot_de_616, In Quarantäne, [6f4eef83d1b93ef82e9910de0ef58a76],
PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_de_466, In Quarantäne, [f0cd046e5e2c6dc9c7d2ebf29c67f60a],
PUP.Optional.GamesDesktop.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|gmsd_de_478, In Quarantäne, [6e4f234fe9a15dd91d7cf5e8788bf20e],
PUP.Optional.CrossBrowse.C, HKLM\SOFTWARE\WOW6432NODE\REGISTEREDAPPLICATIONS|Crossbrowse, Software\Clients\StartMenuInternet\Crossbrowse\Capabilities, In Quarantäne, [536a90e2206a989e51b77ae6d5309868]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\kygyhosy|ImagePath, C:\Users\Luke\AppData\Roaming\B835A680-1430417623-E311-B039-F8A963069189\jnsiB76B.tmp, In Quarantäne, [17a6e58d1a7057df53f493c8cc3925db]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\mewobidy|ImagePath, C:\Users\Luke\AppData\Roaming\B835A680-1430309082-E311-B039-F8A963069189\nsb6350.tmp, In Quarantäne, [932ad49ee4a62a0c88bedc7f4eb75da3]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\poxuqire|ImagePath, C:\Users\Luke\AppData\Local\B835A680-1430425005-E311-B039-F8A963069189\cnsm3B9A.tmp, In Quarantäne, [f5c878fa6723aa8c73d41b4032d3718f]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\rurifuqe|ImagePath, C:\Users\Luke\AppData\Local\B835A680-1430316511-E311-B039-F8A963069189\snsi9750.tmp, In Quarantäne, [8934046e2d5d310563e4cf8c030253ad]
PUP.Optional.MultiPlug.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\xikejyre|ImagePath, C:\Users\Luke\AppData\Local\B835A680-1430425019-E311-B039-F8A963069189\snsi72D4.tmp, In Quarantäne, [318c7af8593178be1730b0abe91c728e]
PUP.Optional.Infonaut.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\insvc_1.10.0.14|ImagePath, "C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe", In Quarantäne, [99240b67038785b1c26d6a602ad99d63]
PUP.Optional.CinemaPlus.C, HKU\S-1-5-21-2833233637-2508301349-1291184669-1001\SOFTWARE\ARENAHD|value, 1, In Quarantäne, [3b82beb48703f2449c6861ffde278e72]
PUP.Optional.PCTuner.C, HKU\S-1-5-21-2833233637-2508301349-1291184669-1001\SOFTWARE\HIGHDEFACTION|value, 1, In Quarantäne, [e9d42d454b3f62d447c8045cfd08c23e]
PUP.Optional.OurSurfing.A, HKU\S-1-5-21-2833233637-2508301349-1291184669-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, oursurfing, In Quarantäne, [e9d44e24098141f59f9a74ecf312dc24]
PUP.Optional.OurSurfing.A, HKU\S-1-5-21-2833233637-2508301349-1291184669-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=fsf&utm_campaign=install_ie&utm_content=ds&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&ts=1430308999&type=default&q={searchTerms}, In Quarantäne, [03ba51212d5dee4849f00858d23302fe]
PUP.Optional.OurSurfing.A, HKU\S-1-5-21-2833233637-2508301349-1291184669-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|TopResultURL, hxxp://www.oursurfing.com/web/?type=ds&ts=1430308755&z=ee6bff7719bca02b2914038gezac6eac5e4bcm1w0c&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&q={searchTerms}, In Quarantäne, [ead3d79b3f4be84e1425223ef31252ae]
PUP.Optional.OurSurfing.A, HKU\S-1-5-21-2833233637-2508301349-1291184669-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BB866FE7-57AF-456D-B09C-81C3118619DA}|URL, hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=fsf&utm_campaign=install_ie&utm_content=ds&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&ts=1430308999&type=default&q={searchTerms}, In Quarantäne, [843994decbbff046b386263af5109f61]
PUP.Optional.OurSurfing.A, HKU\S-1-5-21-2833233637-2508301349-1291184669-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}|URL, hxxp://www.oursurfing.com/web/?utm_source=b&utm_medium=fsf&utm_campaign=install_ie&utm_content=ds&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&ts=1430308999&type=default&q={searchTerms}, In Quarantäne, [5a63fd75c3c71f1745f485db927355ab]
PUM.LowRiskFileTypes, HKU\S-1-5-21-2833233637-2508301349-1291184669-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\ASSOCIATIONS|LowRiskFileTypes, .avi;.bat;.com;.cmd;.exe;.htm;.html;.lnk;.mpg;.mpeg;.mov;.mp3;.msi;.m3u;.rar;.reg;.txt;.vbs;.wav;.zip;, In Quarantäne, [47767df5018953e3ab7b925645beb44c]
Registrierungsdaten: 6
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.oursurfing.com/?type=sc&ts=1430308755&z=ee6bff7719bca02b2914038gezac6eac5e4bcm1w0c&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.oursurfing.com/?type=sc&ts=1430308755&z=ee6bff7719bca02b2914038gezac6eac5e4bcm1w0c&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81),Ersetzt,[fdc077fbeb9f89ad75e7a46c6a9ce41c]
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.oursurfing.com/web/?type=ds&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.oursurfing.com/web/?type=ds&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&q={searchTerms}),Ersetzt,[8b32c7abd8b249ed4816719fdc2ab54b]
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.oursurfing.com/?type=hp&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81, Gut: (www.google.com), Schlecht: (hxxp://www.oursurfing.com/?type=hp&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81),Ersetzt,[f6c7b4be1377ad89ec72cb459472bd43]
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.oursurfing.com/?type=hp&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81, Gut: (www.google.com), Schlecht: (hxxp://www.oursurfing.com/?type=hp&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81),Ersetzt,[7e3f31412c5eed494e10749c7f87e21e]
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.oursurfing.com/web/?type=ds&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.oursurfing.com/web/?type=ds&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81&q={searchTerms}),Ersetzt,[2895ee848bffe452bf9fbe5234d29b65]
PUP.Optional.OurSurfing.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.oursurfing.com/?type=sc&ts=1430308755&z=ee6bff7719bca02b2914038gezac6eac5e4bcm1w0c&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.oursurfing.com/?type=sc&ts=1430308755&z=ee6bff7719bca02b2914038gezac6eac5e4bcm1w0c&from=amt&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81),Ersetzt,[675694def49653e35a02c749fe08827e]
Ordner: 7
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430316511-E311-B039-F8A963069189, Löschen bei Neustart, [d5e829493b4ff73f942a83d929dc07f9],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425005-E311-B039-F8A963069189, Löschen bei Neustart, [dce150220e7c46f025998fcd0203619f],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425019-E311-B039-F8A963069189, Löschen bei Neustart, [615cbdb5f298340201bd520a09fcc43c],
PUP.Optional.ZombieNews.A, C:\Users\Luke\AppData\Local\ZombieNews, In Quarantäne, [338aa4ce2367de5897c4dad4e221ee12],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\code, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
Dateien: 52
PUP.Optional.WebTInst.A, C:\Windows\System32\drivers\Msft_Kernel_webTinstMKTN84_01009.Wdf, Löschen bei Neustart, ,
PUP.HackTool.Agent, C:\$Recycle.Bin\S-1-5-21-2833233637-2508301349-1291184669-1001\$RA7AY8B.exe, In Quarantäne, [b409c7abf991cd6954082ac043bdd12f],
PUP.HackTool.Agent, C:\$Recycle.Bin\S-1-5-21-2833233637-2508301349-1291184669-1001\$RAXXHDQ.exe, In Quarantäne, [5e5f126090fa60d618447179c937867a],
PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-2833233637-2508301349-1291184669-1001\$RTG8Y64.04\0cd19e6d-ad3d-4a4c-abe4-06731ad73841-5.exe, In Quarantäne, [00bd3b370288aa8c37974304ac5a37c9],
PUP.Optional.CrossRider.A, C:\$Recycle.Bin\S-1-5-21-2833233637-2508301349-1291184669-1001\$RTG8Y64.04\utils.exe, In Quarantäne, [0fae640ee6a4b284c8068dbada2ccd33],
Trojan.Downloader, C:\Users\Luke\AppData\Local\Temp\nsa80C6.tmp, In Quarantäne, [803df77b2e5c9a9c35f10e2e33d001ff],
PUP.Optional.Bundle, C:\Users\Luke\AppData\Local\Temp\nsa80C7.tmp, In Quarantäne, [f7c67002147601359db556a79b6a44bc],
Trojan.Downloader, C:\Users\Luke\AppData\Local\Temp\nsr78D7.tmp, In Quarantäne, [f1cce29065251f17978fea5219ea02fe],
PUP.Optional.Bundle, C:\Users\Luke\AppData\Local\Temp\nsr78D8.tmp, In Quarantäne, [e6d786ec4644af8730221ce11ee7a45c],
PUP.Optional.GUPlayer.A, C:\Users\Luke\Desktop\GUPlayer.lnk, In Quarantäne, [437a92e05d2d191db16fb01b020107f9],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430316511-E311-B039-F8A963069189\snsi9750.tmp, Löschen bei Neustart, [d5e829493b4ff73f942a83d929dc07f9],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425005-E311-B039-F8A963069189\cnsm3B9A.tmp, Löschen bei Neustart, [dce150220e7c46f025998fcd0203619f],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425005-E311-B039-F8A963069189\ansv3918.exe, In Quarantäne, [dce150220e7c46f025998fcd0203619f],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425005-E311-B039-F8A963069189\rnsm3B9B.exe, In Quarantäne, [dce150220e7c46f025998fcd0203619f],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425005-E311-B039-F8A963069189\Uninstall.exe, In Quarantäne, [dce150220e7c46f025998fcd0203619f],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425019-E311-B039-F8A963069189\onsi72D6.tmp, In Quarantäne, [615cbdb5f298340201bd520a09fcc43c],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425019-E311-B039-F8A963069189\pnso72F7.exe, In Quarantäne, [615cbdb5f298340201bd520a09fcc43c],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425019-E311-B039-F8A963069189\rnsi72D5.exe, In Quarantäne, [615cbdb5f298340201bd520a09fcc43c],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425019-E311-B039-F8A963069189\snsi72D4.tmp, Löschen bei Neustart, [615cbdb5f298340201bd520a09fcc43c],
PUP.Optional.MultiPlug.A, C:\Users\Luke\AppData\Local\B835A680-1430425019-E311-B039-F8A963069189\Uninstall.exe, In Quarantäne, [615cbdb5f298340201bd520a09fcc43c],
PUP.Optional.Multiplug.A, C:\Windows\System32\Tasks\Bidaily Synchronize Task, In Quarantäne, [932a036f0c7e072f983ca2bce520a55b],
PUP.Optional.Multiplug.A, C:\Windows\Tasks\Bidaily Synchronize Task.job, In Quarantäne, [6d509fd37317e254e6ef8ad417ee4ab6],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\499.json, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\523.json, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\MessageBox.xml, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\un.ini, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\uninstallDlg2.xml, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\UninstallManager.exe, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\bg.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\bg1.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\bk_shadow.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\button.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\button1.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\checkbox.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\checkbox_select.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\checked.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\close.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\loading_bg.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\loading_light.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\min.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\scrollbar.bmp, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\Thumbs.db, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\unchecked.png, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\code\code1.jpg, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\code\code2.jpg, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\code\code3.jpg, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\code\code4.jpg, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\code\code5.jpg, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\code\code6.jpg, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\oursurfing\images\code\Thumbs.db, In Quarantäne, [b706ea888cfe49ed393b27a111f243bd],
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\Mozilla\Firefox\Profiles\ce36tu02.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.oursurfing.com/newtab/?type=nt&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81");), Ersetzt,[932ac9a907836cca6aafe56c33d3f50b]
PUP.Optional.OurSurfing.A, C:\Users\Luke\AppData\Roaming\Mozilla\Firefox\Profiles\ce36tu02.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.oursurfing.com/?type=hp&ts=1430308955&z=163f000315e11019ae43519g4z4c7e7cbe9bet8w1e&from=fsf&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1EB3LMD81LMD81");), Ersetzt,[9726264ce8a282b49d7f72df0ef89f61]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) es ist komisch die FRST.txt ist ziemlich klein Code:
LastRegBack: 2015-04-27 02:28
==================== End Of Log ============================
|