Daveomillo | 07.06.2015 20:01 | hier noch ein log von malwarebyte nach dem ersten scan. die hab ich alle in die Quarantäne und dann entfernt. Hab ich aus dem Verlaufsprotokoll geholt. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 07.06.2015
Suchlauf-Zeit: 14:14:15
Logdatei:
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.07.03
Rootkit Datenbank: v2015.06.02.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: andre_000
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 439276
Verstrichene Zeit: 17 Min, 30 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 10
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [0fd031862a60de58abe70631e61e43bd],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\INSTALLCORE, In Quarantäne, [9946e9ce1674c076c4837fce72935da3],
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [736c17a0b6d45fd7e9ac8bf2e520fa06],
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}, In Quarantäne, [5788d6e17d0d132304915825f312df21],
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [10cf585fb3d752e45f36b4c957ae41bf],
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4A3EDB20-0CEA-11E5-827B-206A8A99BF50}, In Quarantäne, [d20d4b6c4b3fd75fda7a509a33d037c9],
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{AA9A4890-4262-4441-8977-E2FFCBFB706C}, In Quarantäne, [528db2050486b77f6e274f2ec0454fb1],
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BD9B40CC-21BF-444A-B55C-808E2E3D18D9}, In Quarantäne, [1fc03d7ab7d3c472a0f5dda0bc49946c],
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}, In Quarantäne, [7c635d5a76143cfa573e017cdb2a9a66],
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{7D9EB003-A933-11E4-826A-206A8A99BF50}, In Quarantäne, [cc135166b4d6c96d5bf90fdb22e11fe1],
Registrierungswerte: 18
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\INSTALLCORE|tb, 0N2Y1N1N1S2X, In Quarantäne, [9946e9ce1674c076c4837fce72935da3]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cvs&utm_campaign=install_ie&utm_content=ds&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&ts=1426521175&type=default&q={searchTerms}, In Quarantäne, [736c17a0b6d45fd7e9ac8bf2e520fa06]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cvs&utm_campaign=install_ie&utm_content=ds&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&ts=1426521175&type=default&q={searchTerms}, In Quarantäne, [5788d6e17d0d132304915825f312df21]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0}|FaviconURL, hxxp://www.mystartsearch.com//favicon.ico, In Quarantäne, [1cc39225becc3ff75a3b601db154fe02]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|DisplayName, mystartsearch, In Quarantäne, [10cf585fb3d752e45f36b4c957ae41bf]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cvs&utm_campaign=install_ie&utm_content=ds&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&ts=1426521175&type=default&q={searchTerms}, In Quarantäne, [8659ab0c19710e28a2f35a236b9add23]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}|TopResultURL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&q={searchTerms}, In Quarantäne, [0fd096216d1dce68e7ae2c5139ccdf21]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4A3EDB20-0CEA-11E5-827B-206A8A99BF50}|FaviconURL, hxxp://homepage-web.com/favicon.ico, In Quarantäne, [d20d4b6c4b3fd75fda7a509a33d037c9]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4A3EDB20-0CEA-11E5-827B-206A8A99BF50}|FaviconURLFallback, hxxp://homepage-web.com/favicon.ico, In Quarantäne, [f0efe0d763271521b59f45a57192ee12]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4A3EDB20-0CEA-11E5-827B-206A8A99BF50}|TopResultURL, hxxp://search.homepage-web.com/?src=omnibox&partner=acer&q={searchTerms}, In Quarantäne, [5c83c8ef850553e3183ce40657acf40c]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{4A3EDB20-0CEA-11E5-827B-206A8A99BF50}|URL, hxxp://search.homepage-web.com/?src=omnibox&partner=acer&q={searchTerms}, In Quarantäne, [3fa002b5771391a54b095199ce357d83]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{AA9A4890-4262-4441-8977-E2FFCBFB706C}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cvs&utm_campaign=install_ie&utm_content=ds&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&ts=1426521175&type=default&q={searchTerms}, In Quarantäne, [528db2050486b77f6e274f2ec0454fb1]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{BD9B40CC-21BF-444A-B55C-808E2E3D18D9}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cvs&utm_campaign=install_ie&utm_content=ds&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&ts=1426521175&type=default&q={searchTerms}, In Quarantäne, [1fc03d7ab7d3c472a0f5dda0bc49946c]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{E733165D-CBCF-4FDA-883E-ADEF965B476C}|URL, hxxp://www.mystartsearch.com/web/?utm_source=b&utm_medium=cvs&utm_campaign=install_ie&utm_content=ds&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&ts=1426521175&type=default&q={searchTerms}, In Quarantäne, [7c635d5a76143cfa573e017cdb2a9a66]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{7D9EB003-A933-11E4-826A-206A8A99BF50}|FaviconURL, hxxp://homepage-web.com/favicon.ico, In Quarantäne, [cc135166b4d6c96d5bf90fdb22e11fe1]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{7D9EB003-A933-11E4-826A-206A8A99BF50}|FaviconURLFallback, hxxp://homepage-web.com/favicon.ico, In Quarantäne, [05dab6014a40e551ce864d9dc1425ea2]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{7D9EB003-A933-11E4-826A-206A8A99BF50}|TopResultURL, hxxp://search.homepage-web.com/?src=omnibox&partner=acer&q={searchTerms}, In Quarantäne, [fbe46453b3d776c0c094b832986b09f7]
PUP.Optional.HomePageHelper.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{7D9EB003-A933-11E4-826A-206A8A99BF50}|URL, hxxp://search.homepage-web.com/?src=omnibox&partner=acer&q={searchTerms}, In Quarantäne, [558a43740882a195aea628c227dcc33d]
Registrierungsdaten: 13
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ),Ersetzt,[fbe4ded990fa082efff158d47a8c7f81]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&q={searchTerms}),Ersetzt,[e0ff50671f6bfd39016b2a0229dde719]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ),Ersetzt,[fee10ea96c1e092d2547161658ae6b95]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ),Ersetzt,[4699e6d1cdbd2d09ee7e4ae26a9c0000]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&q={searchTerms}),Ersetzt,[8659981f2268a591ee7ec468d92d13ed]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[3da2e6d131599d99204203350df924dc]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLIENTS\STARTMENUINTERNET\IEXPLORE.EXE\SHELL\OPEN\COMMAND, C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ, Gut: (iexplore.exe), Schlecht: (C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.mystartsearch.com/?type=sc&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ),Ersetzt,[ce11873051399e987b7578b438ce2ad6]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&q={searchTerms}),Ersetzt,[944b7d3a8703082e7fedf93362a4659b]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ),Ersetzt,[39a6c9eec2c85bdb73f9f933ef1709f7]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ),Ersetzt,[598687306d1d4beb323aab81f313718f]
PUP.Optional.MyStartSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.mystartsearch.com/web/?type=ds&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/web/?type=ds&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ&q={searchTerms}),Ersetzt,[538c70477713181ef874e14b1fe7936d]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[03dc6750bbcf9e98c89a94a49274c33d]
PUP.Optional.MyStartSearch.A, HKU\S-1-5-21-2601026188-1892711848-3592750507-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Page_URL, hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ, Gut: (www.google.com), Schlecht: (hxxp://www.mystartsearch.com/?type=hp&ts=1426521160&from=cvs&uid=ST1000LM014-1EJ164_W7704FDJXXXXW7704FDJ),Ersetzt,[954a7e393456c76f4e1fea4213f3e21e]
Ordner: 3
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\code, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
Dateien: 26
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\MessageBox.xml, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\310.json, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\uninstallDlg2.xml, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\UninstallManager.exe, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\bg.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\bg1.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\bk_shadow.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\button.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\button1.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\checkbox.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\checkbox_select.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\checked.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\close.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\loading_bg.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\loading_light.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\min.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\scrollbar.bmp, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\Thumbs.db, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\unchecked.png, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\code\code1.jpg, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\code\code2.jpg, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\code\code3.jpg, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\code\code4.jpg, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\code\code5.jpg, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\code\code6.jpg, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
PUP.Optional.MyStartSearch.A, C:\Users\andre_000\AppData\Roaming\mystartsearch\images\code\Thumbs.db, In Quarantäne, [56897e39b9d186b02a52cb3328dbcc34],
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) noch ein späterer log von malwarebytes Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 07.06.2015
Suchlauf-Zeit: 14:41:10
Logdatei:
Administrator: Ja
Version: 2.01.6.1022
Malware Datenbank: v2015.06.07.03
Rootkit Datenbank: v2015.06.02.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: andre_000
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 437654
Verstrichene Zeit: 12 Min, 56 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 0
(Keine schädliche Elemente gefunden)
Registrierungswerte: 0
(Keine schädliche Elemente gefunden)
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 0
(Keine schädliche Elemente gefunden)
Dateien: 0
(Keine schädliche Elemente gefunden)
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) und ein protection log von malwarebytes, das ist alles Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 07.06.2015 14:13:54, SYSTEM, FAMILIEN-PC, Protection, Malware Protection, Starting,
Protection, 07.06.2015 14:13:54, SYSTEM, FAMILIEN-PC, Protection, Malware Protection, Started,
Protection, 07.06.2015 14:13:54, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Starting,
Protection, 07.06.2015 14:13:54, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Started,
Update, 07.06.2015 14:13:57, SYSTEM, FAMILIEN-PC, Manual, Remediation Database, 2015.3.9.1, 2015.5.13.1,
Update, 07.06.2015 14:13:57, SYSTEM, FAMILIEN-PC, Manual, Rootkit Database, 2015.2.25.1, 2015.6.2.1,
Update, 07.06.2015 14:14:03, SYSTEM, FAMILIEN-PC, Manual, Malware Database, 2015.3.9.5, 2015.6.7.3,
Protection, 07.06.2015 14:14:03, SYSTEM, FAMILIEN-PC, Protection, Refresh, Starting,
Protection, 07.06.2015 14:14:03, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Stopping,
Protection, 07.06.2015 14:14:03, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Stopped,
Protection, 07.06.2015 14:14:11, SYSTEM, FAMILIEN-PC, Protection, Refresh, Success,
Protection, 07.06.2015 14:14:11, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Starting,
Protection, 07.06.2015 14:14:12, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Started,
Scan, 07.06.2015 14:32:17, SYSTEM, FAMILIEN-PC, Manual, Start: 07.06.2015 14:14:15, Dauer: 17 Minuten 30 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, "70" nicht-Malwareerkennung,
Protection, 07.06.2015 14:37:05, SYSTEM, FAMILIEN-PC, Protection, Malware Protection, Starting,
Protection, 07.06.2015 14:37:05, SYSTEM, FAMILIEN-PC, Protection, Malware Protection, Started,
Protection, 07.06.2015 14:37:05, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Starting,
Protection, 07.06.2015 14:38:06, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Started,
Scan, 07.06.2015 14:54:06, SYSTEM, FAMILIEN-PC, Manual, Start: 07.06.2015 14:41:10, Dauer: 12 Minuten 56 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, "0" nicht-Malwareerkennung,
Protection, 07.06.2015 14:57:05, SYSTEM, FAMILIEN-PC, Protection, Malware Protection, Starting,
Protection, 07.06.2015 14:57:05, SYSTEM, FAMILIEN-PC, Protection, Malware Protection, Started,
Protection, 07.06.2015 14:57:05, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Starting,
Protection, 07.06.2015 14:57:39, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Started,
Protection, 07.06.2015 16:40:09, SYSTEM, FAMILIEN-PC, Protection, Malware Protection, Starting,
Protection, 07.06.2015 16:40:09, SYSTEM, FAMILIEN-PC, Protection, Malware Protection, Started,
Protection, 07.06.2015 16:40:09, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Starting,
Protection, 07.06.2015 16:40:16, SYSTEM, FAMILIEN-PC, Protection, Malicious Website Protection, Started,
Scan, 07.06.2015 17:13:52, SYSTEM, FAMILIEN-PC, Manual, Start: 07.06.2015 16:58:07, Dauer: 15 Minuten 45 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, "0" nicht-Malwareerkennung,
Scan, 07.06.2015 17:19:48, SYSTEM, FAMILIEN-PC, Manual, Start: 07.06.2015 17:19:14, Dauer: 0 Minuten 33 Sekunden, Bedrohungs-Suchlauf, Abgebrochen, 0 Malwareerkennung, "0" nicht-Malwareerkennung,
(end) |